Every app your team
connected, under control
Ombré finds every SaaS and AI tool connected to Google Workspace and Microsoft 365, scores the risk and explains why, then approves, revokes, or blocks. Automatically.
Discovered apps
Scanning workspace…
Zapier
Gmail · Drive · Calendar
Notion AI
Docs · Drive · reads content
Loom
Profile · Email
Grammarly
Reads Gmail content
Discover
See every app and AI tool in your estate
No agents, no surveys. Connect a workspace and Ombré maps everything your team has authorised.
Shadow SaaS & AI discovery
Every OAuth app connected to Google Workspace and Microsoft 365, with the people and scopes behind each.
Risk scoring
0 to 100 from scopes, vendor trust and reach, always with the reasoning.
Shadow AI
Catch AI tools quietly touching company data and inboxes.
Notion AI
Reads Drive & Docs content
76
High risk
Decide
Triage in minutes, and keep it that way
AI proposes verdicts, your rules automate the obvious, and drift brings real changes back for review.
AI triage
Approve, deny or review, each with a rationale and the policy it matched.
Autopilot
Auto-approve trusted vendors, deny blocked ones, and pre-triage the rest on every scan.
Drift detection
See what changed since the last scan: new scopes, tier jumps, reach growth.
Zapier
Gmail · Drive · Calendar
Ombré suggests
Broad Gmail and Drive write access with vendor SOC 2 unverified. Worth a human look before approving.
Matched rule: sensitive write accessAct & prove
Enforce access and show your work
Remediate in a click, gather compliance evidence, and let employees self-serve.
Revoke & block
Pull access instantly, or block an app in Entra, across every tenant.
Compliance evidence
Vendor SOC 2, data residency and AI-training posture, exportable.
Employee self-service
Staff request tools and see what's approved. Approvals flow into your registry.
Ask Ombré
Query your apps, people, risks and decisions in plain English.
Which apps can read Gmail content?
Two apps hold Gmail content access:
Revoke both
How it works
Live in minutes, not a quarter
Connect
Sign in with Google or Microsoft and connect a workspace in a click. Read-only discovery scopes only.
Scan & score
Ombré discovers every app, scores its risk, and explains why. No agents to install.
Act
Approve, deny, revoke or block, or let Autopilot handle the routine and surface only what needs you.
Security by default
Built to be trusted with your identity data
Least privilege
Read-only discovery scopes, never content.
Encrypted at rest
Tokens and snapshots, app-level with KMS.
RBAC & audit
Every action attributed and logged.
Not used for training
AI reads metadata only, never your data.