SSPM, purpose-built for Google Workspace

See every OAuth app touching your Google Workspace

Every time someone clicks “Sign in with Google,” an app keeps a set of permissions that outlives whoever granted them. Spectyr finds those grants, scores what each one can actually reach, and revokes the ones that shouldn't be there. No agents, no browser extensions.

In development · waitlist members get first access at launch

Workspace scan — acme.com
Illustrative
87Connected apps
6High-risk grants
31Unused 90+ days

    Select an app to see the access it holds.

    Most tools tell you Slack is connected. Spectyr tells you it can read every file in Drive.

    Breaches involving a third party doubled last year, to 30%. Broad SSPM platforms check whether an app is connected. Spectyr reads the individual permissions behind each grant, because “see your email address” and “read and delete all mail” arrive through the same button.

    Verizon 2025 Data Breach Investigations Report, from 22,000 incidents and 12,195 confirmed breaches.

    How it works

    From connect to clean-up in three steps

    1 · Connect

    Authorize Spectyr through Google's own admin APIs. No agents to deploy, no extensions to push, nothing installed on user devices.

    2 · Scan

    Spectyr inventories every OAuth grant across your domain: which app, which users, which scopes. Scheduled scans keep that picture current.

    3 · Act

    Findings arrive ranked by scope-level risk. Revoke an over-permissioned or dormant grant in one click, and the change is recorded.

    What you get

    The Admin console shows you every app. It doesn't tell you which ones matter.

    Who granted it, and when

    App access control lists your connected apps and a count of users. Spectyr names the individual people behind each grant, when they authorized it, and whether the app has been used since.

    Scope-level risk scoring

    Google lists the scopes an app holds. It does not rank them, so 87 apps arrive as 87 equal rows. Spectyr scores each scope and orders the list, because reading a calendar and deleting every file in Drive are not the same risk.

    Revoke where you saw the problem

    Blocking an app domain-wide is one action in either tool. In Spectyr it happens on the screen that showed you why, and the change is recorded against the grant.

    Alerts when something changes

    Google can tell you a grant happened. Spectyr watches what happens after: an app that was Medium and is now Critical, a grant that widened the access it holds, a dormant app that started making calls again. You pick the level worth hearing about. Putting a threshold on a Google alert rule needs a premium edition.

    Blast radius

    A risk score tells you how dangerous an app’s access is. Blast radius answers the question after it: if this app’s token were stolen tomorrow, what would someone actually reach? Which mailboxes and drives, how many people are exposed, whether the app could grant itself more, and how far it could move from there.

    Wysper, the Spectyr scanner

    Why Google first

    Why Google Workspace first

    Your email, your documents and your single sign-on all sit behind one Google login, and every OAuth grant is a door into it. Reading those grants properly means working in Google's own scope model rather than flattening it into something generic, which is why Spectyr starts here and goes deep before it goes wide. Per-scope scoring and domain-wide revocation are what that buys you.

    FAQ

    Common questions

    If something here is unclear, reply to the waitlist email and ask.

    What is SSPM?

    SaaS Security Posture Management: tooling that continuously finds and fixes risky configurations and third-party access in your SaaS platforms. Spectyr is an SSPM built around Google Workspace, starting with the OAuth grants in it.

    Why do OAuth apps in Google Workspace matter?

    Accepting that prompt hands the app standing access to whatever it asked for: mail, Drive files, contacts. The access does not expire when the person stops using the app, or when they leave. Most organizations carry dozens of grants nobody remembers approving.

    How does Spectyr get its data?

    Through Google Workspace's official admin APIs, authorized by your admin. Nothing is installed on user devices and users see no prompts.

    How is Spectyr different from other SSPM platforms?

    Breadth-first platforms cover hundreds of SaaS apps shallowly. Spectyr works at the depth of individual OAuth scopes, which is the level at which you can actually decide whether a grant should stay. Google Workspace is where that starts.

    When can I use Spectyr?

    Spectyr is in development. Join the waitlist and you'll get access in the first wave of the beta.

    Find out what's connected to your workspace

    Join the waitlist for early access. We'll email you once, when it opens.

    Join the waitlist