So we ran a proper SaaS audit this month. Our SSPM reported 340 managed apps, which looks reasonable on a dashboard.
Then we pulled the raw OAuth grant data from Google Workspace and found another 180 apps that no one in IT knew that it existed. 40 of them had full Drive access. One was a project management platform that the marketing team signed up for in early 2024, and three people are still using it. We don’t have a problem with the tool, but the IT team found out about it during the audit.
The SSPM flagged none, but I am thinking its because the apps were never provisioned through IT in the first place. Someone just clicked sign in with Google and that was it. They were living entirely outside the managed ecosystem.
What are you all doing about the SaaS your SSPM will never see?