Skip to content

Google Workspace app audit

How to audit third-party apps connected to Google Workspace

Workspace application-grant data is a strong discovery source when interpreted carefully. This guide separates current token grants, recent audit activity, Google licensing, and the SaaS accounts those sources cannot prove.

Know the sources

Current grants and recent activity answer different questions

The Admin SDK Directory tokens resource can list third-party application tokens issued to a user. The Reports API token audit log records authorization activity. One is useful for current grant review; the other is useful for recent events and investigation context.

  • Directory tokens: application name, client ID, scopes, and user-specific grant context.
  • Token audit activity: recent authorization or revocation events available to the audit log.
  • Licensing API: Google Workspace and related Google product assignments, not a universal SaaS seat inventory.

Audit workflow

Review grants by user, application, scope, and business owner

Use an authorized Workspace administrator and the minimum scopes required for the review. Preserve the source timestamp and avoid collapsing several users or client IDs into one application record until the match is verified.

  1. 01

    Define the users, organizational units, and review date in scope.

  2. 02

    List current third-party tokens or grants for each user and retain client IDs and scopes.

  3. 03

    Use recent token audit events to add authorization and revocation context where available.

  4. 04

    Normalize client IDs to known vendor records without discarding unmatched applications.

  5. 05

    Ask the application owner to confirm business purpose, current need, and offboarding action.

  6. 06

    Record removed grants, accepted access, exceptions, and unknowns with source evidence.

Risk review

Prioritize scope and ownership, not just application count

A rarely used application with broad scopes and no owner can deserve more attention than a widely adopted tool with narrow access and clear administration. Review sensitive scopes, external ownership, stale users, unknown client IDs, and grants that no longer have a business purpose.

Coverage boundary

A Workspace audit is not a complete SaaS inventory

The audit will not reveal every direct password login, non-Google identity, vendor invitation, API token, or paid seat. Reconcile the findings with software ownership and billing evidence before using them for offboarding or inventory completeness claims.

From checklist to maintained record

Keep offboarding evidence attached to the software record.

Billproof early access is being built to reconcile Workspace application evidence, known software, ownership, and billing records into one reviewable offboarding view.

See the offboarding workflow

Sources and scope

Primary references

These sources support the Google Workspace capability statements. Operational checklist items should still be adapted to your contracts, roles, retention rules, and local law.

  1. Google Workspace Admin SDK — tokens.list ↗method reference
  2. Google Workspace Reports API — token audit activity ↗audit guide
  3. Google Workspace Enterprise License Manager API ↗Google licensing scope