Google Drive Third-Party App Access: How to Audit What's Connected
- NeatDrive Team
- Aug 11
- 3 min read

You have audited your sharing links. You have cleaned up external collaborators and tightened Shared Drive permissions. But there is a second door into your files that most teams never check: the apps your people have connected to Drive. A PDF converter someone tried two years ago. A note-taking tool from a trial that ended. An AI assistant a contractor authorized during their last week. Each one holds a token that keeps working long after anyone remembers granting it. Reviewing Google Drive third-party app access closes a gap that no folder-by-folder audit will ever surface.
Why Google Drive third-party app access stays invisible
File sharing is visible. Open the sharing panel on any document and you can see exactly who has access and at what level. App access does not appear there at all. The permission lives on the user's Google account, not on the file, so it never shows up in a folder review, a link audit, or a Shared Drive permissions check. Meanwhile, an app granted the broad Drive scope can read, edit, and delete every file that user can touch, including files in Shared Drives your whole team depends on.
Where connected apps come from
Almost every connection was made by someone doing something reasonable. The problem is that nobody revisits them. The usual sources:
Sign-in-with-Google buttons on SaaS tools that request Drive scopes alongside basic profile access
Workspace Marketplace add-ons installed by individual users rather than domain-wide
Browser extensions that ask for Drive permissions during setup
AI assistants and automation tools that need document access to function
Internal scripts and service accounts built for a one-off project and never decommissioned
How to review Google Drive third-party app access
With admin rights, start in the Google Admin console under Security, then Access and data control, then API controls. Two views matter there. App access control lists every third-party app connected to accounts in your domain, the scopes it holds, and how many users authorized it. The Marketplace apps list shows add-ons installed domain-wide or by individuals.
Without admin access you can still review your own account on Google's app permissions page, which shows every app you personally authorized and what it can reach. Do that first. It takes five minutes and usually surprises people enough to make the domain-wide review an easy sell.
What to flag
Not every connection is a problem. These are the ones worth a second look:
Apps holding full Drive scope when a per-file scope would do the same job
Apps still authorized under accounts you have suspended or are about to delete
Anything you cannot trace back to an owner or a business reason
Vendors that never went through procurement or a security review
Apps one person authorized that reach into Shared Drives the whole company uses
What to do once you have found them
Workspace lets you mark each app trusted, limited, or blocked, and you can move the domain to a default-block posture where only reviewed apps are allowed. That is the endpoint worth aiming for, but get there gradually. Revoke a tool a team depends on with no warning and you will spend the next week on tickets.
Be clear-eyed about what revoking achieves. Cutting a token stops future access. It does not recall data the app already copied to its own servers. That is a vendor and contract question, not a Workspace setting, and it is the reason review beats cleanup.
Make it a standing check
Attach app review to two moments you already have. At offboarding, check what the departing person authorized before you delete the account; once the account is gone, so is the record. Then once a quarter, scan for apps added since the last pass. A quarterly review takes twenty minutes when it is routine and half a day when it has been eighteen months.
Third-party app access is one layer of Drive exposure. Public links, stale external collaborators, and files nobody owns anymore sit in the same blind spot and need the same routine attention. NeatDrive runs a free audit of your Google Drive sharing and file health at app.neatdrive.net, so you get a clear picture of where your exposure actually sits before your next security review asks for one.





Comments