Security & data access
Last updated 19 July 2026
Workspace Audit is read-only by architecture. We authenticate with Google using narrowly-scoped read-only OAuth 2.0 permissions and can never change a setting. In the base product we read only security metadata and configuration — never the contents of your emails, files, calendar events or chats. The optional Drive add-on below grants read access to Drive; even then we use it solely to read sharing metadata, not file contents.
Base scopes we request
These are all “sensitive” scopes (Google verification only). We deliberately request no “restricted” scope in the base product.
cloud-identity.policies.readonlyRead your admin-console policy settings (the core of the audit) — no content, just configuration.admin.directory.user.readonlyList users to check account posture. We read directory metadata, never mailbox contents.admin.directory.user.securityRead per-user security settings (e.g. 2-step verification enrolment).admin.directory.orgunit.readonlyRead your organisational-unit structure so findings can be scoped by OU.admin.directory.domain.readonlyRead your domain list to tell internal from external sharing.admin.directory.group.readonlyRead group settings to audit membership exposure.admin.directory.group.member.readonlyRead group membership to find over-broad access.admin.directory.rolemanagement.readonlyRead admin-role assignments to flag excess privilege.admin.reports.usage.readonlyRead usage reports (e.g. 2SV enforcement) for the User Security module.admin.reports.audit.readonlyRead the audit log to build the Security Timeline.
Optional add-on scope
drive.readonlyOptional add-on. Only if you enable the Shared Drives / Sites module — used to read sharing metadata, never file contents.
How your data is protected
- No domain-wide delegation. We only ever use your own signed-in admin's read-only token — never a service account with standing access to your tenant.
- Encrypted in transit (HTTPS) and at rest.
- Your data is never used to train any AI model.
- You can request deletion of your scan data at any time by emailing darren@dcai.co.za.
Our formal Privacy Policy, Data Processing Addendum and sub-processor list set out the full detail.