Govern SaaS access, AI agents, and Shadow IT from one operational platform.
ThreatLynx discovers third-party applications connected to your Google Workspace and Microsoft 365 tenants via OAuth, classifies permission exposure, scores risk across five explainable dimensions, and provides governance workflows with an audit trail your security, risk, and compliance teams can rely on.
| Application | Category | Users | Scopes | Risk | Status | First seen |
|---|---|---|---|---|---|---|
N Notion AI notion.so | AI · Productivity | 142 | 14 | 78 | Review | Oct 04 |
L Loom loom.com | Video | 86 | 8 | 42 | Approved | Aug 22 |
O Otter.ai otter.ai | AI · Transcription | 38 | 11 | 71 | Review | Sep 18 |
G Grammarly grammarly.com | AI · Writing | 211 | 9 | 64 | Approved | Apr 01 |
F Figma figma.com | Design | 64 | 5 | 28 | Approved | Feb 11 |
Z Zapier zapier.com | Automation | 12 | 17 | 81 | Blocked | Jun 09 |
Four surfaces. One inventory of truth.
Built for security operations, IT administration, and compliance teams that need operational visibility without endpoint agents to maintain.
Continuous OAuth-grant discovery across Google Workspace and Microsoft 365. Captures every authorised third-party application in your tenant — sanctioned or not — without installing software on a single endpoint.
Scope-level permission visibility down to read / write / delete. Understand exactly what each connected application can access across Gmail, Drive, Calendar, Contacts, and Admin Directory — before a governance decision is made.
Rules-based composite scoring across OAuth permission sensitivity, data exposure breadth, user count, vendor jurisdiction, AI indicators, and governance status. Every score is fully explainable — no black-box AI output.
Approve, restrict, or block connected applications through a structured lifecycle. Assign owners, document decisions, and produce an append-only audit trail with actor, action, timestamp, and rationale for every governance event.
Rules-based framework references for Essential Eight (ML2), APRA CPS 234, Australian Privacy Act, and ISO 27001. Governance evidence exports support audit preparation and internal review cycles. Not legal certification.
Identifies likely AI tools, service principals, MCP-connected systems, automation platforms, and copilot integrations using OAuth metadata and vendor patterns. Governance visibility for non-human identities operating in your tenant.
A five-stage governance lifecycle.
From OAuth grant detection to audit-ready evidence export — each stage produces a documented, traceable record.
OAuth grant records are read from Google Workspace Admin SDK and Microsoft Graph. Every connected application, scope, and user authorisation is captured without touching endpoint devices.
Each application receives a composite risk score across five dimensions. AI tool indicators, vendor jurisdiction, and governance status are applied as scoring inputs alongside permission data.
Security and IT teams triage applications by risk score, category, or scope. Applications without a governance decision are flagged Under Review. Owners are assigned for accountability.
Governance decisions — Approved, Restricted, or Blocked — are recorded against each application. Policy-driven automation can apply decisions to matching application categories automatically.
Point-in-time inventory exports, governance decision logs, and audit trails can be exported as structured evidence for access reviews, regulator requests, or internal audit cycles.
Non-human identities in your tenant.
AI tools, service principals, MCP-connected systems, and automation platforms operate with OAuth access to your organisation's data — often without a governance record. ThreatLynx provides visibility into these identities based on OAuth metadata and vendor pattern analysis.
Governance evidence your auditors can work with.
ThreatLynx provides rules-based framework references and structured evidence exports to support audit preparation for Australian regulated sectors — financial services, healthcare, and government.
How ThreatLynx connects to your environment.
A read-only API connection to your identity provider is the only integration required. No agents, no proxies, no changes to your workspace configuration.
Visibility is only the first step. Governance is what matters.
Book a demo to see ThreatLynx running against a sample tenant, or contact our security team to discuss your organisation's governance requirements.