The short answer: any AI tool an employee has granted "connected app" or "add-on" permissions to — through Google Workspace's app marketplace, Microsoft 365's connected apps, or a browser extension with broad permissions — can potentially read, and sometimes modify, files, email, and calendar data. The specific list of tools changes constantly as new ones launch, so the useful skill isn't memorizing a list — it's knowing how to check your own environment.
How this access is typically granted
It usually isn't done through IT. An employee clicks "Sign in with Google" or "Connect to Microsoft 365" inside an AI tool, and depending on what the tool asks for, that can grant it read access to files, email, contacts, or calendar data — sometimes broader than the specific task the employee had in mind.
This is standard, sanctioned functionality on both platforms — it's how legitimate integrations work — which is exactly why it's easy for permissions to accumulate without anyone reviewing them as a whole.
How to check what's currently connected
Google Workspace
A Workspace admin can review connected third-party apps under the Google Admin console's app access controls, and individual users can review their own connected apps under their Google Account's security settings. This shows what's currently authorized and what scope of access (e.g., "view files," "view and manage files") each app has.
Microsoft 365
A Microsoft 365 admin can review consented applications and their granted permissions through the Microsoft Entra admin center (the current name for Azure AD's admin tools). This shows which apps employees have granted access to, and what Microsoft Graph permissions (email, files, calendar, etc.) each one holds.
What to look for during a review
- Scope of access: does the app need everything it's been granted, or more than the task requires?
- Who granted it: was this approved deliberately, or clicked through quickly to get past a sign-in prompt?
- Is it still in use: tools get tried once and forgotten, while the access grant often remains active.
- Third-party reputation: is this a well-known provider with a clear privacy policy, or an unfamiliar tool?
A simple ongoing practice
This doesn't need to be a one-time audit that never happens again. A short recurring review — quarterly is reasonable for most small businesses — of connected apps in both platforms is enough to catch access that's no longer needed or was never fully understood at the time it was granted.
Next step
Our free AI Risk Check includes a specific question on whether connected-app permissions are reviewed before and after connection — take it to see how this fits into your overall exposure picture, and get the free AI Use Policy Template to set expectations going forward.
Related: What Is Shadow AI? · The Safe AI Stack for a 5–25 Person Business