← Blue Lantern Security

Monitor AI Exposure: Which AI Apps Can Reach Your Company Data

Blue Lantern Security's AI exposure scan runs once a day and inventories the third-party apps your users have connected to Google Workspace or Microsoft 365. It identifies which of them are AI tools, how far their permissions reach (mail, files, and calendars versus sign-in only), which are unverified apps holding data scopes, and which grants are new since the last scan. You get the list insurers and customers have started asking for, without reading a single message or file.

Enable AI exposure monitoring

Access: included with the Gmail or Microsoft 365 organization integration on a Seat License at $15 per monitored user per month. Enable it with a checkbox in the integration's settings; it runs once daily and reads grant metadata only. See current pricing.

An employee connects an AI assistant to help with one document. The permission it asked for may cover every document they can open, plus their mail and calendar, and it keeps that access after the task is done. Multiply that by a team and a year of experiments, and nobody knows what can reach the company's data. The scan answers that question every morning.

What does the AI exposure scan report?

Question How the scan answers it
Which apps have access? Every third-party OAuth app with a grant in your organization, listed by app identity
Which of them are AI tools? A curated catalog of known AI applications plus name heuristics
How far does the access reach? Scope classification: mail, files, and calendar access versus sign-in only
Is the publisher verified? On Microsoft 365, unverified apps holding data scopes are flagged. That combination is the classic OAuth-phishing shape
Who granted it? On Microsoft 365, whether a grant belongs to a single user or applies across the tenant. On Google Workspace, per-user grants are rolled up into counts per app
What is new? After the first baseline scan, newly appearing risky apps are highlighted and can trigger alert rules on the AI Exposure run type

Flagged apps become check rows in the report, and an AI exposure section appears in your attestation report alongside device, identity, and mail posture results.

How does it work on each platform?

Platform What is read Permission required
Google Workspace Each directory user's granted third-party OAuth apps, through the Admin SDK token audit The admin.directory.user.security scope added to your existing domain-wide delegation entry. Same client ID, one more scope; no reconnect needed
Microsoft 365 Every service principal, delegated OAuth grant, and application-permission assignment in the tenant, through Microsoft Graph The Application.Read.All application permission with admin consent. If it was not granted at connect time, grant it and re-run the connect flow

The scan reads app identities and scope strings only. It never reads message or file content, and mail monitoring continues unaffected whether or not the scan is enabled.

How do I act on the findings?

  1. Identify the connection and its owner. Confirm who uses the app and what work it supports.
  2. Compare permissions with the task. An app that needed one file does not need broad Drive or SharePoint access. Google distinguishes per-file access from broad Drive scopes; Microsoft distinguishes delegated access from application permissions.
  3. Prioritize sensitive resources and unverified publishers. Broad mail or file access from an unverified app deserves the first look.
  4. Revoke or narrow access that lacks a business need. Revocation happens in the Google Admin console or in Microsoft Entra. Blue Lantern Security shows you the grant; it does not revoke it for you.
  5. Recheck tomorrow. The next daily scan confirms the grant is gone, and the new-app highlight tells you when someone connects something else.

What can AI apps access in your Google Workspace and Microsoft 365? walks through the permission model and review workflow in more depth.

What this scan is, and is not

  • It is an access inventory. A grant means an app can reach data, not that it has read every file or sent anything elsewhere. Activity evidence is a separate question.
  • It will not see pasted text. An inventory of OAuth grants does not reveal someone copying a customer record into a chatbot. Data-loss controls and training cover that.
  • Verified is not the same as safe. Publisher verification establishes identity, not good behavior. A verified app can still request more than it needs. See Microsoft's publisher verification overview.
  • Revoking access is not deletion. Removing a grant stops future access. Data a provider already received is a matter for that provider's terms.

Common questions

Which AI tools does it recognize?

A curated catalog of known AI applications, supplemented by name heuristics for new ones. Every third-party grant is listed regardless, so an unrecognized tool still appears with its scopes.

Does it read my documents or email to find AI usage?

No. It reads grant metadata: app identities and the scope strings each app was granted. Nothing about message or file contents is collected.

Can it revoke risky grants automatically?

No. Revocation is deliberate and stays with your administrators, in the Google Admin console or Microsoft Entra. The scan gives you the list, the reasons, and confirmation the next day.

Will I be alerted when someone connects a new AI app?

Yes, if you create an alert rule on the AI Exposure run type. After the first baseline scan, newly appearing risky apps are highlighted in each run and can be delivered by email or to your SIEM.

Does this cover internal apps my own developers registered?

On Microsoft 365, every service principal and grant in the tenant is enumerated, including internal registrations. Review those with the same questions: who owns it, what it needs, and whether it is still in use.

Enable AI exposure monitoring

Related guides

Sources and further reading