AI inventory

Grammarly

Grammarly · Writing · Confirmed · catalog grammarly. Seen by 2 lanes through 2 findings.

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Combined score
50
High 45 from the strongest lane + 5 for 1 more
People
1
Distinct identities across every lane
Seen by
2
Identity, Endpoint
First seen
Aug 12, 2026
Last seen Aug 12, 2026
identitygoogleworkspaceuser-consentedcorroborateddormantendpointbrowser-extension
Evidence

Where it was seen

Strongest finding →
IdentityGoogle Workspace (demo)
Medium45

0 sign-ins, 1 OAuth grants via Google Workspace (demo)

Assigned
0
Sign-ins
0
OAuth grants
1
Scope tier
High
1 person · Aug 12, 2026Open finding →
Endpoint
Medium45

3 devices, 0 accounts

Devices
3
Accounts
0
Processes
0
Extensions
1
Next steps

Recommended actions

  1. 01
    1 person authorized Grammarly against their Google account with scopes that expose files. Review it under Google Workspace API controls and mark it trusted, limited, or blocked; blocked revokes existing tokens.
    Identity
  2. 02
    Scopes expose files. Evaluate the vendor's retention and training terms before allowing continued use.
    Identity
  3. 03
    Grammarly was connected by users, not assigned by an admin. If it is approved, add it to the Workspace app catalog so access is managed and can be revoked at offboarding.
    Identity
  4. 04
    Nobody signed into Grammarly through Google in 90 days. Unassign or revoke to reduce standing access.
    Identity
  5. 05
    Grammarly runs as a browser extension on 3 devices and can read every page those users open, including webmail and internal apps. Manage it with the browser's ExtensionInstallBlocklist or allowlist policy.
    Endpoint
  6. 06
    Grammarly was seen only on endpoints, not in Entra or network discovery, so it may be used offline or from unmanaged networks. Check the device list for VPN gaps.
    Endpoint
Who

People

PersonDepartmentSourcesSeen bySign-ins · 30 d
n/a
Identity provider
Identity0
Vendor

Policy notes

Trains on data
No
Enterprise tier
Available
Org policy
None set

Reads every text field it is enabled in, including email and documents.

Exposure

Data it can reach

Files & sites
Lanes

Score by source

Each lane scores its own evidence. The combined score takes the strongest lane and adds five points per additional lane, capped at 100.