Findings by source

Grammarly

Google Workspace (demo) Grammarly · Writing · app name matches /^grammarly/

Policy · none set
Policy changes re-score this app on the next sync, which starts right away.
Finding · Open
Risk score
45
Medium
People
1
Assigned, signed in, or granted
OAuth grants
1
0 revoked · 90 days
Scope tier
High
4 scopes
identitygoogleworkspaceuser-consentedcorroborateddormant
Next steps

Recommended actions

  1. 011 person authorized Grammarly against their Google account with scopes that expose files. Review it under Google Workspace API controls and mark it trusted, limited, or blocked; blocked revokes existing tokens.
  2. 02Scopes expose files. Evaluate the vendor's retention and training terms before allowing continued use.
  3. 03Grammarly was connected by users, not assigned by an admin. If it is approved, add it to the Workspace app catalog so access is managed and can be revoked at offboarding.
  4. 04Nobody signed into Grammarly through Google in 90 days. Unassign or revoke to reduce standing access.
Google Workspace (demo) · google

Through the identity provider

Apps
Grammarly
Assigned0
Sign-ins0 by 0 people
OAuth grants1 authorized · 0 revoked
Scopes granted
ScopePeople
openid1
userinfo.email1
documents1
drive.readonly1
Same app, other lanes

Related findings

Who

People

Identifiers come from device telemetry and proxy logs, so they may be account names rather than full directory entries.

PersonDepartmentSourceSign-ins · 30 dGranted
n/aIdentity provider0No direct grant
Why

Evidence

  1. oauth_grants · Aug 12, 2026
    Google Workspace (demo): Grammarly, 1 OAuth grant (openid, userinfo.email, documents) in 90 days
    Detail
    {
      "appIds": [
        "2233445566-grammarly.apps.googleusercontent.com"
      ],
      "scopes": [
        {
          "scope": "openid",
          "users": 1
        },
        {
          "scope": "userinfo.email",
          "users": 1
        },
        {
          "scope": "documents",
          "users": 1
        },
        {
          "scope": "drive.readonly",
          "users": 1
        }
      ],
      "revoked": 0,
      "assignedUsers": 0
    }
  2. oauth_grant · Aug 12, 2026
    [email protected] authorized Grammarly: openid, userinfo.email, documents, drive.readonly
    Detail
    {
      "clientId": "2233445566-grammarly.apps.googleusercontent.com"
    }
  3. corroboration
    Also found by another lane (mde:grammarly)
    Detail
    {
      "findingKey": "mde:grammarly"
    }