Skip to the install command

Google Workspace

Know who can get in. Even after they leave.

cybee shows who can get into your team’s Google Workspace: the accounts, when they sign in and the apps people have let in.

Send the setup guide to my Mac

Step by step, for your Mac. By AirDrop, message or email.

curl -sSf https://get.cybee.dev | sh

From get.cybee.dev, cybee’s install server. Read the script

Run it in Terminal, a chat, your IDE or a CLI. Keep working where you started.Press Command and C to copy.

Your AI assistant

Noor’s project ended. What can she still get into?

Used cybee

cybee10:05

Noor’s account is still open.

Account
Active
Last sign in
Yesterday
Apps she let in
1

Campaign Reports can still read Drive.

Allowed through Noor’s account. Is it still needed?

Review

Ask next

Close Noor’s Workspace access.

Which apps can read our Drive?

account record a-0926-1005Show the account

Illustration: Ana asks her assistant what Noor can still get into now that Noor’s project has ended. cybee answers that Noor’s Google Workspace account is still active, that she last signed in yesterday, and that one app she allowed can still read Drive.

Access outlives the project. Then a client asks about it.

In a small team, people and apps come and go with each client. Their accounts and permissions often stay open after the work ends, until someone outside the company asks who can reach their files.

  • when someone leaves

    A freelancer’s project ends.

    Their work account still opens the shared folders. Nobody has closed it, because nobody was sure whose job it was.

  • any week

    Someone tries an app with their work account.

    An app tried for one job can still have permission months later.

  • before a deal

    A client sends a security questionnaire.

    “Who at your company can reach our files?”

    They want a date and a record, not a promise.

  • on a review

    A partner asks who can reach shared work.

    They want the accounts and the apps, with dates, for the company they are about to trust.

See it. Close it. Show the record.

Connect your company’s Google Workspace once, after you have read the permissions it asks for. Then ask about it in the same assistant you use for your Macs.

SeeFree

Every account and what it let in. Next to the Macs.

cybee lists the accounts in your connected Workspace and their security settings, when each one signed in, the apps given access through an account, Drive downloads and changes to how the organisation is managed.

Luca’s account and Mac26.09.2026

  1. 09:12

    Luca’s work account signed in.sign in · Google Workspace

  2. 09:30

    Moodboard Sync may read Drive, allowed through his account.app access · Google Workspace

  3. 09:36

    Three files downloaded from Drive.Drive download · the event, never the file

  4. 09:41

    Luca’s MacBook Pro is protected. No open alerts.Mac · dated record r-0926-0941

One account, the events around it and the Mac beside it.

CloseFreeProof plan

Someone leaves. Close their access, with a date.

Ask cybee what the person can still reach. It finds their Workspace account and shows the step it proposes. You read it first, and nothing changes until you confirm.

Noor leaves the team26.09.2026

  1. 10:05

    cybee finds Noor’s Workspace account.Still active. Last sign in Fri 18:04.

  2. 10:14

    Ana reads the proposed step and confirms it.Nothing changes before she says yes.

  3. 10:15

    Noor’s Workspace account is closed.Proof plan: sealed in account record a-0926-1015

A person confirms. The record keeps the time.

ProveProof plan

When a client asks, send the right record. Each says what it covers.

Your Workspace gets its own account record: the accounts and events of the organisation you connected. Your Macs have the Trust Passport: the settings cybee checked on each Mac it assessed.

The two stay apart, so neither claims more than it saw. Each one says what was checked and when, and neither certifies the company.

account recorda-0926-1015

10:15

Google Workspace. Noor’s account closed.

  • Active accounts3
  • RemovalConfirmed by Ana

Only the connected Workspace.

Trust Passportsha256 9f3c…b71e

09:45

Four Macs. 118 of 118 checks hold.

  • Disk encryptionSince 12.03.2026
  • ProtectionSince 12.03.2026

Only the Macs it assessed.

Two records, kept apart. Neither certifies the company.

Nobody buys security. Somebody else sets a date.

An agency of about ten people, all on Macs. Their insurer sent a security questionnaire.

  1. Found cybee.
  2. Installed.
  3. First record sealed.
  4. Sent to the insurer.

No demo. No call. The insurance policy was issued.

The first record shows what was true that night. Every day after adds history.

A real customer story, shared anonymously.

Seeing it is free. The sealed record is the Proof plan.

Connecting Workspace and seeing who can get in costs nothing. The sealed account record and the offboarding evidence come with the Proof plan. Your Google Workspace subscription stays separate.

Free

Free

Forever. Unlimited Macs and people.

  • Stops bad software while it runs
  • Alerts in macOS, Slack, Teams and SMS
  • 118 safety checks on each Mac
  • Apps, extensions and AI agents listed
  • “Am I safe?” answers in your AI assistant
  • Google Workspace account activity
  • Email support within one working day

Proof plan

CHFEURUSDGBP9per Mac per month, or 90 a year

Everything in Free, plus:

  • Weak settings fixed and kept fixed
  • The sealed Trust Passport
  • Security training, completion recorded
  • Incident response plan
  • Chat support
Install, then start the 14 day trial

The 14 day trial starts in your AI assistant, after cybee is installed. Ask for a Proof plan feature, such as the Trust Passport. The link arrives in the chat and leads to Stripe, the payment service.

Per Mac, excluding tax. The same number in CHF, EUR, USD and GBP. Runs on Macs with an Apple chip, M1 or newer. Macs with an Intel chip are not supported. To check a Mac, open the Apple menu and choose About This Mac.All plan details

Accounts and events. Never your email or your files.

cybee sees the security side of the Workspace you connect. It does not read what people write or store there.

  • what cybee sees

    The security events of the organisation you connect.

    • Accounts and their security settings, including what is available about extra sign in checks.
    • When a work account was used to sign in.
    • Which apps were given access through a work account.
    • Drive download events, without the documents.
    • Dated changes to how your organisation is managed.
  • outside it

    What it never reads, and what it does not cover.

    • The contents of email.
    • The contents of documents.
    • Personal Google accounts.
    • Client organisations you have not connected.
    • Other services, such as client tools and API keys.

Before you connect it.

What does cybee not do in Workspace?

It does not read email or document contents. It covers only the Google Workspace organisation you connect, not personal Google accounts, client organisations or other services. Closing an account does not rotate keys or erase copies someone already made. It is not a certification. Microsoft 365 is in build.

Does cybee read our emails or documents?

No. Workspace visibility covers accounts and security events, including Drive downloads. It does not read email or document contents.

Which accounts are included?

The Google Workspace organisation you connect. Personal Google accounts, client organisations you have not connected and unrelated services are outside that connection. A connected Mac does not connect its owner’s accounts on its own.

What about Microsoft 365?

It is in build, so you cannot connect it yet. Follow it on the roadmap.

Is Google Workspace itself part of cybee?

No. You keep your own Google Workspace subscription. cybee connects to it and does not replace it.

Your next client will ask. Be ready.

curl -sSf https://get.cybee.dev | sh

Press Command and C to copy.

Send the setup guide to my Mac

Run it in Terminal, a chat, your IDE or a CLI. Keep working where you started.

Free for every Mac with an Apple chip · Asks before it changes your Mac What it installs Read the install script

Install cybee on your Mac.

Not at your Mac? Send these steps to yourself.

Needs a Mac with Apple silicon. To check, open the Apple menu and choose About This Mac: next to Chip, the name starts with Apple M. Intel Macs are not supported.

curl -sSf https://get.cybee.dev | sh

Run it in one of these places. Keep working there.

  • Terminal

    Open Terminal, paste the line and press Return.

    Then cybee status

  • Chat

    Paste it into your AI assistant’s chat and ask it to install cybee. This needs an assistant that runs on your Mac. A chat in a browser tab cannot reach your Mac.

    Then /cybee in the same chat

  • IDE

    Paste it into the terminal in Cursor, or ask Cursor to run it.

    Then /cybee in Cursor’s chat

  • CLI

    Ask Claude Code or Codex to run it. macOS asks for your password in a window.

    Then /cybee in the same session

Your Mac may ask for your password. That is macOS checking it is you. When System Settings opens, switch on CybeeES under Full Disk Access. Protection starts then. Full Disk Access lets cybee watch what programs do. Your files never leave your Mac.

Want the Proof plan?

The 14 day trial starts in your AI assistant, after cybee is installed. Ask for a Proof plan feature, such as the Trust Passport. The link arrives in the chat and leads to Stripe, the payment service.