For Google Workspace & Microsoft 365

Find the apps and ex-employees that still have access — before someone else does.

Esmeris is a read-only access audit for Google Workspace and Microsoft 365. We take stock of every app and token that can reach your data, including the ones ex-employees left behind. You get a graded report in plain English.

Free to start · no credit card · top 3 findings per platform

  • Read-only access
  • Credentials encrypted
  • We never change your settings
How it works

How an audit runs, in three steps

There is nothing to install. You grant a read-only connection and get a clear verdict.

Grant read-only access

You connect a read-only admin account. Esmeris cannot change anything with it.

We scan your tenant

Esmeris inventories every user, app, token and permission across Workspace and 365.

You get a graded report

A letter grade and a prioritized list of findings, each with a plain-English fix.

What we check

The access you forgot you still had

Every check maps to a real way in. Attackers and former staff keep footholds through risky OAuth scopes, org-wide consent grants, leftover accounts, and admins without MFA.

Former-employee access

Accounts and tokens belonging to people who have left but can still reach your data.

Risky app permissions

Third-party apps holding broad scopes, like reading all mail or acting as a user.

Org-wide consent grants

Apps a past admin approved for the whole organization in one click.

Admins without MFA

Privileged accounts missing multi-factor authentication. Attackers go for these first.

Unverified publishers

Connected apps from publishers Google or Microsoft has never verified.

Stale connections

Integrations that haven't been touched in months but still hold live access.

Sample report

See what you’ll get

Every audit ends in one graded report. It has an overall letter grade and findings ranked by severity, each with a plain-English fix. Have a look at a redacted sample before you commit to anything.

Your free report shows the top 3 findings per platform, with no credit card. Upgrade whenever you like to see every finding and the full grade.

Why it matters

Answer your cyber-insurance questions with evidence

Cyber-insurance applications ask about the things Esmeris measures. Bring the graded report and you have your answers in writing.

  • Do all admin accounts enforce multi-factor authentication?
  • Have you removed access for departed employees?
  • Do you review third-party application permissions?
  • Are org-wide consent grants restricted and monitored?
  • Do you track unverified or stale connected apps?
FAQ

Questions we hear most

Ready to see who has access?

Start free and get your top 3 findings per platform, with no credit card. Upgrade when you want the full graded report.

Start your free audit