Which apps can read your company’s Google Drive?
Review forgotten Google Workspace app permissions without interrupting useful work. A plain-language guide for small teams.

How can I check which third-party apps access Google Workspace?
Review connected apps in your Google account and, for your organisation, use the Workspace administrator’s app access controls. Check what each app can access, who authorised it and why it is still needed. Review shared files separately: an app permission and a document-sharing link are different routes to your data.
A free trial can leave a lasting connection
A designer tries a PDF tool. A founder connects a meeting assistant. A growth consultant gives an automation access to a spreadsheet. Each decision makes sense at the time. Months later, the subscriptions and projects have changed, but nobody can confidently name every app that still has permission to access company information.
Start with the accounts used for client work and the services connected to them. Ask each person which tools they still rely on. Do this before blocking unfamiliar apps: a name you do not recognise might power a real delivery process. The objective is to remove forgotten access while keeping necessary work running.
Read the permission, not just the app name
Google uses permission scopes to describe what a connected app can do. In ordinary language, ask whether it can read files, change them, send messages or reach other information. The precise scope matters. Access limited to selected files is different from a broad grant, and a recognisable supplier name does not answer that question.
Write one sentence for each connection: “This app needs this access because it does this job.” If the team cannot finish the sentence, investigate. Record the responsible person, connected account and review date. Avoid treating every connection as malicious; the problem is access that nobody understands or has a current reason to keep.
Two paths into the same work
- App access
Which tools have account permission?
- File sharing
Which people and links reach the files?
- Review
Keep only what current work needs.
Example workflow.
Check file sharing as a different task
Removing an app’s account access does not change every other way a file is shared. A folder might still include a former contractor. A document might have a broad sharing link. A client’s file might belong to an individual rather than the organisation. Review these arrangements alongside the app list, without confusing them.
For example, a departed freelancer may have used a reporting app and also received direct access to a campaign folder. Review the app grant and the folder membership separately. If a tool already copied information, removing future access does not pull those copies back. Check the provider’s deletion process when that matters for the project.
Make the change and verify the result
Ask the owner to confirm whether the connection is still required. If it is, reduce access where the provider supports that and test the actual workflow. If it is not, use the appropriate account or administrator controls to remove access. Workspace options depend on your edition and administrator permissions; follow the current Google instructions.
Keep a dated note of what changed and why. After removal, confirm the intended connection is no longer authorised and that important workflows still work. Review again at a client handover or when a colleague leaves. A small, repeated review is easier to maintain than an ambitious audit that happens only once.
Bring the account review beside the device review
Cybee’s Google Workspace integration adds visibility into connected account activity and access alongside the Macs your team uses. That matters when the same person works across a laptop, shared documents and an AI assistant. You can review the available information from your existing workflow and keep relevant Workspace records on the paid plan.
Keep the evidence clear: a dated record about a Mac does not establish the security of every online account. Workspace findings apply to the connected Workspace environment, not personal Gmail, your bank or every cloud service. Use the separate views together to answer the practical question: who and what still needs access to this client’s work?
What to remember
- Review app permissions and file sharing separately.
- Give each connection a purpose, owner and review date.
- Removing future access does not retrieve information already copied.
Sources and further reading
Product scope and provider guidance can change. Check the linked source for your own setup.
Put it to work.
Continue with a practical guide or see how cybee helps with the work.