Use case · OAuth apps

Every OAuth grant to an AI tool is standing access. See where it leads.

When an employee connects an AI tool to Google Workspace, Microsoft 365, Salesforce, GitHub or Slack, the tool receives a token with its own scopes and lifetime. It does not need a password, it survives password changes and it is rarely reviewed again.

Unreviewed2+
ai-notetaker
Google Workspace
mail.read, drive
dana.reyes
Connected by 1 userNever
slide-generator
Microsoft 365
files.read
3 users
Connected by 3 users14d
Broad scopes2+
crm-enricher
Salesforce
crm.export
tomas.okafor
Full export2d
repo-assistant
GitHub
repo, admin:org
platform team
Org admin6d
No owner2+
sales-assistant
Slack
channels:history
Left the company
Offboarded owner41d
meeting-summarizer
Google Workspace
calendar
Unassigned
14 users9d
Scoped2+
translation-tool
Google Workspace
drive.file
priya.nair
Single files1d
survey-bot
Microsoft 365
forms.read
mara.kowalski
Read only3d
THE PROBLEM

Why OAuth grants are an attack path

Two well documented breaches followed this route. In the Salesloft Drift breach, stolen OAuth tokens gave attackers Salesforce data within the grants' permissions, and the exports contained further credentials. In the Vercel breach, a token granted to an AI analytics tool led to a Google Workspace account, internal systems and customer secrets. Every step used access that had been granted on purpose.

Vercel breach
AI analytics tool
The vendor is breached
OAuth token
Granted to the tool on purpose
Google Workspace account
Signed in with the token
Internal systems
Reached from the account
Critical
Customer secrets
The end of the path
Read the teardown
WHAT ELMOZ SHOWS

What Elmoz shows for OAuth and SaaS integrations

Third-party apps 38
ai-notetakerConnected by 1 userAI tool
meeting-summarizerConnected by 14 usersAI tool
sales-assistantSlack workspaceAI tool
slide-generatorConnected by 3 usersAI tool
Scopes
ai-notetakermail.read · driveMailFiles
meeting-summarizercalendarCalendar
crm-enrichercrm.exportExport
repo-assistantrepo, admin:orgAdmin
Grant owners
ai-notetakerdana.reyesOwned
slide-generatorLeft the companyOffboarded
crm-enricherNo ownerUnassigned
ai notetakerConnected by one employee
oauth grantMail and drive scopes
workspaceAccount with internal tools
secretsCredentials in shared docsCritical
slide-generatorLow · 1 file scope→
meeting-summarizerMedium · calendar→
ai-notetaker● Critical · reaches secrets→
crm-enricherHigh · crm.export→
sales-assistantMedium · channels→

An example path

A grant, a user account and a shared document. Each step is legitimate. Together they are a path Elmoz can trace and rank.

Security GraphFocus: ai-notetakerAll assetsIdentitiesData stores
ATTACK PATH8 entities · 3 access steps
ai-notetakerAI tool · OAuth app!OAuth grantMail and Drive scopesRefresh tokenNo expiry2dana.reyesWorkspace accountWorkspace tenantProductionSSO appsInternal tools!Shared drivesRead access3Findings3 issuesRunbooksShared documentsAPI keysData findingPII/EmailData finding
FAQ

Questions, answered.

Short answers on OAuth grants to AI tools and how to review them.

Are OAuth apps a security risk?

They can be. An OAuth grant is standing access that does not need a password and usually does not trigger MFA. If the vendor behind the app is breached, the attacker can use the grant within its scopes.

How do I review OAuth grants to AI tools?

In Google Workspace use the third-party app access page in the Admin Console, in Microsoft Entra the enterprise applications and user consents. Check scopes, owners and last use, and revoke apps nobody uses.

What does Elmoz add to an OAuth app list?

It connects each grant to what it can reach through the user account and further systems, so you can see which grants would lead to sensitive data if the vendor were compromised.

See what your agents can reach. Before someone else does.

Book a demo and we walk through the access paths in an environment like yours.