1. Connect
Sign in with Google and grant read-only Drive metadata access. The app requests no file-content or permission-write scope.
Read-only, install-forward evidence for changes in external access to files visible to one Google account.
Sign in with Google and grant read-only Drive metadata access. The app requests no file-content or permission-write scope.
Run a bounded scan. Up to 1,000 files visible to the connected account are checked through paginated Drive permission requests. The first result is the honest baseline.
Later scans show added and removed external users, groups, domains, and anyone-link access. Export the exact change set as a signed CSV or PDF receipt.
This is not a whole-domain audit. The app does not impersonate coworkers, use domain-wide delegation, or inspect files the connected account cannot see. A scan that reaches its 1,000-file cap is labelled partial instead of silently claiming completion.
Drive file content is never requested or downloaded. File names and external grantee labels are encrypted. Stable HMAC fingerprints are used to compare snapshots without storing raw file or permission identifiers. Receipt links are signed and short-lived.
Paid installations can run weekly scheduled checks and manual scans, up to 12 scans per month. Evidence is retained for up to 365 days while the installation remains active.
$7 per connected Google account per month after a 14-day trial. Billing is handled through Stripe. Cancel through the billing portal before deleting the app ledger.
Deletion asks Google to revoke the refresh token and removes encrypted credentials, permission snapshots, receipts, sessions, and billing identifiers held by Cazimedia. It never changes Drive permissions.
Support: [email protected]