Last updated September 1, 2026

Google Workspace integration

Rapid Risk Review (RRR) is an enterprise security platform for discovering, assessing, and controlling Shadow IT and Shadow AI. A customer's authorized Google Workspace administrator can optionally connect RRR for the two specific workflows below.

1. Shadow IT and Shadow AI discovery

RRR reads Google OAuth authorization audit events and limited directory context so security administrators can see which third-party and AI applications users have authorized and which departments are affected.

2. RRR extension beta-channel management

RRR lets an administrator enroll selected test users in a dedicated Google group and apply the beta install policy only for RRR's own managed browser extension. Normal users and unrelated policies are untouched.

Permissions and exact use

Google OAuth scopeWhat RRR doesWhy it is required
admin.reports.audit.readonlyReads OAuth authorization audit metadata: application name, OAuth client ID, granted scopes, authorization time, and authorizing user email.Identifies third-party applications authorized across the Workspace domain for Shadow IT and Shadow AI discovery.
admin.directory.user.readonlyReads only primary email, department, and organizational unit.Correlates users found in authorization events with organizational context. RRR does not retain unrelated directory records or additional profile fields.
admin.directory.groupCreates and manages only the dedicated rrr-ext-beta group and membership selected by the customer administrator.A group targets a small beta cohort without moving users between organizational units or altering unrelated groups.
chrome.management.policyReads, applies, verifies, and resets only the Chrome InstallType policy for RRR's own extension, targeted to the dedicated beta group.Moves selected test users between RRR's stable and beta update channels without modifying unrelated extensions or Chrome policies.
RRR does not access user content.

These scopes are not used to read Gmail, Drive, Calendar, contacts, files, messages, browser history, prompts, or page content. RRR does not manage unrelated groups, users, organizational units, extensions, or policies.

Administrator control and least privilege

Storage, protection, and retention

Google Workspace data and discovered-application metadata are tenant-scoped and available only to authorized users in the connecting RRR organization. Administrative beta-channel credentials are application-encrypted in service-role-only storage. RRR protects access through authentication, tenant authorization, audit logging, encryption in transit, and applicable encryption at rest.

OAuth credentials are retained only while connected. Disconnecting stops future RRR access and deletes the local credential. RRR attempts Google-side token revocation; if Google is unavailable, the administrator is instructed to remove RRR through Google's third-party access controls.

Previously discovered metadata remains subject to the customer's retention policy until deletion is requested. Disconnecting beta-channel access does not delete the Google group or automatically reset external Google policies; administrators should unenroll beta users first and may remove remaining objects in Google Admin.

Google API Services User Data Policy and Limited Use

RRR's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

RRR does not sell Google Workspace API data, use it for advertising, or use raw or derived Google Workspace API data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.

Questions, access, or deletion requests

See the complete Privacy Policy. For Google Workspace data access or deletion requests, contact privacy@rrr.dev.