← All resources

How to find the third-party apps with access to your Google Workspace

To find every third-party app with access to your Google Workspace, open the Google Admin console and go to Security → Access and data control → API controls → Manage third-party app access. That page lists every app connected to your domain, who connected it, and whether it’s marked Trusted, Limited, or Blocked. The rest of this guide is how to spot the risky ones in that list.

Which scopes an app holds

Beyond the connected-apps list, the App access control view shows which apps hold restricted scopes — the sensitive ones like Gmail and Drive access. An app marked Trusted with restricted scopes can reach far more than a limited add-on, so this is where you start separating convenient integrations from dangerous ones.

What to look for

  • Broad scopes. Apps that can “read, compose, send, and permanently delete all your email” or “see, edit, create, and delete all your Google Drive files” are the ones to scrutinize first.
  • Org-wide / domain-wide grants. An app authorized for the entire domain — or via domain-wide delegation — is far riskier than the same app connected by one user.
  • Unverified publishers. Apps Google hasn’t verified should be treated with suspicion.
  • Stale connections. Tokens that haven’t been used in months still work until revoked.

The catch with doing it manually

The Admin console shows you the data, but it doesn’t prioritize it. A mid-sized domain can have hundreds of grants across dozens of apps and thousands of user-app pairs. Deciding which of those actually matter — cross-referencing scope risk, who still works there, and whether MFA is on — is the hard part, and it’s easy to miss the one token that matters.

A faster path

This is exactly what Esmeris automates: a read-only audit that inventories every app, token, and permission and ranks them by real-world risk, then hands you a graded report in plain English. See the sample report for what that looks like.

Start your free audit