How to find the third-party apps with access to your Google Workspace
To find every third-party app with access to your Google Workspace, open the Google Admin console and go to Security → Access and data control → API controls → Manage third-party app access. That page lists every app connected to your domain, who connected it, and whether it’s marked Trusted, Limited, or Blocked. The rest of this guide is how to spot the risky ones in that list.
App access control: which scopes an app holds
The companion App access control view, under the same API controls page, is where Google Workspace manages what each connected app is allowed to reach. It shows which apps hold restricted scopes (the sensitive ones, like Gmail and Drive access) and it’s where an app’s Trusted, Limited, or Blocked status is set. An app marked Trusted with restricted scopes can reach far more than a limited add-on, so start your review there.
What to look for
- Broad scopes. Apps that can “read, compose, send, and permanently delete all your email” or “see, edit, create, and delete all your Google Drive files” are the ones to scrutinize first.
- Org-wide / domain-wide grants. An app authorized for the entire domain, or via domain-wide delegation, is far riskier than the same app connected by one user.
- Unverified publishers. Apps Google hasn’t verified should be treated with suspicion.
- Stale connections. Tokens that haven’t been used in months still work until revoked.
The catch with doing it manually
The Admin console shows you the data, but it doesn’t prioritize it. A mid-sized domain can have hundreds of grants across dozens of apps and thousands of user-app pairs. The hard part is deciding which of those matter. You have to cross-reference scope risk against who still works there and whether MFA is on, and it’s easy to miss the one token that matters.
A faster path
Esmeris automates this with a read-only audit. It inventories every app, token, and permission, ranks the risk, and hands you a graded report in plain English.