Auditex for Google Workspace

Google Workspace audits.
Read-only by design.

Check Gmail forwarding, Drive sharing, Calendar access, groups and devices with a read-only domain-delegated or OAuth run. Review findings and coverage gaps in the same report-pack contract as Microsoft 365.

Read-only, for tenants you own or may audit.
Not certification, not legal advice and not guaranteed security.

Explore
Auditex for Google Workspace: Terminal running Auditex on the Google Workspace demo, with proof-table, API-inventory and verify-pack results.View screenshot
Rendered from Auditex’s offline demo run on its sample tenant
Read-onlyNo content readsLocal raw evidence

Explore the evidence

From Gmail and Drive
to one report pack.

Sharing and forwarding.
Found and ranked.

Auditex flags mail forwarded outside the domain, files shared with anyone, external calendar access, open groups and stale or compromised devices, each tied to its evidence.

High-severity findings from the demo domain, from 2-step verification to external Drive access.View screenshot

Recorded collectors.
Read-only audit evidence.

Directory, Gmail settings, reports, alerts, devices, DNS, Drive, groups and Calendar collectors record what was attempted and the class of data touched. The API inventory lets you inspect the run’s read-only boundary and its gaps.

API call inventory for the demo domain: nine GET calls with their data classes.View screenshot

In detail

One contract.
Both suites.

Google runs produce the same manifest, evidence index, validation file and customer pack as Microsoft 365 runs, and pass the same verify-pack checks.

Customer pack verification for the demo domain with no issues.View screenshot

Get started with Auditex.

  1. Get Auditex.

    Clone the repository and install it with Python 3.11 or newer on macOS, Linux or Windows. Google Workspace and MCP support use optional dependencies.

  2. Grant read-only access.

    Run auditex setup-guide for the exact roles or scopes, then sign in with a reader account for a tenant you are authorised to audit.

  3. Review the pack.

    Read the findings, proof table and API inventory locally, then run auditex report verify-pack before you hand anything over. Review recorded coverage gaps alongside the findings.

Good to know

A few details.

Does Auditex change anything in my tenant?

No. The public audit surface is read-only. The separate lab-bootstrap toolkit is a distinct setup tool. Validation fails a run whose API inventory reports tenant writes or mailbox and file content reads.

Where does the evidence go?

Raw evidence stays on the machine that ran the audit. Normalised records, findings and MCP-ready report packs (for Model Context Protocol clients) are the surfaces meant for review and for AI assistants.

Is the report a certification?

No. Auditex is not certification, not legal advice and not guaranteed security. It gives a reviewer evidence to check; a person still makes the judgement.

Who may run it?

Only people who own the tenant or have the owner’s written authorisation. In the UK, unauthorised access is an offence under the Computer Misuse Act 1990; similar laws apply elsewhere.

What does it cost?

Nothing. Auditex is free and open source under the Apache License 2.0. Source, docs, issues and releases live on GitHub.

Workspace evidence.
Kept local.

View Auditex on GitHub