Think about how many apps and tools your team has connected to Google Workspace over the past few years. A project management tool here. An email automation platform there. A scheduling app, a survey tool, a document signing service. Each one was connected because someone needed it for something.

That App You Connected to Google Workspace Two Years Ago Could Still Have Access to Everything

Now think about how many of those connections were ever reviewed or removed when they were no longer needed.

For most businesses, the honest answer is none of them. And that is a bigger security problem than most people realize.

How Third-Party App Access Works

When an employee connects a third-party app to Google Workspace, they grant that app permission to access parts of their Google account. Depending on what they agreed to during setup, that access can include reading and sending email, accessing files in Google Drive, viewing contacts, managing calendar events, and more.

This access is granted through a standard authorization system called OAuth. When you see a screen that says "This app would like to access your Google account" and click Allow, you are creating a connection that stays active indefinitely unless someone specifically revokes it.

The connection does not expire when the employee stops using the app. It does not expire when the employee leaves the company. It does not expire when the app's vendor is acquired or gets compromised. It simply stays active, with whatever access was originally granted, until someone removes it.

Why Forgotten Access Becomes a Breach Path

An attacker who compromises a third-party app that has OAuth access to a Google Workspace environment does not need to steal a password or bypass multi-factor authentication. They already have a valid, authorized path into the organization's email, files, and contacts. From Google's side, that access looks completely legitimate — because technically, it is.

Real-world Google Workspace breaches have been traced back to exactly this pattern. The breach did not require defeating any obvious security control. It required finding an app integration that had been forgotten, was still active, and had permissions broad enough to access sensitive business data.

The risk compounds in situations that are common in most businesses. An employee who left the company may have had app connections tied to their account that were never revoked during offboarding. An app connected for a short-term project may still have full access to email and Drive long after the project ended. And many apps request more access than they actually need because employees click through the permission screen without reviewing what they are granting.

What Your Team Should Do Right Now

The first step is finding out what is actually connected. In the Google Workspace Admin Console, go to Security, then API Controls, then App Access Control. This shows every connected app, what permissions it holds, and how it was authorized. Individual users can also review their own connected apps at myaccount.google.com under Third-party apps with account access.

Once you have visibility, remove any app that is no longer actively used or whose purpose you cannot identify. Pay particular attention to anything with access to read or send email, or broad access to Google Drive.

Update your offboarding process. When an employee leaves, revoking connected app access should be a specific step alongside disabling their account. And going forward, employees should not be connecting apps with broad Google Workspace permissions without IT review and approval.

Every third-party app connected to Google Workspace is a door. Most were opened for a good reason. The problem is that nobody closed them when the reason went away. Auditing what has access, removing what no longer belongs, and controlling future connections are straightforward steps that directly reduce your exposure. The access that leads to a breach is often the access nobody remembered granting.