Google Workspace App Access Review
Reviews third-party OAuth apps, their per-user tokens, and domain-wide delegations in a Google Workspace domain, and proposes which to block, restrict, remove, or keep.
What this agent does
This read-only agent reviews third-party access in a Google Workspace domain. It reads the configured-apps export I hand it for each app's access setting and verification status. It reads the per-user OAuth tokens from the Admin SDK for the scopes each app holds and the users who granted them. It reads the domain-wide delegations from the API controls export and the admin audit log. It ranks each by the sensitivity of its scopes, the user count, its last use from the token audit log, and whether the app is verified. It proposes which apps to block, restrict, or keep, and which delegations to remove, with the evidence for each. A person makes every change.
The challenge
A Workspace user can authorize an unconfigured third-party app unless the domain restricts it. A note-taking tool keeps full Drive access after the user stops using it. A service account with domain-wide delegation to every mailbox outlives the migration it served. An unverified app holds Gmail read access from many users. Nobody joins the admin console settings with the tokens users grant.
The solution
The agent joins the configured-apps export with the per-user tokens and the delegations in one pass. It states each scope in plain words, such as read all mail or see and manage all Drive files. It proposes the narrowest change for each item and presents every proposal as a candidate. Provides a ranked queue of app access, with the evidence for each proposal.
Workflow
- 01
Read the configured apps
Read the configured-apps export for each app's access setting and verification status, and the API controls export for domain-wide delegations.
- 02
List tokens
List the per-user OAuth tokens from the Admin SDK, grouped by app, with their scopes and user counts.
- 03
Measure use
Read the token audit log for authorizations and activity per app in the window.
- 04
Rank and propose
Rank each app and delegation by scope sensitivity, user count, last use, and verification, and write a block, restrict, remove, or keep proposal with the evidence.
- 05
Report
Publish the ranked queue with each proposal and the current app access settings.
Agent template
# Google Workspace App Access Review
## Measurable outcomes
Every third-party app with a token or a configured setting, and every domain-wide delegation, is in the ranked queue. Each one has its scopes in plain words and a proposal. Track the apps flagged by at least one rule. A proposal counts as applied when the next run finds the grant removed or narrowed.
## Procedure
Each run, read the configured-apps export I hand it, and the per-user tokens from the Admin SDK. From the export, record each app's access setting and its verification status. Record whether the domain restricts unconfigured third-party apps. From the tokens, group the grants by app client ID, with the scopes each app holds and the number of users who granted them. Read domain-wide delegation from the API controls export I hand it, and from AUTHORIZE_API_CLIENT_ACCESS events in the admin audit log. Record each delegation's client ID and scopes. Read the token audit log for the last 90 days, and record each app's last authorization and last activity. Translate each scope into plain words, such as read all mail, send mail as the user, see and manage all Drive files, read contacts, or read the directory. Rank each app and delegation by the most sensitive scope it holds, weighted by the number of users who granted it. Lower the rank for apps used in the last 30 days. Lower the rank for verified apps. Lower the rank for apps I mark as approved. Flag apps with no activity in 90 days. Flag apps whose tokens belong to suspended users. Flag unverified apps with sensitive or restricted scopes. Flag apps that hold Gmail or full Drive scopes that no approved use needs. Flag delegations I have not marked as approved. For each app, propose one of block, restrict, or keep. For each delegation, propose remove or keep. Block means set the app to blocked in app access control. Restrict means set the app to specific Google data with only the scopes its use needs. Remove means delete the domain-wide delegation. Keep means the use is approved and the scopes match it. Give the evidence for each proposal, such as the scopes, the user count, the last activity, and the verification status. Present every proposal as a candidate and change nothing. Never revoke a token, change an app access setting, or remove a delegation.
## Requirements
It needs read-only Admin SDK access to user tokens. It needs read-only Reports API access to the token and admin audit logs. It needs the configured-apps export and the API controls export I hand it, and nothing more. It never changes tokens, settings, or delegations. Reports show app names, scopes, and counts. User names appear as stable pseudonyms. Related templates
-
Microsoft Entra ID App Consent Review
Reviews delegated grants, application permissions, and directory roles held by apps in an Entra ID tenant, and proposes which to revoke, restrict, or keep.
Identity and Access 1 tools -
Microsoft Entra ID Offboarding Verification
Checks each departed user for an account re-enabled by sync, owned apps with valid secrets, and access outside Entra ID, and reports each open path.
Identity and Access 9 tools -
Microsoft Entra ID Posture Report
Delivers a weekly Entra ID report on permanent privileged roles, Conditional Access changes, and expiring app credentials, with what changed since last week.
Identity and Access / Reporting and Compliance 1 tools -
Google Workspace Offboarding Verification
Checks each departed user for Drive files shared outside the domain, live OAuth tokens, and access outside Workspace, and reports each open path.
Identity and Access 9 tools