Google Workspace integration
Rapid Risk Review (RRR) is an enterprise security platform for discovering, assessing, and controlling Shadow IT and Shadow AI. A customer's authorized Google Workspace administrator can optionally connect RRR for the two specific workflows below.
1. Shadow IT and Shadow AI discovery
RRR reads Google OAuth authorization audit events and limited directory context so security administrators can see which third-party and AI applications users have authorized and which departments are affected.
2. RRR extension beta-channel management
RRR lets an administrator enroll selected test users in a dedicated Google group and apply the beta install policy only for RRR's own managed browser extension. Normal users and unrelated policies are untouched.
Permissions and exact use
| Google OAuth scope | What RRR does | Why it is required |
|---|---|---|
admin.reports.audit.readonly | Reads OAuth authorization audit metadata: application name, OAuth client ID, granted scopes, authorization time, and authorizing user email. | Identifies third-party applications authorized across the Workspace domain for Shadow IT and Shadow AI discovery. |
admin.directory.user.readonly | Reads only primary email, department, and organizational unit. | Correlates users found in authorization events with organizational context. RRR does not retain unrelated directory records or additional profile fields. |
admin.directory.group | Creates and manages only the dedicated rrr-ext-beta group and membership selected by the customer administrator. | A group targets a small beta cohort without moving users between organizational units or altering unrelated groups. |
chrome.management.policy | Reads, applies, verifies, and resets only the Chrome InstallType policy for RRR's own extension, targeted to the dedicated beta group. | Moves selected test users between RRR's stable and beta update channels without modifying unrelated extensions or Chrome policies. |
These scopes are not used to read Gmail, Drive, Calendar, contacts, files, messages, browser history, prompts, or page content. RRR does not manage unrelated groups, users, organizational units, extensions, or policies.
Administrator control and least privilege
- An authorized Workspace administrator initiates each OAuth connection and sees the requested scopes on Google's consent screen.
- The two read-only scopes power discovery. The two write-capable scopes power only the optional RRR beta-channel workflow and are constrained by RRR's application logic.
- RRR's discovery connection tests both Reports and Directory access and fails if either required permission is unavailable.
- Beta enrollment accepts one explicitly selected user at a time and targets only
rrr-ext-betaand RRR's configured extension ID.
Storage, protection, and retention
Google Workspace data and discovered-application metadata are tenant-scoped and available only to authorized users in the connecting RRR organization. Administrative beta-channel credentials are application-encrypted in service-role-only storage. RRR protects access through authentication, tenant authorization, audit logging, encryption in transit, and applicable encryption at rest.
OAuth credentials are retained only while connected. Disconnecting stops future RRR access and deletes the local credential. RRR attempts Google-side token revocation; if Google is unavailable, the administrator is instructed to remove RRR through Google's third-party access controls.
Previously discovered metadata remains subject to the customer's retention policy until deletion is requested. Disconnecting beta-channel access does not delete the Google group or automatically reset external Google policies; administrators should unenroll beta users first and may remove remaining objects in Google Admin.
Google API Services User Data Policy and Limited Use
RRR's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
RRR does not sell Google Workspace API data, use it for advertising, or use raw or derived Google Workspace API data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models.
Questions, access, or deletion requests
See the complete Privacy Policy. For Google Workspace data access or deletion requests, contact privacy@rrr.dev.