ARIA ingests Google Workspace Alert Center signals, investigates phishing and business email compromise attempts in context, and escalates confirmed threats for security engineer review.
ARIA's email monitoring is built on top of Google Workspace Alert Center, the native security alert feed that Google produces for Workspace administrators. Alert Center fires when Google's own detection systems identify a phishing attempt, a malware attachment, a suspicious login linked to an email account, or a government-backed attack warning. ARIA subscribes to this feed via a service account with read access to the tenant's Alert Center and Admin SDK logs.
This means ARIA's email visibility is scoped to what Google exposes: it does not independently scan the body or attachments of every message. What it adds is investigation depth — pulling account activity context, correlating with other signals from the same tenant, and making a triaged finding out of a raw Google alert that would otherwise sit in an admin console few employees monitor.
For Microsoft 365 tenants, equivalent alerting is available through Microsoft Defender for Office 365 and the M365 Security & Compliance Center, though the specific event types and coverage differ from Google Workspace Alert Center.
When Google identifies a phishing message delivered to an inbox — or blocked before delivery — Alert Center fires an event that includes the sender, recipients, message ID, and Google's classification. ARIA receives that event and enriches it:
If the alert is a confirmed threat — malicious sender, known phishing infrastructure, evidence of user interaction — it escalates to a security engineer with the full investigation context. If the enrichment shows the alert is a false positive or a low-risk marketing email, ARIA closes it automatically with a recorded rationale.
Business email compromise (BEC) is the most financially damaging email threat category for organizations that don't carry cyber insurance with dedicated BEC riders. Unlike phishing, BEC rarely uses malicious links or attachments — it relies on impersonation and social engineering. The message looks legitimate. Google's classifier often doesn't flag it.
ARIA detects BEC precursors and patterns through identity and email metadata signals:
A login from an unfamiliar IP or device combined with immediate inbox rule creation — forwarding all mail to an external address — is a strong indicator of account compromise being used for BEC. ARIA correlates these events across the Workspace Admin SDK and Gmail activity logs.
Alert Center fires on outbound mail where the sender's display name matches an executive but the sending address does not match the domain. ARIA investigates whether the account sending the message has any prior relationship with the recipient or any legitimizing activity in the tenant history.
New mail forwarding rules created by a user — especially rules that silently copy all inbound mail to an external address — are surfaced by the Admin SDK activity log. ARIA flags these because they are a reliable indicator of either an account compromise or an insider moving mail outside the organization's visibility.
Alert Center includes signals on spam campaigns that reach Workspace inboxes despite Google's filters. ARIA logs these events and provides context on campaign scope — whether the same campaign hit multiple users in the tenant, whether the sending infrastructure is associated with known credential harvesting operations, and whether any user has interacted with the messages.
Spam alerts rarely escalate. Most are confirmed low-risk and closed automatically. The value is in the audit trail: a documented record of what reached the environment, when, and what ARIA determined.
ARIA does not scan the full body or attachments of messages for sensitive content patterns — it has no data loss prevention capability in email. Message content access is limited to metadata surfaces exposed by the Gmail API and Alert Center. This is an intentional scope constraint: content inspection raises significant privacy considerations and is out of scope for the current platform.
ARIA also does not modify email routing, quarantine messages, or block senders automatically. Any containment action — revoking a compromised account's sessions, removing an inbox rule — is proposed by ARIA and executed only after a security engineer approves it.
A 30-minute call, a read-only ARIA agent connected to your Google Workspace tenant, and a findings report within 48 hours — including open Alert Center findings ARIA would have triaged.
Book Free AssessmentARIA monitors identity, endpoints, and cloud activity alongside email — the same triage pipeline handles all four.
View All Use Cases