How it works
How 8200.dev stands between AI and action
It sees every AI tool with access to your data, applies the policy you set for each rule, and acts at the source only when you opt in — with a kill switch, an audit trail and a way back.
No credit card. No sales call. Just connect and see your risk.
See, decide, act — six steps from connect to proof
See
See every AI tool with access
Connect a source read-only and 8200.dev maps every AI agent, app, integration and person that can reach your data — and what each one can do.
- Step 1
Connect
One-click OAuth, read-only. Two minutes and no agents to install — we never touch your data unless you explicitly turn on auto-remediation.
- Step 2
Discover
We scan your users, files, sharing links and permissions on every sync — 30+ security checks across your whole workspace.
What we check
30+ checks, grouped into the categories that actually move your risk.
External sharing
Files shared to anyone with the link, to people outside your domain, or open to the whole internet.
Shared Drives
Every Shared Drive's members, external access and restriction settings — and any drive with no manager.
Third-party apps
Which OAuth and marketplace apps users connected to your Workspace, and how much access each one holds.
Stale accounts
Users who have not signed in for months but still hold access, and dormant privileged accounts.
Over-permissioning
Org-wide edit access, broad group permissions, and ownership sprawl across sensitive files.
Sensitive data
Files whose names or locations match credential, financial, HR and PII patterns you can tune per org.
Sensitive exposure
Sensitive content reachable by external parties or far more people than it should be.
AI agents & service accounts
Non-human identities and AI agents with standing access to your data — what they can reach, and where it is over-broad.
Decide
Decide what each one may do
Every finding is scored by severity and blast radius. For each rule you set the policy and the tier — and every organization starts on the one that only reads.
- Step 3
Prioritize
Every finding is scored by severity and blast radius. A single posture score, from 0 to 100, tells you exactly where you stand and what to fix first.
Three tiers — and only one of them writes
Detect & Alert
Read-only. Finds risky access, data flows and agent actions, and explains each one. Every organization starts here.
Recommend & Guide
Still read-only. Adds the exact fix and step-by-step instructions for a person on your side to apply.
Auto-remediate
The only tier that writes, and it is off by default. It needs the organization switch, an armed policy and write scopes you grant per connector; until then it runs as a simulation. It only revokes or reduces access — it never deletes files or touches their contents.
Act
Act at the source — only when you say so
Fix it yourself with the exact steps, or arm Auto-remediate for the rules you choose and 8200.dev revokes or downgrades the access itself.
- Step 4
Fix
Each finding comes with step-by-step remediation. Or arm a policy for the rule and, once write access is granted, 8200.dev revokes or reduces the access for you — every action logged.
Auto-remediation
Set a policy once. We hold the line.
A file gets shared externally. 8200.dev catches it on the next scan. Your policy says "auto-fix external sharing" — so the share is revoked automatically, and you see exactly what happened in your audit log. Done.
Read-only by default — always. 8200.dev only makes a change after you approve a separate, explicit elevated-access grant for that specific connector, and you can revoke it any time without interrupting monitoring. You’re always in control of what can write versus what can only read. Auto-fix is not available on Google Workspace yet: it switches on once Google has verified the write scope it needs.
Before
A budget spreadsheet is shared to "anyone with the link".
Exposed to the public internet. Nobody noticed.
After
The external share is revoked automatically within one scan.
Logged to your audit trail, reversible, fully attributable.
And you can always stop it
Enforcement you can't see, stop or undo isn't control. Three things make sure you can.
Kill switch
One global switch pauses all enforcement instantly and returns everything to simulate-only. It overrides every other setting.
Audit trail
Every action is recorded: whether a person or a policy triggered it, when, on which finding, and the state before and after.
Reversible
Each action records the state it changed, so a removed link or share can be put back from that record; a revoked key is replaced with a fresh one. Revoking the write grant stops enforcement without interrupting monitoring.
Prove it to an auditor
The same record becomes compliance evidence, mapped to SOC 2, ISO 27001, GDPR, HIPAA and NIST CSF controls — mapped, not certified.
- Step 5
Analyze
Map data flows with Flow Guard, learn behavioral baselines with UEBA, and benchmark your posture against industry peers.
- Step 6
Prove
Generate compliance evidence for five frameworks, board-ready executive reports, incident records and an exportable audit log.
Continuously monitoring thousands of resources across security-conscious teams — every sync, every day.
For MSSPs & IT partners
Manage every client from one account
MSSPs, IT consultancies and managed service providers run all their clients' Google Workspace security from a single partner account — a consolidated dashboard, portfolio reports, white-label, and self-serve onboarding.
Start managing your clients' securityStart your free scan
Connect in two minutes and see your posture score. No credit card, no call with a salesperson — just your real risk.