Sample report. This is the built-in demo workspace — a typical 26-person business that never reviewed its access.

Top 5 things to fix this week

Stale & unused accounts

Accounts that can still sign in and read company data, but that nobody is actively using — the classic leftover access of former staff, interns and contractors.

2-step verification

Whether a stolen or guessed password alone is enough to get into an account. 2-step verification (a phone prompt or security key) is the single best protection against account takeover.

Administrators

Who holds the master keys. Admin accounts can read every mailbox, reset every password and delete every file — each one must be justified and protected.

✓ No issues found in this category.

Third-party app access

Apps and add-ons your team granted access to company data by clicking "Allow". These keep their access until someone revokes it — most are forgotten within a week.

AppAccess levelGranted by
Mail Merge TurboFull data access2 people
PDF Convert ProBroad access4 people
CRM Sync ToolBroad access3 people
TimeTrack.ioUnrecognised5 people
Emoji for GmailUnrecognised1 person
SlackKnown vendor19 people
ZoomKnown vendor14 people
CanvaKnown vendor6 people

External file sharing

How often access to company data was newly extended to people outside your organisation in Drive. We count the sharing changes themselves — a link made externally visible, or an outsider given access to an item they had none of — not views, edits or downloads. Only the count is kept: no file name, file identifier or file content is stored or shown.