Vector 02 · App

Every app that touches your tenant, with what it can reach.

App shows every application, AI tool and OAuth grant connected to your tenant, with what each one can reach and who granted it. When a grant carries a scope it should not have, or a consent request arrives from a publisher nobody knows, it revokes automatically, via the Workspace and 365 admin SDKs.

Orvander Holdings/Vectors/App
AUG 24 - AUG 31 · 2026
Apps connected
34
via Microsoft 365
OAuth grants
128
+6 this period
Risky scopes
6
across 4 apps
Pending review
1
scope grant
Activity · AppGrantsRisky
LAST 7 DAYS
02402424 Aug25 Aug26 Aug27 Aug28 Aug29 Aug30 Aug31 Aug
Connected apps View findings
AppDomainUsersScopesRiskLast activity
Notelynotely.app42Mail.Read · Files.ReadWrite.AllReview2 days ago
Chatterchatter.io118openid · profile · offline_accessOK5m ago
Codehubcodehub.dev36repo · read:orgOK1h ago
Sketchlysketchly.co21files:readOK3h ago
Prooflyproofly.ai9Mail.Read · Mail.SendRisky6 days ago
Meetnote AImeetnote.ai14Calendars.Read · Mail.ReadReview1 day ago
Docsigndocsign.eu27Files.Read.All · profileReview4h ago
Needs review 1 open
Unusual scope grant: Notely → Mail.Read, Files.ReadWrite.All
daniel.chen@orvander-holdings.com · #4826 · 2 days ago
Review

Every connected app, every grant, and the one scope change waiting on a decision.

67%of users reach AI services from non-corporate accounts on corporate devicesVerizon DBIR, 2026
45%of employees are now regular AI users on corporate devices, up from 15% a year earlierVerizon DBIR, 2026
increase in shadow-AI policy violations, now the third most common non-malicious insider actionVerizon DBIR, 2026
What it evaluates

Full app inventory

Every third-party application employees have connected, including AI tools nobody approved.

Scope-level risk

Which apps can read mail, files or contacts, and which only need a profile.

Consent phishing

Malicious OAuth grants that never need a password, blocked before an employee can approve them.

One-click revoke

Remove risky grants without waiting for a ticket.

The riskiest app is the one someone connected

A third-party tool granted mail, drive or calendar scopes keeps that access until it is explicitly revoked, and abandoned grants accumulate for years. Network and expense-based discovery miss all of it: free tiers leave no invoice, and remote adoption never crosses your network.

  • Full app and OAuth-grant inventory across Workspace and 365
  • Scope-level risk, per app and per user
  • Consent phishing blocked before the grant lands
  • One-click grant revocation, no ticket
Reads with

No vector works alone.

See it on your own signals.

Free for one account. Four minutes to connect Google Workspace or Microsoft 365.