Google Workspace
LiveProductivity & CollaborationGoogle Workspace connector — read-only, agentless
Scans Google Drive files and folders, their sharing settings, and the user directory to map who can access what across your Workspace.
To connect Google Workspace, you'll approve a Google authorization. On the screen that appears, click Advanced → Continue — this is Google's standard screen for apps in the verification process.
What we scan
- File and folder names and their sharing settings (never file contents)
- User and group directory metadata (to classify internal vs external access)
Read-only monitoring — nothing in your Google Workspace data changes unless you turn on auto-remediation and grant write access separately.
Security findings
35 detection rules run on every Google Workspace scan. Each finding ships with a plain-language explanation, the evidence behind it and remediation steps.
- CRITICALPublic exposure
Public link with edit/owner access
- CRITICALExternal access
External principal holds ownership
- CRITICALShadow it
Unvetted app with full Drive/mailbox or admin scopes
- CRITICALAI agent
Agentic AI platform holds delegated workspace access
- CRITICALAI built app
AI-built app can access customer PII
- HIGHPublic exposure
Public link share (link-only)
- HIGHPublic exposure
Public + web-discoverable share
- HIGHExternal access
External access to sensitive data
- HIGHExternal access
External collaborator with edit access
- HIGHOver permission
Sensitive resource editable org-wide
- HIGHOver permission
Broad group access to sensitive data
- HIGHAI agent
Service account with broad write access
- HIGHAI agent
AI agent with access to sensitive data
- HIGHAI agent
AI agent with edit/owner access
- HIGHExternal access
Access granted to a look-alike (typosquat) domain
- HIGHShared drive
External member on a Shared Drive
- HIGHShared drive
Anyone-with-the-link file inside a Shared Drive
- HIGHShared drive
Shared Drive has no Manager (orphaned)
- HIGHShadow it
Shadow-AI tool (ungovernable AI vendor) connected to the workspace
- HIGHShadow it
Unknown app can send email as your users
- HIGHAI built app
AI-built app holds broad data scopes
- HIGHAI built app
AI-built app has no documented data-retention policy
- MEDIUMOver permission
Broad org-wide edit access (aggregate)
- MEDIUMOver permission
Resource with multiple owners
- MEDIUMStale access
Stale external read access
- MEDIUMStale access
Dormant privileged internal account
- MEDIUMMisconfig
Direct share breaks folder inheritance
- MEDIUMShared drive
Shared Drive allows external sharing
- MEDIUMShared drive
Shared Drive with excessive membership
- MEDIUMShared drive
Stale Shared Drive (no recent activity)
- MEDIUMShadow it
App authorized by a single user with broad scopes
- MEDIUMAI built app
Unverified recently-created app with broad scopes
- MEDIUMMisconfig
Vendor AI-training data-contribution posture
- LOWShared drive
Shared Drive's sharing restrictions could not be read
- LOWShadow it
Stale app authorization unused for 90+ days
Related guide
How to connect Google Workspace
Step 1
Sign up or log in to 8200.dev
Step 2
Go to Connectors → Google Workspace
Step 3
Click Connect and authorize via Google Workspace's consent screen
Step 4
8200.dev scans automatically — results appear within minutes
Connect your first source in minutes — free, read-only, no sales call.