Find the apps and ex-employees that still have access — before someone else does.
Esmeris is a read-only access audit for Google Workspace and Microsoft 365. We inventory third-party apps, OAuth tokens, and ex-employee access — then hand you a clear, graded report in plain English.
Free to start · no credit card · top 3 findings per platform
- Read-only access
- Credentials encrypted
- We never change your settings
From access to answers in three steps
No agents to install, no changes to your environment — just a read-only look and a clear verdict.
Grant read-only access
You connect a read-only admin account. We never get the keys to change anything.
We scan your tenant
Esmeris inventories every user, app, token and permission across Workspace and 365.
You get a graded report
A clear letter grade with prioritized findings and plain-English fixes — no jargon.
The access you forgot you still had
From risky OAuth scopes and org-wide consent grants to ex-employee access and admins without MFA — every finding maps to a real way attackers and former staff keep a foothold after you think the door is closed.
Former-employee access
Accounts and tokens belonging to people who have left but can still reach your data.
Risky app permissions
Third-party apps holding broad scopes — read all mail, manage files, act as a user.
Org-wide consent grants
Apps approved for the whole organization, often by a single click long ago.
Admins without MFA
Privileged accounts missing multi-factor — the single biggest breach lever.
Unverified publishers
Connected apps from publishers Google or Microsoft has never verified.
Stale connections
Integrations that haven't been touched in months but still hold live access.
See exactly what you’ll get
Every audit ends in one graded report — an overall letter grade, findings ranked by severity, and plain-English fixes. Take a look at a redacted sample before you commit to anything.
Your free report shows the top 3 findings per platform — no credit card. Upgrade anytime for every finding and the full grade.
Answer your cyber-insurance questions with evidence
Insurers increasingly ask exactly what Esmeris measures. A graded report turns guesswork into documentation.
- Do all admin accounts enforce multi-factor authentication?
- Have you removed access for departed employees?
- Do you review third-party application permissions?
- Are org-wide consent grants restricted and monitored?
- Do you track unverified or stale connected apps?
Practical guides from the audit trenches
Step-by-step walkthroughs you can run today in Google Workspace and Microsoft 365 — no Esmeris account needed.
Using an access audit to answer your cyber-insurance questionnaire
Cyber-insurance applications now ask detailed access-control questions. Here's how a Google Workspace / Microsoft 365 access audit gives you evidence-backed answers.
Finding admin accounts without MFA in Microsoft 365
Privileged accounts without multi-factor authentication are the single biggest breach lever in Microsoft 365. Here's how to find the gaps — including the ones Conditional Access misses.
Risky OAuth scopes, explained
What OAuth scopes are, which ones are dangerous, and how to tell whether a connected app in Google Workspace or Microsoft 365 has more access than it needs.
Questions we hear most
Ready to see who has access?
Start free and get your top 3 findings for Google Workspace and Microsoft 365 — no credit card. Upgrade for the full graded report.
Start your free audit