Govern the SaaS
your enterprise didn't
know it was running.
ThreatLynx helps discover third-party applications connected to your Google Workspace and Microsoft 365 tenants via OAuth, scores them against framework-grade criteria, and gives security teams an audit trail their regulators can review.
| Application | Category | Users | Scopes | Risk | Status | First seen |
|---|---|---|---|---|---|---|
N Notion AI notion.so | AI · Productivity | 142 | 14 | 78 | Review | Oct 04 |
L Loom loom.com | Video | 86 | 8 | 42 | Approved | Aug 22 |
O Otter.ai otter.ai | AI · Transcription | 38 | 11 | 71 | Review | Sep 18 |
G Grammarly grammarly.com | AI · Writing | 211 | 9 | 64 | Approved | Apr 01 |
F Figma figma.com | Design | 64 | 5 | 28 | Approved | Feb 11 |
Z Zapier zapier.com | Automation | 12 | 17 | 81 | Blocked | Jun 09 |
Shadow IT visibility — without an agent on a single endpoint.
Four product surfaces working from one inventory of truth. Built for security and IT teams that need operational visibility, not another endpoint to patch.
See every third-party application — sanctioned or not.
Continuous SaaS discovery runs as new OAuth grants are issued. Inventory connected vendors, the users who authorised them, and the scopes they granted. ThreatLynx helps identify connected applications as they appear in your tenant.
- 01OAuth-grant capture across Workspace and M365
- 02User-by-user authorisation history with timestamps
- 03Domain, category, vendor domicile, and prior-seen flags
| Application | Category | Users | Scopes | Risk | Status | First seen |
|---|---|---|---|---|---|---|
N Notion AI notion.so | AI · Productivity | 142 | 14 | 78 | Review | Oct 04 |
L Loom loom.com | Video | 86 | 8 | 42 | Approved | Aug 22 |
O Otter.ai otter.ai | AI · Transcription | 38 | 11 | 71 | Review | Sep 18 |
G Grammarly grammarly.com | AI · Writing | 211 | 9 | 64 | Approved | Apr 01 |
F Figma figma.com | Design | 64 | 5 | 28 | Approved | Feb 11 |
Z Zapier zapier.com | Automation | 12 | 17 | 81 | Blocked | Jun 09 |
A risk model your auditor can read.
Every discovered app receives a composite score across four explicit dimensions — data breadth, permission sensitivity, vendor domicile, and affected user count. No black-box AI label. Every score is fully explainable from the inputs.
- 01Composite score 0–100 with per-dimension contributors
- 02Tunable thresholds — your tolerance, your policy
- 03Per-vendor history — see how risk has shifted over time
| # | Application | Composite | Data breadth | Sensitivity | Domicile | Exposure |
|---|---|---|---|---|---|---|
| 01 | Zapier | 81 | 73 | 69 | US | 12 users |
| 02 | Notion AI | 78 | 70 | 66 | US | 142 users |
| 03 | Otter.ai | 71 | 64 | 60 | US | 38 users |
| 04 | Grammarly | 64 | 58 | 54 | US | 211 users |
| 05 | Miro | 47 | 42 | 40 | NL | 92 users |
| 06 | Loom | 42 | 38 | 36 | US | 86 users |
| 07 | Calendly | 35 | 32 | 30 | US | 174 users |
Permission visibility down to the scope.
See exactly what each connected app can read, write, or delete — Gmail, Drive, Calendar, Contacts, and Admin Directory. Triage by impact and revoke high-risk grants without leaving the console.
- 01Scope-level read / write / delete breakdown
- 02Sensitivity classification (Standard, Restricted, Admin)
- 03One-click revocation routed through the OAuth API
| Service | Scope | Read | Write | Delete | Grants |
|---|---|---|---|---|---|
| Gmail | gmail.readonly | 142 | |||
| Drive | drive.file | 142 | |||
| Drive | drive.metadata | 142 | |||
| Calendar | calendar.events | 142 | |||
| Admin | admin.directory.user | 4 | |||
| Contacts | contacts.readonly | 142 |
Approve, restrict, or block — with the audit trail to prove it.
Codify your governance posture as policies. Assign owners, document decisions, and let ThreatLynx record every action against every application, automatically. Export point-in-time evidence for access reviews and regulator requests.
- 01Approve / Review / Block with assigned owners
- 02Policy-driven automation for predictable enforcement
- 03Audit trail with actor, action, timestamp, and rationale
| Policy | Scope | Owner | 7d triggers | Status | |
|---|---|---|---|---|---|
| Block apps with admin.directory.* write | OAuth scopes | S. Patel | 12 | Active | › |
| Require review for AI tools with PII access | Category · AI | M. Chen | 8 | Active | › |
| Auto-approve apps with vendor SOC 2 + region AU | Vendor posture | Auto | 24 | Active | › |
| Notify owner on new high-risk discovery | Risk ≥ 70 | Auto | 6 | Active | › |
Built for Australian regulated sectors.
ThreatLynx provides governance visibility and evidence workflows relevant to financial services, healthcare, and government environments. Framework mappings are rules-based references to support governance readiness — not compliance certification.
Operational in under ten minutes.
No infrastructure changes. No endpoint software. No procurement gauntlet. Just an OAuth authorisation and an inventory waiting on the other side.
Authorise — read-only
Sign in as a Workspace or M365 administrator and authorise ThreatLynx via OAuth. We request a scoped, read-only token. No agents, no proxies, no changes to tenant configuration.
Discovery runs automatically
ThreatLynx maps every connected application, permission scope, and affected user. Your full SaaS inventory — including apps IT didn't know existed — is available within minutes.
Review, govern, evidence
Triage by composite risk, record governance decisions against each application, and export point-in-time evidence packs for stakeholders, access reviews, and regulators.
Organisation-size pricing — never per seat.
Predictable platform pricing based on organisational complexity and risk exposure. All amounts in Australian Dollars, excluding GST. Regulated or multi-entity organisations should contact us for a tailored proposal.
Operating under APRA, IRAP, or residency obligations?
We work directly with financial services, healthcare, and government teams to scope deployments around APRA CPS 234 obligations, IRAP assessment support, Australian data residency, and SIEM forwarding.