New
Platform overview

Govern SaaS access, AI agents, and Shadow IT from one operational platform.

ThreatLynx discovers third-party applications connected to your Google Workspace and Microsoft 365 tenants via OAuth, classifies permission exposure, scores risk across five explainable dimensions, and provides governance workflows with an audit trail your security, risk, and compliance teams can rely on.

Agentless
OAuth API only — no endpoint software.
Read-only
Never writes to your tenant data.
AU resident
Security telemetry stored in AWS Sydney · ap-southeast-2.
Explainable
Every score traceable to its inputs.
app.threatlynx.com.au/discovery
Production · AWS Sydney
⌘K
Discovered SaaS
1,248
↑ 12 this week
High-risk apps
34
needs review
OAuth permissions
8,592
across 4 tenants
Posture · E8
92%
aligned
Shadow IT discovery · past 30 days
+ 41 new apps · 6 newly classified high-risk
7d30d90d
Applications· 1,248
Source: Google WorkspaceLast sync 4m ago
ApplicationCategoryUsersScopesRiskStatusFirst seen
N
Notion AI
notion.so
AI · Productivity14214
78
ReviewOct 04
L
Loom
loom.com
Video868
42
ApprovedAug 22
O
Otter.ai
otter.ai
AI · Transcription3811
71
ReviewSep 18
G
Grammarly
grammarly.com
AI · Writing2119
64
ApprovedApr 01
F
Figma
figma.com
Design645
28
ApprovedFeb 11
Z
Zapier
zapier.com
Automation1217
81
BlockedJun 09
Live demo · sample tenant · Globalcorp Pty LtdSwitch tabs → to explore
The platform

Four surfaces. One inventory of truth.

Built for security operations, IT administration, and compliance teams that need operational visibility without endpoint agents to maintain.

SaaS Discovery

Continuous OAuth-grant discovery across Google Workspace and Microsoft 365. Captures every authorised third-party application in your tenant — sanctioned or not — without installing software on a single endpoint.

OAuth Intelligence

Scope-level permission visibility down to read / write / delete. Understand exactly what each connected application can access across Gmail, Drive, Calendar, Contacts, and Admin Directory — before a governance decision is made.

Risk Scoring

Rules-based composite scoring across OAuth permission sensitivity, data exposure breadth, user count, vendor jurisdiction, AI indicators, and governance status. Every score is fully explainable — no black-box AI output.

Governance Workflows

Approve, restrict, or block connected applications through a structured lifecycle. Assign owners, document decisions, and produce an append-only audit trail with actor, action, timestamp, and rationale for every governance event.

Compliance Readiness

Rules-based framework references for Essential Eight (ML2), APRA CPS 234, Australian Privacy Act, and ISO 27001. Governance evidence exports support audit preparation and internal review cycles. Not legal certification.

AI & Agent Governance

Identifies likely AI tools, service principals, MCP-connected systems, automation platforms, and copilot integrations using OAuth metadata and vendor patterns. Governance visibility for non-human identities operating in your tenant.

How it works

A five-stage governance lifecycle.

From OAuth grant detection to audit-ready evidence export — each stage produces a documented, traceable record.

01
Discover

OAuth grant records are read from Google Workspace Admin SDK and Microsoft Graph. Every connected application, scope, and user authorisation is captured without touching endpoint devices.

Inventory timestamp recorded per sync run.
02
Classify

Each application receives a composite risk score across five dimensions. AI tool indicators, vendor jurisdiction, and governance status are applied as scoring inputs alongside permission data.

Score contributors stored per application per assessment.
03
Review

Security and IT teams triage applications by risk score, category, or scope. Applications without a governance decision are flagged Under Review. Owners are assigned for accountability.

Review actions attributed to named users with timestamps.
04
Govern

Governance decisions — Approved, Restricted, or Blocked — are recorded against each application. Policy-driven automation can apply decisions to matching application categories automatically.

Decision, actor, rationale, and policy reference logged to append-only trail.
05
Export evidence

Point-in-time inventory exports, governance decision logs, and audit trails can be exported as structured evidence for access reviews, regulator requests, or internal audit cycles.

Exports include inventory hash, export timestamp, and review context.
AI & agent governance

Non-human identities in your tenant.

AI tools, service principals, MCP-connected systems, and automation platforms operate with OAuth access to your organisation's data — often without a governance record. ThreatLynx provides visibility into these identities based on OAuth metadata and vendor pattern analysis.

Metadata-based detection
Identification uses OAuth grant records and vendor name patterns — not content inspection or endpoint monitoring.
No employee surveillance
ThreatLynx does not monitor individual user behaviour, keystrokes, or application usage patterns.
Governance-focused
The goal is a documented governance record for non-human identities — not automated blocking without review.
ThreatLynx identifies likely non-human identities and AI-connected systems using SaaS metadata and OAuth permission analysis. Detection confidence may vary by provider and configuration.
AI writing and productivity tools
NHI
e.g. Grammarly, Notion AI, Otter.ai, Jasper
Identified via OAuth metadata and vendor name matching. Typically hold mail-read or document-access scopes.
AI assistant copilots
NHI
e.g. ChatGPT plugins, Microsoft Copilot extensions, Gemini workspace integrations
Broad-scope AI assistants integrated into workspace environments. Flagged as higher-sensitivity based on scope breadth.
Automation and workflow platforms
NHI
e.g. Zapier, Make (Integromat), n8n
Multi-user, multi-scope integrations. Frequently hold cross-service permissions that amplify exposure if misconfigured.
Service principals (M365)
NHI
e.g. Azure AD enterprise apps, registered applications, managed identities
Non-human identities with application-level delegated permissions. Discovered via Microsoft Graph enterprise application records.
MCP-connected systems
NHI
e.g. Model Context Protocol integrations, LLM tool-use frameworks
Identified via vendor patterns in OAuth client metadata. Detection confidence varies by provider — review by application owners is recommended.
Autonomous integration identities
NHI
e.g. Apps with broad scopes, no single user owner, persistent delegated access
Flagged based on OAuth grant characteristics: service-level authorisation, admin-delegated access, or unusual scope combinations.
Compliance readiness

Governance evidence your auditors can work with.

ThreatLynx provides rules-based framework references and structured evidence exports to support audit preparation for Australian regulated sectors — financial services, healthcare, and government.

Point-in-time inventory snapshots with export timestamps
Governance decision log with actor attribution
OAuth scope inventory per application
Framework-referenced evidence packages
Append-only audit trail for regulatory review
ThreatLynx supports governance readiness and evidence management. It does not provide legal certification or regulatory accreditation. Framework references are rules-based operational mappings — they do not constitute compliance certification or legal advice.
Framework alignment
Full mapping pack
BodyFrameworkAlignmentCoverage
ASD / ACSCEssential EightML2 App ControlDirect
APRACPS 234Asset register · third-partySupports
OAICPrivacy Act · APP 8, 11PII exposure surfaceSupports
ISO/IEC27001:2022 Annex AA.8 Assets · A.9 AccessSupports
DTAHosting StrategyAU sovereigntySupports
References support governance readiness. They do not certify compliance or constitute legal accreditation.
Platform architecture

How ThreatLynx connects to your environment.

A read-only API connection to your identity provider is the only integration required. No agents, no proxies, no changes to your workspace configuration.

1Sources
Google Workspace
Available
Admin SDK · Domain-wide delegation
Microsoft 365
Available
Microsoft Graph · Enterprise applications
2Connection
OAuth Admin APIs
Read-only token · No write access
Microsoft Graph
Service principal auth · Delegated permissions
3Engine
Discovery engine
Grant capture · Sync runs · Delta detection
Risk scoring
Rules-based · 5-dimension composite · Explainable
Governance layer
Policy engine · Decision lifecycle · Owner tracking
4Outputs
SaaS inventory
Live · Exportable · Point-in-time snapshots
Audit log
Append-only · Actor-attributed · Timestamped
Evidence exports
Structured · Framework-referenced · Audit-ready
Authentication
Service account (Google) or service principal (M365). OAuth 2.0 only. No user credentials stored.
Data residency
Customer security telemetry is stored in Australia (AWS Sydney, ap-southeast-2); some processing uses named US subprocessors (email, billing).
Access scope
Read-only OAuth API access. ThreatLynx does not write to, modify, or delete tenant data or configuration.

Visibility is only the first step. Governance is what matters.

Book a demo to see ThreatLynx running against a sample tenant, or contact our security team to discuss your organisation's governance requirements.