OAuth grants, the AI you never installed

Which third-party AI tools hold live access into your Google Workspace or Microsoft 365, and how to cut them off.

An employee tries an AI notetaker. It asks for calendar and Drive access. They click Allow, and a third party holds a live token into your systems. Nothing was installed, so no endpoint scan will find it.

Oversight → Registry → Grants lists every third-party app with access to your tenant and marks the AI ones.

Accept the list as it stands today, in one click. After that the screen stays quiet and speaks only when an app you approved gains a permission it did not have before.

Revoking is an Enterprise capability.

Connecting is a read-only sign-in with your own identity provider. Damn never sees your password. If you keep the tenant watched, so that it re-scans and can tell you about a change, your provider issues a renewal token that is encrypted with this workspace's own key and stored on your server. It never leaves it, it only ever reads, and stop watching deletes it. Untick that and nothing is stored, but nothing checks in between either, so a change waits until somebody signs in again.

This is a record, not a control. It tells you what an app is authorised to reach, never what it read. Revoking stops future access and does not undo what was already read.