ARIA ingests Google Workspace admin audit logs, Drive sharing events, and OAuth token lifecycle changes — detecting mass file exports, permission escalations, and token anomalies that the Admin Console surfaces but does not investigate.
ARIA's cloud monitoring pipeline pulls from the Google Workspace Admin SDK — specifically the Reports API, which provides structured audit logs for Admin console actions, Drive file activity, login events, and OAuth grant changes. These are the same logs available in the Admin console's audit report views, but delivered continuously to ARIA's triage pipeline rather than requiring manual inspection.
For organizations using Microsoft 365, cloud activity monitoring is available through a separate integration. The specific event types and coverage differ from Google Workspace. If your environment is primarily M365, contact us to discuss what's supported before making assumptions about equivalent coverage.
ARIA does not inspect file content. It does not read the contents of Drive documents, email bodies, or attachments. Detection is based on the metadata that the Admin SDK makes available: who accessed what file, when, from where, and what action they took on it.
Changes to the Google Workspace admin environment — domain settings, user provisioning, delegated admin grants, group membership changes, application access policies — are logged by the Admin SDK and ingested by ARIA continuously. Most of these events are routine; ARIA identifies the ones that are not:
Granting an OAuth client domain-wide delegation gives a service account the ability to impersonate any user in the tenant. This is a legitimate mechanism for certain integrations but represents a significant access scope change. ARIA fires immediately when domain-wide delegation is granted or modified. The investigation includes which OAuth client received delegation and what permission scopes it was given.
An admin account that suspends or deletes a large number of user accounts in a short window — outside of a normal offboarding workflow — is a high-confidence indicator of either account compromise or a destructive insider action. ARIA detects the volume anomaly and investigates what account performed the actions and whether there are other anomalous indicators on that account.
Enabling access for unchecked third-party applications across the org, or disabling existing access controls, changes the effective security posture of the Workspace environment. ARIA logs and investigates app access policy changes, particularly those that expand the set of applications that can connect to org data.
Google Drive activity logs record when files are shared externally, downloaded, or moved. ARIA monitors for patterns that suggest data staging or exfiltration:
A single external share is not an alert. The same user sharing fifty files externally in an hour, following a suspicious sign-in earlier in the day, is. ARIA correlates Drive activity with the identity events it already monitors — the combination of signals matters as much as the individual event.
ARIA surfaces these findings to a security engineer. Revoking file access or suspending the account is an action the engineer approves and ARIA executes through a separate, scoped API call. No containment runs automatically.
The Admin SDK provides visibility into OAuth token events: when applications receive tokens, when tokens are revoked, and when applications request tokens with expanded scopes. ARIA monitors this feed for:
ARIA's cloud monitoring covers the audit log events the Google Workspace Admin SDK makes available. It does not cover cloud infrastructure — virtual machines, containers, storage buckets, databases — deployed under a separate GCP project that is not connected to the Workspace Admin SDK. Cloud infrastructure monitoring (GCP, AWS, Azure) is a distinct integration not included in the base service.
ARIA does not inspect file content. It cannot identify whether a specific Drive document contains personally identifiable information or regulated data. Detection is based on behavioral signals — who accessed what, when, and in what pattern — not on content scanning.
admin.reports.audit.readonly (for admin console, Drive, login, and OAuth audit logs), admin.directory.user.readonly (for user and group data including MFA status), and Alert Center viewer. The service account does not have admin console access, cannot change settings, and has no write permissions to any Workspace resource. All containment actions that involve modifying the Workspace environment go through a separate, scoped API credential that requires explicit security engineer approval before use.A read-only ARIA connection to your Workspace Admin SDK surfaces admin anomalies, Drive sharing patterns, and OAuth grant records within 48 hours — at no cost.
Book Free AssessmentCloud activity is one signal in a pipeline that also covers email, identity, and endpoints.
View All Use Cases