Google Workspace access for AI

Your security team will actually approve this one

ShareWatch gives Claude scoped access to Google Docs, Sheets, and Slides with a complete audit trail, granular permissions, and zero content retention. Infrastructure-level enforcement — not prompts.

0
sensitive OAuth scopes requestedEvery scope ShareWatch asks for is non-sensitive under Google's own classification.
0
bytes of file content cachedNo Redis, no temp files, nothing on disk. A pass-through proxy by architecture.
70+
audit event types loggedReads, writes, deletions, permission changes, admin actions — with the policy chain.

This is what your auditor gets

Live tail

Live tail, search, filter, CSV export, or streamed to your SIEM in real time.

The ShareWatch audit log: every file operation with user, client, action, status, and the full policy decision
Who accessed what

User, file, MIME type, bytes, duration — every read, write, and create.

Which client did it

Claude Cowork, Claude Code, Browser, API — identified and badged per row.

Every denial explained

Expand a row for the policy decision, who set it, and a reference ID for the admin.

For security teams

Approve AI without approving your whole Drive

Org defaults, group policies, per-user overrides, deny-wins. Revoke a file mid-conversation. Export the evidence.

READ THE CONTROLS →
For engineers

drive.file scope, Zanzibar-inspired RBAC, no cache layer

Per-user OAuth tokens, SHA-256 hashed at rest. Structured events over Pub/Sub. Two minutes to a working connector.

READ THE DOCS →

Four answers to the questions that kill AI adoption

01 / Scope

“Can it read everything in Drive?” No.

Claude sees only files created through ShareWatch or explicitly picked by the user. No browsing, no shared drives. Google enforces it at the API layer — not us.

02 / Permissions

“Who decides who can write?” You do, three levels deep.

Everyone can read, Engineering can write, but not Jeff — Jeff deleted last month's financials. Deny wins, and the full evaluation chain is visible to admins and users.

03 / Revocation

“Can we pull it back?” Instantly, mid-conversation.

Block a file and it's gone from the session. Disable a user and every session is revoked. Re-enable with one click. Blocked attempts are logged with an audit reference.

04 / Retention

“Where does our content sit?” Nowhere.

Content passes through and is never cached, stored, logged, or written to disk. Per-user OAuth tokens, no shared service accounts. An architectural constraint, not a config flag.

Up and running in 2 minutes

01
Add the connector

One URL in Claude. No config files, no API keys.

02
Sign in with Google

ShareWatch requests only drive.file — the most restrictive file scope Google offers — and every scope it requests is non-sensitive under Google's classification.

03
Start working

Create docs, read spreadsheets, build decks. Everything logged, scoped, auditable.

Security by architecture, not by policy

No amount of prompt engineering bypasses an OAuth scope restriction. Enforcement lives at the infrastructure layer, where it can't be talked around.

OAuth 2.0 + PKCESHA-256 hashed tokensTLS 1.2+ enforcedZero content cachingReal-time SIEM exportPer-user token isolationSAML/OIDC SSOFile access via drive.file only
Where we are on compliance

ShareWatch is a few weeks old and does not have a SOC 2 report yet. It's on the roadmap — Type I first, then Type II — and we won't claim either until an auditor signs. Until then the controls above are the whole story, and they are verifiable today: read the audit schema, check the requested scopes on the Google consent screen, and see for yourself that nothing is cached.

Unedited, from the model being constrained
“Give me a clean refusal over a quiet hope. A denied API call is unambiguous. My judgment, under adversarial pressure, is not.”

— Claude, in an unedited review of the tools that constrain it

Pricing
Free for individuals

Full audit log and scoped access at no cost. Team and org plans add group policy, per-user overrides, SAML/OIDC SSO, and SIEM export.

SEE PLANS →

Ready to let your team use AI — safely?

The security controls your CISO requires. The AI access your team wants.

Get started Book a tour