snoka — security scanner for Google Workspace built in Sweden · contact@snoka.app

Workspace security audit, from your terminal

Find what your Workspace is exposing.

Snoka inspects every user, file, group and admin setting in a Google Workspace tenant, scores its security posture, and produces an audit-ready report — from a terminal on your machine, with nothing installed in the tenant and no key files to guard.

scanning is free · reports, email & remediation are Pro

snoka — scanbash
$ snoka all ########## ## -+####++### ## ###++######++##. #++#++++## #### # #-######- ## # ### # +++++++# # #### ####+++#### ### ###+ #+-#+++## # +# # ###+..#++#+++++. .#### ######### ##### #### ######## #### #### ###### # . # +##+####### ##### #--++ ### ###### ## #### #### ### ### ###### # . # +#+++#++ .########- -# #+# # ######### ### ### ## ### ### ###### ### ### +. - #-+##+######+#+############# # ### ###. ##### #### #### ### #### ########## # -# ##### # # . . . ############# ######### #### ##### ######## #### #### #### ### # # ##+###+ # # ########### +# # #.#+++### # # # # # #-###+++# # # # # ##+++++++# # # # . +# ### #-#+++++#++ #-+ . # ########++#### ### # ############### .. .# .########+ # ############################################ Snoka 1.0 — noses through your Workspace and finds what's exposed ▶ Drive external-sharing scan Sniffed 48 users — found 12 exposed files (3 high)▶ Account & 2SV hygiene Checked 48 accounts — found 7 issues (1 high)▶ External mail forwarding & delegation Checked 48 mailboxes — found 2 forwarding issues▶ Admin-console policy posture Sniffed 257 policies — found 9 risky settings Security score: 61 / 100 (D) — Significant gaps ✉ Report emailed to admin@yourdomain.com$
Fig. 01 — a full tenant scanten checks, one command
01Index of checks

Ten checks cover the leaks that cause real incidents.

Oversharing, quiet mail forwards, over-permissioned OAuth apps, risky tenant defaults, suspicious sign-ins, spoofable domains — found in one pass, deduplicated, and tracked scan-over-scan.

IDCheckWhat it flagsCIS controls
drive-shares Drive external sharing Files visible to anyone with the link, or shared to external people, groups and domains — across every user's Drive. 4.2 – 4.4
shared-drives Shared-drive exposure External members and organizers on shared drives, and files opened to anyone by link or public search. 4.2 – 4.4
account-hygiene Account & 2SV hygiene Admins without 2-step verification, unenrolled users, stale and suspended accounts. 1.1, 1.2
third-party-apps Third-party app access OAuth grants holding full Gmail, full Drive or admin scopes, rated by reach — plus app passwords that skip 2SV. 2.1, 2.3
mail-forwarding Mail forwarding & delegation Auto-forwards, forwarding filters and mailbox delegates pointing outside the organization. 5.1, 5.17
group-exposure Group exposure External members and owners; groups anyone on the internet can join, read or post to.
admin-policy Admin policy posture Tenant-wide settings left risky: 2SV enforcement, password rules, session length, sharing defaults, POP/IMAP and more. 1.1 – 5.17
sign-in-activity Sign-in & suspicious activity What Google itself flagged in the last 30 days: suspicious sign-ins, leaked-password and hijack suspensions, failed-sign-in bursts.
admin-audit High-risk admin changes Access-expanding actions from the last 90 days: new super admins, admin-role grants, new domain-wide delegation, 2SV rollbacks.
email-auth Email authentication Missing or weak SPF, DKIM and DMARC records that let outsiders send mail as your domain.
02The report

Evidence you can hand to an auditor. Or a customer.

2.1Security score, 0–100 with a grade

Severity-weighted, so one critical exposure outweighs ten trivia. Trends show what appeared and what got fixed since the last scan.

2.2CIS benchmark mapping

Findings cite controls from the CIS Google Workspace Foundations Benchmark; the appendix lists every assessed control as CLEAR or OPEN.

2.3Audit appendix

Methodology, an accepted-risk register, and the log of every remediation action — each report is self-contained evidence.

2.4PDF for people, CSV and JSON for machines

Share the PDF, pipe the JSON into your tooling, keep the CSVs for the record.

Snoka Workspace security report

report id: security-report-2026-07-07 · snoka v1.3 · domain: yourdomain.com

A
96 / 100 — Strong posture

2 new · 5 resolved since last scan

HIGH 0 MED 1 LOW 2
CLEARCIS 1.12-Step Verification enforced for admins
CLEARCIS 2.1Less secure app access disabled
OPENCIS 4.3Only internal users distribute content externally
CLEARCIS 5.1No mailbox delegation to external accounts
CLEARCIS 5.17Automatic forwarding disabled
Fig. 02 — the PDF your auditor receivesgenerated by every scan
03Setup

Running in minutes, not a services engagement.

A guided wizard walks through the one-time Google Admin steps with pre-filled links. There is no key file to download, store, or rotate — ever.

STEP 1

Install

Any machine with Node 18+ — Windows, macOS or Linux. Run snoka and the wizard takes it from there.

STEP 2

Sign in with Google

A browser sign-in, then one click on a pre-filled delegation link in your Admin console. Read-only scopes by default; short-lived tokens only.

STEP 3

Scan, schedule, fix

Run snoka all, schedule it daily with the report emailed to you, and revoke risky access from the review queue — confirmed, logged, reversible.

04Privacy

There is no Snoka cloud.

Snoka is a command-line tool, not a SaaS. Scans run on your computer against Google's own APIs; reports are written to your disk and emailed by your admin account through Gmail. None of it ever reaches us — there is no backend to breach.

  • We never see your tenant, your files, your users, or your findings.
  • Read-only by default — write access is a separate, explicit opt-in.
  • Every remediation re-verifies live, asks for confirmation, is logged — and can be reverted.
data flowcomplete
┌───────────────────┐ ┌───────────────┐ │ your machine │ ⇄ https │ Google APIs │ │ │ └───────────────┘ │ findings.json │ │ reports/*.pdf │ │ history/ │ there is no third box. └───────────────────┘
Fig. 03 — everything Snoka talks toexhaustive
05Pricing

Scanning is free. Evidence and automation are Pro.

Free

A first look at your posture

€0

  • All ten security checks
  • Security score in the terminal
  • Findings triage & review queue
  • One domain
Recommended

Pro

IT admins who own one tenant

€19 / month

per domain · 14-day free trial

  • Everything in Free
  • Audit-ready PDF, CSV and JSON reports
  • CIS benchmark mapping & appendix
  • Email delivery & scheduled scans
  • Remediation with one-command revert
Start 14-day free trial

MSP

Teams managing client tenants

€99 / month

up to 10 tenants · 14-day free trial

  • Everything in Pro
  • License covers 10 customer domains
  • Priority support
  • White-label reports — planned
Start 14-day free trial

prices exclude VAT · checkout and invoicing by Polar · cancel any time · 14-day refund policy

your license key arrives by email right after checkout — unlock Pro with snoka license activate <key>

06FAQ
What does "keyless" actually mean?

Most Workspace tools ask you to download a service-account JSON key — a permanent credential that can leak. Snoka never uses key files: you sign in with your Google account, and it mints short-lived tokens through domain-wide delegation. Nothing long-lived is ever written to disk.

What access does Snoka need?

Read-only scopes for scanning: directory, Drive metadata, Gmail settings, groups and policy data. Remediation and email delivery each need one extra scope, are off by default, and are enabled by you with a pre-filled Admin console link.

Does any of my data reach your servers?

No. Snoka has no backend. Scans, reports and history live on the machine you run it from. The only thing that ever talks to us is license validation — your key and plan, never tenant data.

Which Google Workspace editions does it work with?

Any edition with API access — Business Starter and up. You don't need the Enterprise tier: Snoka provides posture reporting Google reserves for its most expensive plans.

What do I need to run it?

A super-admin account, a machine with Node 18+ (Windows, macOS or Linux), and about ten minutes for the guided setup. On Windows, Snoka sets up a scheduled scan for you (Task Scheduler); on macOS or Linux it hands you a ready-to-paste cron line.

Is it safe to let it fix things?

Remediation is opt-in and conservative: every action re-checks the live state, asks for confirmation, and is written to an audit log with an undo payload — what Snoka removes can be restored with one command. The one exception is revoking an OAuth app grant, which only the user can re-authorize; Snoka tells you so before you confirm.

I subscribed — how do I activate Pro?

Your license key arrives by email from Polar right after checkout. On the machine that runs the scans: snoka license activate <key> — before or after setup, either works. snoka license shows what's active. One key covers one domain (Pro) or up to ten (MSP).

Ten minutes from now, you could know.

One scan. Every quiet leak. A score you can track, a report you can hand over.