Home
IT Hub
AI

How to Audit and Revoke OAuth Scopes for AI Apps

Reco Security Experts
Updated
September 25, 2026
September 25, 2026
8 min read

Authorizing an AI tool through Google or Microsoft takes seconds. The OAuth grant may stay active long after the session ends, letting the app request new access tokens without another sign-in.

‍

Risk can grow as tools add integrations, request broader scopes, and gain users. If an attacker steals a token, they inherit its access. In August 2025, stolen OAuth tokens from the Salesloft Drift integration exposed customer environments across more than 700 organizations, according to FINRA's alert on the incident.

‍

This article explains how to use Reco to find connected AI apps, assess their scopes, choose the right response, complete revocation, and verify the result.

‍

Step 1: Identify AI Apps With OAuth Access

‍

Use Reco's AI Discovery inventory to identify connected AI tools. It refreshes daily.

‍

Navigate to Apps → AI Apps

AI Discovery dashboard listing 1,387 AI apps, with usage, vendor ranks, discovery methods, and authorization statuses.

The page lists every AI app in use across the organization. Review Users, Discovery Method, and Authorization to see how widely each tool is used, how it was found, and whether it was approved.

‍

For the complete discovery workflow, see Reco's guide to setting up AI Discovery.

‍

Export the list and prioritize unsanctioned tools with broad adoption or OAuth access.

‍

Step 2: Review the OAuth Scope Landscape

‍

Navigate to Apps → SaaS-to-SaaS

‍

Use Charts to scan high-risk scope counts, Table to compare apps and permissions, and Graph to trace connections between apps and plugins.

Prioritize sensitive data exposure and powerful permissions, not scope count alone.

‍

Step 3: Classify Each Scope by Risk

‍

Assess each scope's capabilities, data reach, persistence, and business purpose. Google scope names below are shortened except for the full-mail scope.

In Reco, search for an AI plugin in the Table view and group by Scope to see each permission it holds and what it allows.

SaaS-to-SaaS Scopes dashboard showing ChatGPT-related app permissions, including file, site, user, alarm, and bookmark access.
Scope Type Example Scope What It Allows Review Action
Read Access gmail.readonly Read mailbox messages and settings Confirm need for mailbox-wide access
Write Access gmail.modify Read, send, and modify mail Restrict unless essential
Delete Access https://mail.google.com/ Full mail access, including permanent deletion Require explicit justification
Broad File Access drive.readonly Read and download accessible Drive files Prefer drive.file when the app can use selected files
Offline Access offline_access (Microsoft) Request refresh tokens for ongoing access Review alongside the data scopes

‍

Read-only can still expose sensitive data. Check Google's Gmail and Drive scope references and Microsoft's offline_access documentation for exact capabilities.

‍

Reco's AI Permission Sprawl Remediation distinguishes between permissions granted and actively used. An unused scope may be a strong candidate for removal.

‍

Step 4: Investigate and Choose a Response

‍

Review the publisher, authorizing identity, plugins, data sources, approval status, and owner. Delegated permissions operate within the user's access; application permissions can operate without a signed-in user.

‍

Cross-check owners against your offboarding workflow. OAuth grants and automated workflows can survive the departure of the employee who created them.

‍

Finding What to Check Action
Unsanctioned app with high-risk scopes Affected users and data Revoke access; investigate prior activity
Approved app with unnecessary scopes Actual usage and business purpose Reduce access; test required functions
Approved app with justified scopes Owner and documented need Retain; record approval and review date
Unknown publisher Vendor identity and accountability Validate; revoke if trust cannot be established
New plugin or broader scopes Changed permissions and data reach Restrict pending assessment and reapproval
Abandoned integration Current owner and continuing need Reassign with approval or revoke

‍

Some platforms cannot remove a single scope from an existing grant. Reduction may require changing the app's requested permissions, revoking the grant, and collecting fresh consent.

‍

Step 5: Revoke or Restrict Access

‍

Before revoking, confirm the owner, dependent agents and workflows, and replacement credentials. Capture the app, OAuth client ID, authorizing identity, and scopes in Reco, then act in the source platform.

‍

Platform Where to Act Available Response
Google Workspace Admin console → Security → Access and data control → API controls → Manage Third-Party App Access Choose Blocked to deny access, or Limited to restrict it to unrestricted services
Microsoft Entra Entra admin center → Entra ID → Enterprise apps → All applications → App → Permissions Admin consent → select permission → … → Revoke permission

‍

Google's Limited setting is not full revocation. In Entra, the portal revokes admin consent; use Microsoft Graph or PowerShell for user consent permissions.

Revocation should be paired with consent controls. Otherwise, a user may authorize the application again later.

‍

Record the change and timestamp, then update the app's authorization status in Reco.

‍

Step 6: Verify That Revocation Succeeded

  • Confirm the targeted grant is removed or the intended access restriction is enforced.
  • Test that the app can no longer perform the prohibited access.
  • Review activity after the remediation timestamp for signs of continued access.
  • Record the action, owner, reason, and timestamp for audit evidence.

Previously issued access tokens may remain valid until expiry. Check post-change activity through the applicable token lifetime; a configuration change alone is not proof of access removal.

‍

Step 7: Monitor for OAuth Scope Drift

‍

Use Reco's SaaS-to-SaaS view to review new plugins and permission changes across approved and unsanctioned apps. Test relevant detection policies in Preview before enabling them.

‍

Suggested Review Schedule

‍

Task Suggested Frequency What to Check
Review Newly Connected AI Apps Weekly New OAuth grants and unsanctioned tools
Review High-Risk Scopes Monthly Excessive or unnecessary permissions
Review Plugins and Publishers Monthly New integrations and unknown vendors
Revalidate Business Ownership Quarterly Abandoned or ownerless connections
Review Revoked Connections After revocation; monitor for reconnection Successful access or renewed grants

‍

Use this schedule as a starting point; adjust it to data sensitivity and review material changes when they occur.

‍

Conclusion

‍

Use Reco to identify and assess AI app permissions, then remove unnecessary access at the source. Close each finding only after verification, and reopen the review when permissions or ownership change.

No items found.
EXPERIENCE RECO 1:1 - BOOK A DEMO

Discover How Reco Can Help You Protect Your AI Environment

“I’ve looked at other tools in this space and Reco is the best choice based on use cases I had and their dedication to success of our program. I always recommend Reco to my friends and associates, and would recommend it to anyone looking to get their arms around shadow IT and implement effective SaaS security.”
Mike D'Arezzo
Executive Director of Security
“We decided to invest in SaaS Security over other more traditional types of security because of the growth of SaaS that empowers our business to be able to operate the way that it does. It’s just something that can’t be ignored anymore or put off.”
Aaron Ansari
CISO
“With Reco, our posture score has gone from 55% to 67% in 30 days and more improvements to come in 7-10 days. We are having a separate internal session with our ServiceNow admin to address these posture checks.”
Jen Langford
Information Security & Compliance Analyst
“That's a huge differentiator compared to the rest of the players in the space. And because most of the time when you ask for integrations for a solution, they'll say we'll add it to our roadmap, maybe next year. Whereas Reco is very adaptable. They add new integrations quickly, including integrations we've requested.”
Kyle Kurdziolek
Head of Security

Explore More

Your agents are already running. Do you know what they're doing?

Request a demo