Why ForgeWatch

It sees everything your workforce connected. It can change nothing.

Read-only without exception, nothing installed, one authorization to a complete inventory, evidence an auditor accepts, and a person who reads every finding. That is the whole case — the rest of this page is the proof.

The blind spot

Your security stack was built for a different layer.

An OAuth grant is a standing permission living in your identity provider. It is not a file, not a device, and not network traffic — so the tools that guard those three things never see it.

Your endpoint tools watch laptops.

An OAuth grant never touches a laptop. It is a standing permission your identity provider hands an app, and it keeps working after the browser tab closes, after the employee goes home, and after they leave the company.

Your firewall watches the network.

Cloud-to-cloud access never crosses it. When an AI notetaker reads a mailbox, the traffic runs between the vendor and Microsoft or Google — nothing on your side sees a packet.

Your admin console lists apps — one at a time.

The native consoles show a grant if you know where to click, but not what it can reach in plain language, not when it was first authorized, not what changed since last quarter, and not in a form an auditor will accept.

Six reasons

What you are actually buying.

  1. 01

    Read-only. No exceptions.

    Read-only on Microsoft 365 and Google Workspace · never a write scope

    ForgeWatch never requests a write or mutate scope on any provider — that is a design constraint, not a setting. It can see what an app was granted. It cannot change, delete, revoke, or send anything in your environment. The tool that sees everything holds no keys of its own.

  2. 02

    Nothing installed. Anywhere.

    0 agents · 0 installs

    Collection is cloud-to-cloud. No endpoint agent, no browser extension, no per-employee rollout, no change-management ticket. Your people never notice the scan — and nothing has to be maintained on the machines they carry around.

  3. 03

    One authorization to the whole picture.

    First inventory within days, historical grants included

    A single admin consent stands up discovery. The first inventory includes every app holding a token today, the scopes it holds, who granted it, and grants authorized years ago by people who have since moved on — not just the tools somebody remembered to write down.

  4. 04

    Evidence that survives an auditor.

    4 frameworks · timestamped · exportable

    Findings seal into timestamped reports mapped to HIPAA, SOC 2, PCI-DSS and ISO 27001. When the examiner asks what AI can touch regulated data, you hand over a dated record with the controls it maps to — not a screenshot from the night before.

  5. 05

    A person reads every finding.

    Findings, not alerts

    Software finds the grant; someone still has to say what it means for a clinic or a law firm. Every engagement puts an analyst between the scan and your inbox — with a plain-English explanation, exact revocation steps, and a note for the employee that doesn’t accuse anyone of anything.

  6. 06

    Built for small regulated businesses.

    Per-organization pricing · no security team required

    Enterprise SSPM and CASB suites assume a security team to run them and a budget to match. ForgeWatch is priced per organization, set up in one call, and written for the owner or compliance lead who has to answer for it — not for a SOC that does not exist yet.

The alternatives

How it compares to what you could do instead.

Categories, not vendors. Each one is a reasonable choice for some businesses; none of them was built for the identity layer at a small-business budget.

CapabilityForgeWatchEndpoint agentEnterprise CASB / SSPMManual audit
Sees OAuth grants made cloud-to-cloudYesNoYesPartly
Nothing installed on employee devicesYesNoPartlyYes
Never holds write access to your dataYesPartlyPartlyYes
Historical grants, including departed staffYesNoPartlyNo
Evidence mapped to HIPAA / SOC 2 / PCI-DSS / ISO 27001YesNoPartlyNo
A person explains each findingYesNoNoPartly
Runs without a dedicated security teamYesPartlyNoNo
Stays current between auditsYesYesYesNo

yes partly / depends on product○ typically no

We’d rather you know

What a grant scan cannot see.

A tool that claims to see everything is a tool you cannot trust at exam time. Here is where our visibility ends, and what we do about it.

  • Personal accounts.

    If an employee pastes client data into a chatbot under a personal login, no grant exists in your directory for us to read. We say so in the analyst concerns memo rather than let a clean report imply otherwise.

  • Tools bought on a card with no login tie-in.

    SaaS paid for on an expense report and never connected to your identity provider is invisible to a grant scan. An expense-CSV import closes part of that gap; we are honest about the rest.

  • Revoking for you.

    Read-only means read-only. When something has to go, you get the exact steps for your admin console and a draft note for the employee — the click stays yours, by design.

Safe to connect

Safe to authorize — and you can prove it.

The absence of footprint is the trust story. Every line below is a design constraint we hold ourselves to, not a setting you have to remember to turn on.

Read-only scopes only

Enforced in code. Never a write or mutate permission.

No credentials held

Consent lives in your directory. We cannot log in as your users.

Revocable in one step

Remove the app from your tenant and access ends immediately.

Data minimization

We store the fact of a grant and its scope — never the contents it can reach.

Tenant separation

Every record keyed to your organization; one client never sees another.

Encrypted in transit

TLS on every connection to providers and to report recipients.

The full posture, including how we protect our own keys, is on the Security page.

Fair questions

The things people ask before they say yes.

Doesn’t our MSP already handle this?
Most MSPs manage devices, patches, backups and the help desk. OAuth grants sit in the identity layer, outside that scope, and few MSPs have tooling that reads them — which is why we also offer ForgeWatch white-labeled to MSPs for the clients they serve.
We can see apps in the Google or Microsoft admin console.
You can, one app at a time, if you know the page. What the console will not give you is scopes translated into plain language, the date a grant was first authorized, what changed since your last review, and a dated report mapped to your framework.
We don’t really use AI.
That is exactly the environment where the first inventory surprises people. Notetakers, scheduling assistants, browser extensions and CRM add-ons acquire AI features quietly, and the grant an employee approved two years ago still stands.
Will it disrupt anyone?
No. There is nothing to install, nothing runs on a device, and the scan reads metadata your provider already keeps. Employees are not notified by the scan itself; how you handle a finding with them is your call, and we draft the note.
Can it break anything?
It cannot. ForgeWatch holds no write permission, so there is no code path that changes your environment. The worst case is that you learn something you would rather not have known.
What if we want out?
Remove the ForgeWatch application from your tenant. Access ends that instant, with no action required from us.

See what your workforce already connected.

One read-only authorization. A complete inventory within days. A person to walk you through every line of it.