New · OAuth scope intelligence for Google Workspace and Microsoft 365

Stop risky AI plugins
before they touch company data.

ScopeGuard scans browser extensions, OAuth apps, email add-ons, and IDE plugins before installation, then enforces security policy based on permissions, scopes, publisher identity, and version drift.

app.scopeguard.com / overview
Plugins discovered
221
High-risk
14
Pending review
7
Blocked installs
19
Risk trend · last 7 days+18% high risk
Top alerts
  • Gmail send scope added
  • All-sites permission added
  • Publisher ownership change

Trusted by security teams at modern enterprises

NorthwindHelix BioArdent PayStratifyQuay LabsLinden & Co
The problem

Employees install AI tools faster than security can review them.

Every Chrome extension, Gmail add-on, GitHub app, and VS Code plugin can read browser tabs, mailboxes, source code, and customer data. Most are installed in one click — and most security teams have no inventory, no policy, and no visibility into what changed last week.

47 new browser extensions installed this quarter

12 OAuth apps granted Gmail read access without review

9 IDE plugins now reading workspace files

6 extensions silently expanded permissions in 30 days

The solution

One control plane for every plugin and OAuth grant

ScopeGuard sits between your employees and every plugin marketplace, mailbox, and IDE.

Pre-install control

Every browser extension, OAuth app, and IDE plugin passes through a security gate before it can read company data.

OAuth scope intelligence

See exactly which Google Workspace and Microsoft 365 scopes an app requests — and which sensitive ones to block by default.

Publisher and permission drift monitoring

Get alerted when an installed plugin changes ownership, adds a scope, or starts contacting new domains.

What we catch

Real signals from real installations

Critical

Extension requests access to all websites

AI Meeting Summarizer Pro · Chrome

Critical

OAuth app requests Gmail read access

ChatMail Assistant · Google Workspace

High

Publisher changed last week

Prompt Saver Plus · Indie Maker LLC

High

New version added external data sharing

ChatMail Assistant v3.2.0

Medium

Unverified publisher requesting Drive access

Calendar Copilot · Tempora Labs

Medium

IDE plugin added workspace file read

CodePilot Helper · VS Code

How it works

From discovery to enforcement in one workflow

1Step 1

Discover plugins

Pull inventory from Chrome Enterprise, Edge, Google Workspace, Microsoft 365, GitHub, and IDE marketplaces.

2Step 2

Score risk

Combine permissions, OAuth scopes, publisher identity, and behavior into a unified risk score.

3Step 3

Enforce policy

Auto-allow, block, or route to review based on rules your security team controls.

4Step 4

Monitor drift

Continuously watch for new scopes, new domains, and publisher ownership changes.

Know which AI tools can read your company data — before employees install them.

Book a 30-minute walkthrough with a ScopeGuard security engineer.

  • SOC 2 Type II
  • Read-only deployment
  • 14-day pilot