Google Workspace
Audit users, 2-step verification, super admins, and OAuth app grants.
Identity & access
Evidence coverage
What this connector audits
Checks this connector runs once it's connected. This is the full list; we don't claim coverage beyond what's implemented.
- Active users not enrolled or enforced for 2-step verification
- Super-admin inventory and super-admin 2SV gaps
- Optional employee allowlist offboarding gaps
- OAuth app grants with high-risk scopes
Least privilege
What we need
Field labels only. We never show secret values here. Credentials are encrypted at rest and used only to run the checks above.
- OAuth access token(secret credential)
- Service-account JSON(secret credential)
- Delegated admin email
- Customer ID
- Employee emails
Optional
Where this evidence goes
Which frameworks this evidence supports
Google Workspace evidence feeds into controls for any framework you run that requires this check type; the same synced evidence can satisfy more than one framework's requirements instead of being collected per audit.
Don't see your system?
Tell us what you use and what it needs to prove. We'll follow up about adding a connector.
Wire in Google Workspace evidence
Get a guided demo, or start by scanning any domain for free.