verifiedagents.ai
All posts

5 min readAI Agents · Cybersecurity

Your Fastest AI Inventory Is an OAuth Screen You Already Own

By Josh Woodruff, Founder & CEO, MassiveScale.AI | Founding Chair, Agentic Trust Framework at the CSAI Foundation

Hero: Your Fastest AI Inventory Is an OAuth Screen You Already Own

TL;DR: Every time someone clicked "allow" to connect an AI tool to email, files, calendars, or offline access, your identity provider recorded it as an OAuth consent grant. That makes Entra, Google Workspace, Okta, or whatever you run your fastest AI inventory: a 30-minute walkthrough, no new product, no budget. Most teams find far more connected tools than they expected.

Last updated October 5, 2026. Rebuilt for verifiedagents.ai as the step-by-step audit, with the same-afternoon lockdown.

It's the record created the moment someone clicks "allow" to connect an AI tool to their accounts. Microsoft Entra logs a person's own approval as an object called oAuth2PermissionGrant, and an app-to-app connection as an app role assignment. Either way, the click got recorded somewhere you can read, whether IT approved the tool or not.

That click is the whole control event. Someone connects a note-taker to their calendar or a writing assistant to their inbox, and the tool now runs with that person's access, indefinitely, until somebody revokes it.

George Gerchow describes three places shadow AI shows up: the endpoint, the browser, and identity. Most teams watch the first two. Almost nobody checks the third, and the third is free to pull this week.

Why is this the fastest inventory you own?

Because the data already exists and self-counted lists are wrong. Todd Inskeep, an IANS Faculty member, said in June 2026 that CrowdStrike's services team has never found a company with an accurate AI inventory. One client counted 150 agents on its own list. CrowdStrike found more than 500 running.

I've run this walkthrough with three clients between June and September 2026: a global manufacturer, a big-box retailer, and a two-person security team at a therapeutics company that did the whole thing live on one call, no scripting. Three industries, same finding every time. The screen with the answer had been open the whole time.

How do you audit OAuth grants in Microsoft Entra?

Four steps, about 30 minutes, one person.

  1. Open the Entra admin center and go to Enterprise applications, then All applications. Every tool anyone ever clicked "allow" for is a row, consumer AI apps included.

  2. Set the filter to Application type equals Enterprise Applications and sort by created date. The newest rows are your discovery list.

  3. Open anything you don't recognize and click Permissions. The user consent tab shows who approved it and what it reaches: mail, files, calendar, offline access, and whether it can write and send or only read. Broad write access goes to the top of the review pile.

  4. Export the list and add one column: owner. That sheet is your agent registry, version one.

Microsoft publishes its own guide covering the admin center path plus the PowerShell and raw Graph API routes, whichever your team can run.

What about Google Workspace and Okta?

Provider

Where the record lives

What to watch for

Microsoft Entra

Enterprise applications, Permissions tab

Write and send scopes, offline access

Google Workspace

Admin console, Security, API controls

Domain-wide delegation: those apps can act as any user, not just the approver

Okta

System Log token grant events

Which app called on behalf of which person

Okta's silent-consent surface is smaller because admins provision most access there, so the log review does the same job the Entra screen does.

What should you do the same afternoon?

Close the front door before you start pruning. In Entra, change User consent settings from "anyone can consent to anything" to verified publishers only, or admin consent only, and turn on the admin consent workflow so new requests route to a named reviewer.

Then revoke what fails an honest look, and tell each person before you do it. A controlled re-request path turns a blunt prune into a real filter, and it shows you who actually depended on what. From there, right-size what survives using least privilege for AI agents.

One thing to say plainly: a consent policy stops new grants from piling up. It does nothing about an already-approved app that starts behaving badly later. That's a separate monthly check, owned by whoever administers that platform.

Where is this heading?

Toward removing the consent screen entirely. Enterprise-Managed Authorization moves the approval from an individual's click to a policy your identity provider enforces up front. Okta shipped the first version, Cross App Access, with Anthropic as a launch client on the connecting side. One login, policy decides which AI tools a person can reach, one place to revoke. Plan for it next year. Do the lockdown with what you have now.

Frequently asked questions

Do I need to buy a tool to find shadow AI this way?

No. Every identity provider already logs this, and the admin screens are included in what you pay today. Discovery products add risk scoring and automation on top.

What's the difference between a delegated permission and an app permission?

Delegated is what one person approved for themselves. An app permission runs on its own, tied to no person's click. Both appear on the same Entra screen, under different tabs.

Will revoking a grant break something?

It can, so tell the person first and publish the approved path before pruning. People who actually needed the tool ask for a re-review. People who forgot it existed don't.

Does this catch every AI tool in the company?

No. Only tools connected through your identity provider. A tool on a personal email, used only in a browser, leaves no trace here. For that population, use the network and finance sweeps in the shadow AI playbook.

Key takeaways

  • Every "allow" click left a record you can read today, for free.

  • Self-counted inventories run short. 150 claimed, 500 found.

  • Thirty minutes in Entra produces registry version one.

  • Lock consent settings the same afternoon, then prune with warning.

  • Policy-based authorization is coming. The cleanup is yours to do now.

Measure the blast radius you already own

The free ATF assessment takes about ten minutes and scores how governed your connected agents really are.

The screen with the answer has been open the whole time. Somebody just has to look at it.

See where your agents stand.

The free assessment takes ten minutes and scores you on the five elements of the Agentic Trust Framework.