Skip to main content

Company Audits External Tools and Finds 43 Services

A software engineer audits internal systems and discovers 43 external services with standing access to company data, highlighting OAuth risks.

AI-written
Inewgen
06 Oct 2026Source: Dev.to3 min read (0 views)
Share
Company Audits External Tools and Finds 43 Services

Stock photo for illustration only, not from the actual event

Font size
  • Found 43 external services holding standing access to Slack, Google Drive, code, and company contacts.
  • One service was a free CRM trial from 2024 that had been continuously syncing contacts for two years.
  • OAuth grants act as a supply chain where we hand keys directly to another company's security posture.
  • Mitigation involves maintaining an inventory, minimizing standing access, and batch-exporting data instead.

Following a round of secrets rotation and document reconnaissance, a vendor security breach headline prompted a critical question: who outside this building can read our data right now? The answer revealed forty-three external services holding standing access to company words, files, code, or customers. While most services were recognized, one turned out to be a free CRM trial from 2024 that had been continuously syncing contacts for two full years.

OAuth grants represent a supply chain we sign ourselves. Every grant functions as a key handed over to another company, tied directly to their security practices, employees, future acquirers, and their worst day. When a vendor suffers a data breach, attackers do not require your password because the vendor's grant handles the rest.

The inventory process began by checking every application installed on the organization via the GitHub API, followed by human-audited pages in Slack and Google Workspace settings. It also covered browser extensions logged into company accounts, payment processors, DNS records, monitoring dashboards, and registrars. An effective inventory requires five key columns: vendor, surface, scopes, data reach, and funeral plan, because you cannot revoke what you have never documented.

43External tools with standing access
2 yearsDuration of continuous contact syncing

One practical defense strategy involves replacing standing read access with a monthly batch export. For example, database event records can be dumped and compressed into a gzip file for a one-way upload, ensuring that a connection never left open cannot leak data. Furthermore, downgrading vendor permissions is often frictionless since most providers fail to notice, indicating how little they actually required those broad scopes.

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

software developer computer screen code workspace

Stock photo for illustration only, not from the actual event

Conducting a third-party OAuth audit is an essential security practice often overlooked in modern organizations. As software teams integrate numerous SaaS tools for convenience, forgotten API permissions accumulate over time. Regularly reviewing and minimizing these grants significantly shrinks the organization's security attack surface against upstream vendor breaches.

Certain grants remain load-bearing, such as Single Sign-On (SSO), backups, and payment processors. Organizations should tier vendors based on data reach and review them continuously. Small teams cannot inspect the internal security of 43 separate vendors, making it vital to minimize standing access instead of relying on vendor questionnaires.

Source: Dev.to

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article