Connect Google Workspace

OAuth consent for Gmail, org-policy restrictions, multi-user scans.

Last updated 2026-05-11 BEC Audit

Start the audit from /mailbox-audit/<UUID>/start/. Pick Google Workspace and you are redirected to Google's consent screen.

Google displays the exact scopes requested. All are read-only and limited to mailbox metadata. Approve to continue.

If your org blocks third-party OAuth apps

Google Workspace admins can restrict third-party OAuth. If you see "Access blocked: This app's request is invalid," your Workspace admin must add LeakTrace to the allowed app list. Forward them the consent screen URL — they can approve from the Google Admin Console.

Personal Gmail accounts

BEC Mailbox Audit is intended for business use. Personal @gmail.com accounts work but lack the corporate context that makes findings actionable (no shared mailboxes, no admin policies to harden).

Did this answer your question? If not, the AI assistant in the bottom-right can help, or email [email protected].