Find the apps and ex-employees that still have access — before someone else does.
Esmeris is a read-only access audit for Google Workspace and Microsoft 365. We take stock of every app and token that can reach your data, including the ones ex-employees left behind. You get a graded report in plain English.
Free to start · no credit card · top 3 findings per platform
- Read-only access
- Credentials encrypted
- We never change your settings
How an audit runs, in three steps
There is nothing to install. You grant a read-only connection and get a clear verdict.
Grant read-only access
You connect a read-only admin account. Esmeris cannot change anything with it.
We scan your tenant
Esmeris inventories every user, app, token and permission across Workspace and 365.
You get a graded report
A letter grade and a prioritized list of findings, each with a plain-English fix.
The access you forgot you still had
Every check maps to a real way in. Attackers and former staff keep footholds through risky OAuth scopes, org-wide consent grants, leftover accounts, and admins without MFA.
Former-employee access
Accounts and tokens belonging to people who have left but can still reach your data.
Risky app permissions
Third-party apps holding broad scopes, like reading all mail or acting as a user.
Org-wide consent grants
Apps a past admin approved for the whole organization in one click.
Admins without MFA
Privileged accounts missing multi-factor authentication. Attackers go for these first.
Unverified publishers
Connected apps from publishers Google or Microsoft has never verified.
Stale connections
Integrations that haven't been touched in months but still hold live access.
See what you’ll get
Every audit ends in one graded report. It has an overall letter grade and findings ranked by severity, each with a plain-English fix. Have a look at a redacted sample before you commit to anything.
Your free report shows the top 3 findings per platform, with no credit card. Upgrade whenever you like to see every finding and the full grade.
Answer your cyber-insurance questions with evidence
Cyber-insurance applications ask about the things Esmeris measures. Bring the graded report and you have your answers in writing.
- Do all admin accounts enforce multi-factor authentication?
- Have you removed access for departed employees?
- Do you review third-party application permissions?
- Are org-wide consent grants restricted and monitored?
- Do you track unverified or stale connected apps?
Guides you can use today
Step-by-step walkthroughs for Google Workspace and Microsoft 365. You don't need an Esmeris account to follow them.
Finding ex-employee access that survives offboarding
Former-employee access hides in OAuth tokens, app passwords, forwarding rules, and shared files. This guide covers where to look in Google Workspace and Microsoft 365.
Admin consent and org-wide app grants in Microsoft 365, explained
One admin click can give a third-party app access to every mailbox and file in your tenant. This guide explains admin consent in Microsoft 365 and how to review what's been granted.
Using an access audit to answer your cyber-insurance questionnaire
Cyber-insurance applications ask detailed access-control questions. An access audit of your Google Workspace or Microsoft 365 turns each answer into documented evidence.
Questions we hear most
Ready to see who has access?
Start free and get your top 3 findings per platform, with no credit card. Upgrade when you want the full graded report.
Start your free audit