How to Check Which Apps Can Access Your Business Accounts

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Check Which Apps Can Access Your Business Accounts.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for How to Check Which Apps Can Access Your Business Accounts.

In Google Workspace, open the Admin console and go to Security, then Access and data control, then API controls, then Manage Third-Party App Access. The Accessed apps list shows each app your staff have let in, how many users and which services it reaches. Staff can check their own at myaccount.google.com/connections; Microsoft 365 admins use Enterprise apps in the Entra admin centre.

Look hardest at apps that can read or send Gmail, or open all of Drive, and that only one or two people use: AI email assistants, meeting note-takers and add-ons someone tried once. Those grants usually outlive the reason they were given, and they keep your data within reach of a company you may never have chosen.

Follow me on Instagram@sagnikteaches

Three kinds of connection, three levels of risk

Not every entry on the list is a problem. Google's own account settings split connections into three kinds, and the risk rises sharply from the first to the third.

Connect on LinkedInSagnik Bhattacharya
Connection typeWhat it meansRiskWhat to look for
Sign in with GoogleThe app uses your Google account as its login and gets your name, email and profile pictureLowWork accounts used to sign up for personal apps; tools you have no record of paying for
Linked accountYour Google account and an account on another service are linked so features work across bothMediumLinks nobody remembers making
Access to your Google AccountThe app can read, and sometimes change, specific Google data such as Gmail, Drive, Calendar or ContactsHighMail and full-Drive access, especially for AI tools and one-user apps

Microsoft 365 has the same idea under different names. An app can hold delegated permissions that one user consented to, or permissions an admin approved for the whole organisation. Either way, the question is the same: what can this app reach, and does it still need to?

Subscribe on YouTube@codingliquids

A 20-minute audit in the Google Admin console

You need an admin with the Service Settings privilege; in a small business that is usually the owner's super admin account.

  1. Go to Security, then Access and data control, then API controls, and select Manage Third-Party App Access.
  2. Open the Accessed apps list. It shows each app's name, the number of users who have granted it access, and the Requested services column, which lists the Google APIs it asked for (Gmail, Drive, Calendar and so on; non-Google services appear as "Other").
  3. Sort by the services column and pull out everything touching Gmail or Drive.
  4. Sort by users. Apps with a single user deserve a question: who, why, and is it still in use?
  5. Check the Configured apps list, which holds apps you have already marked Trusted, Limited or Blocked. In a first audit it is usually empty.
  6. Export or copy the list into a sheet with columns for app, users, services, owner, decision and date.

While you scan, a few patterns deserve an immediate second look:

  • Mail access that includes sending or permanent deletion. Reading mail is one thing; sending as a member of staff or deleting mail beyond recovery is what makes a breach expensive.
  • Full Drive access for a single-purpose tool. A PDF converter or signature tool rarely needs every file you can open.
  • Generic or unfamiliar names ("AI Assistant", "Mail Helper") with no obvious vendor behind them.
  • Apps still granted by people who have left. Grants made by an ex-employee sit on their account until it is deleted or the tokens are revoked.
  • Two tools doing the same job, such as three different note-takers. Each extra one is another company holding recordings of your calls.

Google's full reference for these settings is in its Workspace Admin Help page on third-party app access. The audit itself changes nothing; decisions come after you have seen the whole list.

What a six-person roofing contractor found

An illustrative example makes the numbers concrete. A roofing contractor with six people on Google Workspace (owner, office manager, two estimators, two crew leads) ran the audit for the first time. The Accessed apps list had 23 entries. Nine were used by only one person, and five could read or send Gmail. The ones worth a decision looked like this:

App (described)UsersServicesDecision
Roof-measurement report service3Drive, GmailKeep; mark Trusted
E-signature tool for quotes2Drive, GmailKeep; mark Trusted
AI email-writing browser add-on1Gmail (read, compose, send)Remove; use Gemini in Gmail, already in the Workspace plan
AI meeting note-taker A2Calendar, DriveKeep one note-taker, company account only
AI meeting note-taker B1CalendarRemove
Free PDF merging website1DriveRemove
CRM trial from two years ago2Gmail, ContactsRemove; ask the vendor to delete data
Zapier1Gmail, SheetsKeep; move the connection to the office mailbox
Accounting software1GmailKeep; mark Trusted
Fitness and food apps using Sign in with Google3Profile onlyAsk staff to switch to personal accounts

In the end they removed 11 apps, marked 4 as Trusted and left the profile-only sign-ins to the individuals. It took 35 minutes including two short conversations. The item that surprised the owner was the email add-on: an estimator had installed it over a year earlier to tidy up quote emails, it had permission to send mail as him, and he had forgotten it existed. Risky browser add-ons like that one are the subject of spotting fake AI apps and risky extensions.

Checking one person's account in five minutes

The admin view shows the whole company, but it is also worth asking each person to look at their own account once, because it teaches them what a permission request looks like. On a Google account, the connections page (myaccount.google.com/connections) lists every third-party link and lets you filter by type:

  1. Choose the filter Access to your Google Account first, since those carry the most risk.
  2. Select an app, then See details, to view which Google services it can reach.
  3. If you don't use it any more, select Remove access and confirm.
  4. Repeat with Linked account (the option there is Delete link) and Sign in with Google (Stop using Sign in with Google).

Removing Sign in with Google from an app you still use means you'll need another way to log in to it, so set a password on that app first. For the roofing contractor, the office manager sent this to everyone: "Please open your Google account connections page, remove anything you don't recognise or no longer use, and reply with a list of what's left." Four of the six replied within a day, and their lists matched the admin view, which is a useful cross-check that nothing was missed.

Getting an AI assistant to explain a permission list

Permission names are written for developers. You can paste them into ChatGPT, Claude or Gemini and ask for plain English, as long as you treat the answer as a starting point.

An app on our Google Workspace has these permissions:
- Read, compose, send, and permanently delete all your email from Gmail
- See, edit, create, and delete all of your Google Drive files
- See your primary Google Account email address

The app is described as "an AI writing assistant for emails".
1. Explain each permission in plain English.
2. For each, give the worst realistic misuse if the app's company
   were breached or sold.
3. Say which permissions an email-writing assistant would genuinely need.
Keep it under 200 words.

An illustrative reply:

1. Gmail: the app can read every message, write and send mail as you, and delete mail so it can't be recovered. 2. Drive: it can open, change or delete any file you can reach, including shared folders. 3. Email address: it knows who you are. Worst case: a breach exposes all mail and files, or an attacker sends invoices from your address. An email-writing assistant needs, at most, access to draft messages; full Drive access and permanent deletion are not needed for that job.

What to check before acting on it: the assistant doesn't know what this particular app actually does, only what its description suggests. Open the vendor's own page or ask the staff member what they use it for. In this case the answer confirmed the verdict, and the app went.

The same audit in Microsoft 365

For Microsoft 365 businesses, the list lives in Microsoft Entra ID, the directory behind your accounts. Microsoft documents the steps in Microsoft Learn:

  1. Sign in to the Microsoft Entra admin centre as at least a Cloud Application Administrator (the global admin account works too, but use it sparingly).
  2. Go to Entra ID, then Enterprise apps, then All applications.
  3. Select an app, then Permissions.
  4. The Admin consent tab shows permissions approved for the whole organisation. The User consent tab shows what individual users granted.
  5. Select a permission to see its details. You can revoke admin-consented permissions from the portal with the three-dot menu and Revoke permission.

Two catches. First, permissions on the User consent tab can't be revoked in the portal; Microsoft points you to Microsoft Graph or PowerShell for those, which is a job for whoever manages your IT if you don't script. Second, revoking doesn't stop a user granting the same access again, which is why the consent settings further down matter.

Staff can check their own work account at myapplications.microsoft.com: hover over an app, choose the three-dot menu, then Manage your application. The top section shows permissions they granted, with Revoke Permissions; permissions an admin approved appear below and can't be removed by the user. For personal Microsoft accounts, the equivalent page is account.live.com/consent/Manage.

Check the connections inside your other tools

Google and Microsoft only show apps that reach Google or Microsoft data. Your other systems keep their own lists, and AI tools have added a lot to them. A realistic sweep covers:

  • ChatGPT and Claude. In settings, look at which apps (ChatGPT's former "connectors") or connectors are attached: Gmail, Drive, Outlook, SharePoint, Slack. What those can see is covered in detail in what ChatGPT's connectors can see in your Drive and inbox.
  • Zapier and Make. Each connection runs under someone's login. List which person's account each one uses; a Zap on an ex-employee's Gmail stops the day their account is suspended.
  • Accounting, CRM and job-management software. Most have a "connected apps" or "integrations" page in settings. Look for trials, old payment tools and duplicate AI add-ons.
  • Social and advertising accounts. Scheduling tools and AI caption apps often hold posting rights long after the free trial ended.

For the roofing contractor, this sweep found two more: an AI reply tool attached to the business Facebook page, and a second Zapier account an estimator had opened with the same work email. Both were removed the same day.

Stop new grants piling up

An audit without a rule is a job you repeat forever. Both platforms let you control what staff can approve.

  • Google Workspace: in the same API controls area, mark the apps you rely on as Trusted and block the ones you removed. Then choose a setting for unconfigured apps. "Allow users to access third-party apps that only ask for Google sign-in info" lets staff use Sign in with Google but stops unknown apps reaching Gmail or Drive until you approve them. The stricter option blocks all unconfigured third-party apps.
  • Microsoft 365: in the Entra admin centre, under Enterprise apps, Consent and permissions, then User consent settings, you can choose "Do not allow user consent", which means only admins approve apps. Pair it with the admin consent workflow so staff can request an app rather than work around you. Microsoft notes that changing these settings only affects future consent; existing grants stay until you revoke them.

Tell staff the rule in one sentence ("if a new app asks for access to email or files, send the request to me and I'll approve it within a day"), and the approval queue becomes your record of new AI tools. In the roofing contractor's first month under the rule, one request arrived: an estimator wanted an AI tool that turns roof photos into a written condition report. The owner checked the permission screen, saw it asked only for access to files it creates in Drive rather than the whole Drive, approved it and added it to the register. The whole exchange took ten minutes, and the estimator didn't have to hide anything. The broader set of checks before connecting anything is in the AI security checklist for email and files.

What breaks when you revoke, and how to avoid a Monday outage

Removing an app's access is instant and it breaks whatever the app was doing. A realistic mistake: an office manager revokes a scheduling tool that looked unfamiliar on a Friday evening. On Monday, the crew calendar has stopped showing new jobs, because that tool was what pushed bookings into Google Calendar. Nobody connected the two for half a day.

Three habits prevent it:

  1. Ask before removing anything with more than one user. A two-line message to the users is enough: "Do you use this? What for?"
  2. Revoke in the morning, midweek, so you can spot and fix breakage the same day.
  3. Note what each removal might affect in your sheet, and check it the next day.

If something does break, the fix is usually to reconnect the app with the right account (a shared office mailbox rather than a person) and mark it Trusted so it isn't caught in the next sweep.

Make it a quarterly 15-minute habit

The first audit is the long one. After that, a quarterly check takes about 15 minutes: open Accessed apps, compare it with last quarter's sheet, and deal only with new entries. Do an extra check whenever someone leaves, because their grants are the ones most likely to be forgotten; the staff offboarding checklist includes this step.

A simple register keeps each review honest. The roofing contractor's entry for one app read:

App:        E-signature tool
Users:      Office manager, owner
Services:   Drive (files it creates), Gmail (send signing requests)
Why:        Customers sign quotes online
Owner:      Office manager
Decision:   Keep - Trusted (reviewed 12 Mar)
Next check: June

Over a year that register becomes a record of every tool that has touched your customer data, which is useful for your own peace of mind and for any client or insurer who asks how you control access.

Further reads

Sources: Google Workspace Admin Help (control which third-party and internal apps access Google Workspace data); Google Account Help (manage links between your Google Account and apps from other developers); Microsoft Learn (review permissions granted to enterprise applications; configure how users consent to applications); Microsoft Support (edit or revoke application permissions in the My Apps portal).

Want your app permissions tidied properly?

On a 1:1 call we'll run the audit together on your Google or Microsoft account, decide which AI add-ons stay, and set the consent rules so the list stays short.

Book a 1:1 call with me