AgentGuard, by ScreenComply

Permissions

AI agent permission audit.

Every permission, every agent, every person.
Then take back the ones that shouldn't exist.

An agent's permissions were granted in a hurry, by one person, on a consent screen nobody reads. This audit lists them all, flags the dangerous ones, and lets you remove them with a single confirmed click.

Google Workspace available now. Removal needs the Control plan.

The four permissions that matter most

Most agent permissions are harmless. These four are where the damage happens, and the audit shows exactly which agents hold them and for whom.

Gmail

Send email as a person

An agent that can send mail can speak for your staff to customers, banks and colleagues. Reading mail is a privacy issue. Sending it is an impersonation issue.

Drive

Edit and share files

Full Drive access lets an agent change documents and share them outside the company. The audit shows every external share an agent made.

Breadth

Access to everyone

Some apps are installed for the whole company by one administrator. One decision, every inbox. The audit shows how many people each app can act for.

Admin

Administrative scopes

A handful of apps ask for the ability to manage users or settings. Almost none of them need it. These are flagged first.

What the audit flags

Excessive

The app asked for more than its feature needs. A scheduling tool holding full Drive access. A note-taker that can send email. The audit puts the permission next to what the app actually did, so the gap is obvious.

Unused

Access that was granted and then forgotten. The app still holds a live token and could act at any time, but hasn't in weeks. Unused access is pure downside: all the risk, none of the value.

Orphaned

Granted by someone who has since left, moved teams or changed roles. Offboarding checklists revoke the person's account. They rarely revoke the apps the person connected. We wrote a guide about this.

Unreviewed

New connections from the last seven days that nobody has looked at. The audit surfaces them as they appear, so the review happens while the decision is still fresh.

Permission findingsexample
  • ExcessiveDots can edit any file and send email for 41 people. Installed by one administrator for the whole company.
  • OrphanedInstinct was connected by a user who left on Sep 12. Still active. Still polling.
  • UnusedClaude for Gmail can read mail for 14 people. Two of them have not used it in 30 days.
  • UnreviewedPerplexity connected by 3 people this week. Read-only Drive. No activity yet.

Illustrative. Your findings come from your Workspace's own app grants and admin records.

Fixing it takes one click, not a ticket

  1. 1

    Pick the app and person

    Filter the permission list by app or by person. Open the grant you want to remove.

  2. 2

    See what will change

    The exact permissions that will be removed, for exactly one person. Nothing else is touched.

  3. 3

    Confirm

    The app loses its access for that person. The action is recorded with who did it, when, and what was removed.

Want it to happen without you? Set a policy on the Control plan and the audit can revoke automatically when an agent breaks the rule. See how policies work.

Questions

What is an AI agent permission audit?

A review of every permission AI apps and agents hold in your company accounts: which apps, which people they act for, what they are allowed to do, and whether that access is still needed. It ends with removing the access that should not exist.

How do AI agents get permissions in the first place?

Usually one click. An employee signs into an AI tool with their Google account and approves a consent screen. From then on the tool holds a token that lets it act for that person, often for years, until someone revokes it. Administrators can also install an app for everyone at once.

Can I revoke an agent's permissions from AuditMyAgent?

Yes, on the Control plan. Pick the app and the person, see exactly what will be removed, and confirm. The action is recorded. Revoking does not stop a later reconnection; to block an app permanently, use the app access control in Google Admin, and the dashboard shows you where.

How often should we audit agent permissions?

Continuously is the honest answer, because new connections happen every week. If you do it by hand, quarterly is the minimum. The audit refreshes the permission inventory daily and flags new connections as they appear, so the review becomes a glance instead of a project.

Find the permissions
nobody meant to grant.

Connect Google Workspace as an administrator. Your permission inventory is ready within the hour.

Audit My Permissions

Removal and policies are on the Control plan, $10 per employee per month, with a 3-day free trial.