Sample report. This is the built-in demo workspace — a typical 26-person business that never reviewed its access.
Access-risk report
Vermeer & Partners Accountants
Scanned 19 Sept 2026 · 26 accounts · read-only scan
Urgent: serious access risks are wide open — start on the top fixes today.
Top 5 things to fix this week
- 1
Review 3 apps with broad access to email or files
CriticalRevoke any app your business does not actively use.
Affected: Mail Merge Turbo, PDF Convert Pro, CRM Sync Tool
Decide whether your business actually uses this app. If not, remove its access in Google Admin → Security → API controls → App access control (and each user can also revoke it at myaccount.google.com → Security → Third-party apps). To stop this recurring, restrict which apps may access Google data under API controls.
- 2
Turn on 2-step verification for your admin — today
CriticalAn admin password alone protects your entire Google Workspace.
Affected: inge@vermeerpartners.example
Have this admin enable 2-Step Verification today at myaccount.google.com → Security → 2-Step Verification. Prefer a security key or Google prompt over SMS. Then enforce it for all admins in Google Admin → Security → Authentication → 2-step verification.
- 3
Suspend 1 account unused for 6+ months
CriticalLong-dormant accounts are the classic leftover-access hole.
Affected: sanne@vermeerpartners.example
In Google Admin (admin.google.com) go to Directory → Users, click the person, then "Suspend user". If they have left for good, transfer their email and files to a colleague (Google offers this when you delete the account) and then delete it to stop paying for the licence.
- 4
Get 3 people enrolled in 2-step verification
HighA second sign-in step blocks most account-takeover attacks.
Affected: tim@vermeerpartners.example, welkom@vermeerpartners.example, femke@vermeerpartners.example
Ask the person to turn it on at myaccount.google.com → Security → 2-Step Verification. To make it mandatory for everyone, in Google Admin go to Security → Authentication → 2-step verification and set enforcement (give people a 2-week enrollment window).
- 5
Review 2 accounts inactive for 90+ days
HighConfirm each is still needed; suspend the ones that are not.
Affected: tim@vermeerpartners.example, pieter@vermeerpartners.example
In Google Admin (admin.google.com) go to Directory → Users, click the person, then "Suspend user". If they have left for good, transfer their email and files to a colleague (Google offers this when you delete the account) and then delete it to stop paying for the licence.
Stale & unused accounts
Accounts that can still sign in and read company data, but that nobody is actively using — the classic leftover access of former staff, interns and contractors.
Sanne de Wit hasn't signed in for 220 days
- What this means
- This account is still active and can sign in, read email and open company files, but nobody has used it for months.
- Why it matters
- Unused accounts are the classic way ex-staff and forgotten contractors keep access. They are also easy targets — nobody notices when someone else starts using them.
- How to fix it
- In Google Admin (admin.google.com) go to Directory → Users, click the person, then "Suspend user". If they have left for good, transfer their email and files to a colleague (Google offers this when you delete the account) and then delete it to stop paying for the licence.
2 accounts affected
- Tim Janssen hasn't signed in for 130 days
- Pieter van Dijk hasn't signed in for 95 days
- What this means
- This account is still active and can sign in, read email and open company files, but nobody has used it for months.
- Why it matters
- Unused accounts are the classic way ex-staff and forgotten contractors keep access. They are also easy targets — nobody notices when someone else starts using them.
- How to fix it
- In Google Admin (admin.google.com) go to Directory → Users, click the person, then "Suspend user". If they have left for good, transfer their email and files to a colleague (Google offers this when you delete the account) and then delete it to stop paying for the licence.
Welkom Mailbox was created 200 days ago and has never signed in
- What this means
- This account was created but has never been signed into.
- Why it matters
- An account nobody uses still has a working password and mailbox. It is an unwatched door into your business. It may also be costing you a licence — this scan cannot see licence assignment, so check that separately in Google Admin before treating the cost as fact.
- How to fix it
- In Google Admin go to Directory → Users, click the account and choose "Suspend user". If it was created by mistake or for someone who never started, delete it.
Joris Willems is suspended and is not archived
- What this means
- This account is suspended (blocked from signing in) and is not archived. This scan does not verify its licence assignment.
- Why it matters
- A suspended account may still have a paid licence. Check its assignment and retention requirements before deciding whether to archive or close it.
- How to fix it
- In Google Admin go to Directory → Users, filter by "Suspended", open the account and either delete it (Google will offer to transfer their email and Drive files first) or move it to an Archived User licence if you must keep the data.
2-step verification
Whether a stolen or guessed password alone is enough to get into an account. 2-step verification (a phone prompt or security key) is the single best protection against account takeover.
Admin Inge Bakker has no 2-step verification
- What this means
- An ADMINISTRATOR account — with the power to read mailboxes, reset passwords and delete users — signs in with only a password.
- Why it matters
- If this one password is phished, the attacker owns your entire Google Workspace: every mailbox, every file, every user. This is the single most dangerous gap a small business can have.
- How to fix it
- Have this admin enable 2-Step Verification today at myaccount.google.com → Security → 2-Step Verification. Prefer a security key or Google prompt over SMS. Then enforce it for all admins in Google Admin → Security → Authentication → 2-step verification.
3 accounts affected
- Tim Janssen has no 2-step verification
- Welkom Mailbox has no 2-step verification
- Femke Visser has no 2-step verification
- What this means
- This person signs in with only a password — no second step (like a phone prompt) is required.
- Why it matters
- Passwords get phished and reused. A second sign-in step is the single most effective protection against account takeover — Google reports it blocks the vast majority of automated attacks.
- How to fix it
- Ask the person to turn it on at myaccount.google.com → Security → 2-Step Verification. To make it mandatory for everyone, in Google Admin go to Security → Authentication → 2-step verification and set enforcement (give people a 2-week enrollment window).
2-step verification is not enforced for your organisation
- What this means
- Your organisation allows people to skip the second sign-in step — it is optional, and some people have not turned it on.
- Why it matters
- Optional security settings stay off. Enforcement is what actually closes the door; otherwise one phished password is enough.
- How to fix it
- In Google Admin go to Security → Authentication → 2-step verification, tick "Allow users to turn on 2-Step Verification", set Enforcement to "On", and give a short grace period so people can enroll. Warn the team first — anyone not enrolled by the deadline is locked out until they enroll.
Administrators
Who holds the master keys. Admin accounts can read every mailbox, reset every password and delete every file — each one must be justified and protected.
✓ No issues found in this category.
Third-party app access
Apps and add-ons your team granted access to company data by clicking "Allow". These keep their access until someone revokes it — most are forgotten within a week.
3 accounts affected
- "Mail Merge Turbo" has FULL access to email or files for 2 people
- "PDF Convert Pro" has broad data access for 4 people
- "CRM Sync Tool" has broad data access for 3 people
- What this means
- Someone on your team granted this third-party app broad access to company data (their email, files or contacts).
- Why it matters
- The app — and anyone who compromises the app's maker — can use that access without ever needing a password. Most people forget these grants exist within a week of clicking "Allow".
- How to fix it
- Decide whether your business actually uses this app. If not, remove its access in Google Admin → Security → API controls → App access control (and each user can also revoke it at myaccount.google.com → Security → Third-party apps). To stop this recurring, restrict which apps may access Google data under API controls.
2 accounts affected
- Unrecognised app "Emoji for Gmail" has access for 1 person
- Unrecognised app "TimeTrack.io" has access for 5 people
- What this means
- A third-party app that we could not match to a well-known vendor has access to at least one account.
- Why it matters
- It currently holds only limited permissions, but unrecognised apps are worth a 30-second check — attackers use innocuous-looking apps as a foothold.
- How to fix it
- Ask the person who granted it what it is (shown in Google Admin → Security → API controls → App access control). If nobody recognises it, revoke it.
| App | Access level | Granted by |
|---|---|---|
| Mail Merge Turbo | Full data access | 2 people |
| PDF Convert Pro | Broad access | 4 people |
| CRM Sync Tool | Broad access | 3 people |
| TimeTrack.io | Unrecognised | 5 people |
| Emoji for Gmail | Unrecognised | 1 person |
| Slack | Known vendor | 19 people |
| Zoom | Known vendor | 14 people |
| Canva | Known vendor | 6 people |
External file sharing
How often access to company data was newly extended to people outside your organisation in Drive. We count the sharing changes themselves — a link made externally visible, or an outsider given access to an item they had none of — not views, edits or downloads. Only the count is kept: no file name, file identifier or file content is stored or shown.
140 new external-access grants in the last 90 days
- What this means
- Access to your files was extended outside your organisation many times in the last 90 days. We count the Drive events that granted new outside access — a link made externally visible, or someone outside your domain given access to an item they previously had none of.
- Why it matters
- Each of those is a copy of company data you no longer fully control. Old shares to ex-clients, personal addresses and "anyone with the link" tend to accumulate silently, and nobody reviews them.
- How to fix it
- In Google Admin go to Reports → Audit and investigation → Drive log events and filter the event to "Link sharing visibility change" or "User sharing permissions change" to see what went where. Set sharing defaults under Apps → Google Workspace → Drive and Docs → Sharing settings (e.g. warn on external sharing, or restrict to allowlisted domains).
Appendix — all 26 accounts
| Account | Last sign-in | 2-step | Role | Status |
|---|---|---|---|---|
Daan Vermeer daan@vermeerpartners.example | yesterday | on | Super admin | Active |
Inge Bakker inge@vermeerpartners.example | 4 days ago | off | Super admin | Active |
Sanne de Wit sanne@vermeerpartners.example | 7 months ago | on | User | Active |
Tim Janssen tim@vermeerpartners.example | 4 months ago | off | User | Active |
Pieter van Dijk pieter@vermeerpartners.example | 3 months ago | on | User | Active |
Welkom Mailbox welkom@vermeerpartners.example | never | off | User | Active |
Femke Visser femke@vermeerpartners.example | 3 days ago | off | User | Active |
Ruben Smit ruben@vermeerpartners.example | 2 days ago | on | User | Active |
Anouk Meijer anouk@vermeerpartners.example | yesterday | on | User | Active |
Jeroen de Boer jeroen@vermeerpartners.example | 6 days ago | on | User | Active |
Lotte Mulder lotte@vermeerpartners.example | 2 days ago | on | User | Active |
Bas de Groot bas@vermeerpartners.example | 9 days ago | on | User | Active |
Eva Bos eva@vermeerpartners.example | yesterday | on | User | Active |
Thomas Vos thomas@vermeerpartners.example | 12 days ago | on | User | Active |
Nina Peters nina@vermeerpartners.example | 5 days ago | on | User | Active |
Kees Hendriks kees@vermeerpartners.example | 20 days ago | on | User | Active |
Marit van Leeuwen marit@vermeerpartners.example | 3 days ago | on | User | Active |
Sven Dekker sven@vermeerpartners.example | 8 days ago | on | User | Active |
Iris Brouwer iris@vermeerpartners.example | 2 days ago | on | User | Active |
Daniël Dijkstra daniel@vermeerpartners.example | 15 days ago | on | User | Active |
Floor Smits floor@vermeerpartners.example | 7 days ago | on | User | Active |
Mark de Graaf mark@vermeerpartners.example | 30 days ago | on | User | Active |
Ellen Kuipers ellen@vermeerpartners.example | 45 days ago | on | User | Active |
Noor van der Berg noor@vermeerpartners.example | 11 days ago | on | User | Active |
Joris Willems joris@vermeerpartners.example | 13 months ago | off | User | Suspended |
Lisa Hoekstra lisa@vermeerpartners.example | 25 days ago | on | User | Suspended |
Methodology & honest limits
This report is a point-in-time, read-only scan of your Google Workspace using Google's Admin SDK. We read your user directory (sign-in times, 2-step verification status, admin roles), the list of third-party apps your team granted access to, and Drive audit events, which are reduced to sharing counts in memory as each response is processed. We request no Drive or Gmail permission, so file contents and email messages are never sent to us, and no file name, file identifier or file content is ever stored, logged or shown — metadata and counts only.
The score is deterministic: every finding carries a fixed penalty by severity (critical 15, high 10, medium 5, low 2), capped per category so no single problem area can zero the score alone.
This is visibility, not protection. Fixing the items in this report reduces common access risks, but no report can guarantee you won't be breached. This is not a compliance certification and not legal advice. Data reflects the moment of the scan; re-scan after making changes.
You can delete all scan data, including this report, at any time from your dashboard.