How AccessOwl Finds Hidden Apps
- SSO Logs
- Invitation Emails
AccessOwl checks OAuth grants of users to applications. In addition to that, it reviews the last six months of
Google Workspace SSO logs for activity data.
Whenever someone used “Sign in with Google,” AccessOwl flags that app as potentially untracked.
If an app doesn’t support Google SSO, it won’t appear in this scan.
How User Sync and Imports Affect Discovery
Discovery, user sync, and user list imports provide different types of information:- Discovery identifies app usage from Google Workspace OAuth, SSO, and invitation-email signals.
- User sync means syncing the current user list and permissions from a connected application.
- Importing a user list removes the Discovered Users tab after an import. The tab reappears if new access is discovered over time. Previously discovered users remain available in the Reports tab.
Apps with User Sync
When an application has an active user sync, AccessOwl treats the synced user list as the source of truth. The Discovered Users tab is no longer shown for that application. Enabling user sync does not delete your discovery history. Previous SSO and invitation-email discovery records stay queryable in the Reports tab filtered by Application, and export to CSV, including for users who have since become managed. Only the Discovered Users tab on the application is hidden.An employee who uses a free account or a separate vendor workspace with their company email might not appear as a separate discovered user under the synced application.
Discovery Timing
How often does application discovery run?
How often does application discovery run?
AccessOwl checks Google Workspace OAuth and SSO activity automatically each day. New activity does not appear immediately after a user signs in.
Why might an expected user or app still be missing?
Why might an expected user or app still be missing?
Discovery is best-effort. Results can be delayed or unavailable when a mailbox is unavailable or when your Google Workspace configuration prevents the required access.
What Happens When Apps Are Found
We send a Slack message to Org Admins or centrally set Org Admin Slack notification channel.Approve or Ignore
Once AccessOwl discovers an app:- Approve it if you want to officially manage it. This lets people request the app or automates onboarding/offboarding.
- Ignore it if it’s a personal or irrelevant tool (e.g., someone’s side-project account).
Personal or Irrelevant Apps
Not everything your team signs up for needs central management. Ignored apps stay visible in AccessOwl’s records but won’t alert you again.Taking Action on Discovered Apps
If you find a large “free tier” group (like Fireflies or any other service) with many employees:- Decide if you want to keep them as free users, upgrade them to a paid plan, or remove them entirely.
- Use AccessOwl to track which users belong there, so you can handle offboarding if someone leaves.
Finding User Permissions
By default, discovery only confirms that users have accounts, not their exact role (admin, viewer, etc.). For more detail:- Direct Integrations: Connect AccessOwl directly to apps like Slack or Jira for real-time user lists and permission levels.
- Manual Upload: Use our Google Sheets template to import user data if an app doesn’t have an API or easy export.
Next Steps
- Run Application Discovery
Check your Google Workspace SSO logs to uncover hidden tools. - Enable Email Checks
For non-Google SSO apps, let AccessOwl detect invitation emails. - Approve or Ignore
Decide whether to manage or dismiss each discovered tool. - Sync Deeper Permissions
If you need role-level visibility, set up direct integrations or import user lists. - Stay Proactive
Periodically review newly discovered apps to keep your environment safe and uncluttered.

