Why the SSO list is incomplete
Central assignment is evidence—not the entire account universe
An account can be created with a direct password, a Google OAuth grant, a vendor invitation, a secondary email address, or an API credential. A company can also keep paying for software after the original identity relationship changes.
- The vendor never supported your identity provider.
- A user chose Sign in with Google without a centrally assigned SSO application.
- The account uses an alias, personal address, or contractor domain.
- The subscription is visible in billing records but not in identity administration.
Evidence ladder
Use several lawful business sources and keep their claims separate
Work only with records your organization is authorized to inspect. Each source answers a different question, so label whether it shows current access, historical activity, ownership, or merely a paid subscription.
- 01
Export or review centrally assigned SSO applications and current Google-connected grants.
- 02
Compare them with the maintained software inventory and named application owners.
- 03
Review approved password-manager collections, procurement records, and administrator lists.
- 04
Match software invoices and finance records to vendors missing from the identity view.
- 05
Ask the employee and application owners to resolve remaining likely or unknown records.
Reconciliation
Classify the result instead of forcing false certainty
A useful discovery record separates confirmed access, likely access, historical evidence, paid subscription without user attribution, ruled out, and unknown. This makes it possible to investigate gaps without claiming a coverage level the evidence cannot support.
What not to infer
Absence from one source is not proof of absence
No OAuth token does not mean no password account. No current invoice does not mean no free account. A card charge proves spend, not which person can log in. A recent audit event proves activity at that time, not necessarily current access.
From checklist to maintained record
Keep offboarding evidence attached to the software record.
Billproof early access is being built to reconcile Workspace application evidence, known software, ownership, and billing records into one reviewable offboarding view.
Sources and scope
Primary references
These sources support the Google Workspace capability statements. Operational checklist items should still be adapted to your contracts, roles, retention rules, and local law.
- Google Workspace Admin SDK — user tokens list ↗current token grants
- Google Workspace Reports API — token audit activity ↗recent grant activity