Workspace security audit, from your terminal
Find what your Workspace is exposing.
Snoka inspects every user, file, group and admin setting in a Google Workspace tenant, scores its security posture, and produces an audit-ready report — from a terminal on your machine, with nothing installed in the tenant and no key files to guard.
scanning is free · reports, email & remediation are Pro
Ten checks cover the leaks that cause real incidents.
Oversharing, quiet mail forwards, over-permissioned OAuth apps, risky tenant defaults, suspicious sign-ins, spoofable domains — found in one pass, deduplicated, and tracked scan-over-scan.
| ID | Check | What it flags | CIS controls |
|---|---|---|---|
| drive-shares | Drive external sharing | Files visible to anyone with the link, or shared to external people, groups and domains — across every user's Drive. | 4.2 – 4.4 |
| shared-drives | Shared-drive exposure | External members and organizers on shared drives, and files opened to anyone by link or public search. | 4.2 – 4.4 |
| account-hygiene | Account & 2SV hygiene | Admins without 2-step verification, unenrolled users, stale and suspended accounts. | 1.1, 1.2 |
| third-party-apps | Third-party app access | OAuth grants holding full Gmail, full Drive or admin scopes, rated by reach — plus app passwords that skip 2SV. | 2.1, 2.3 |
| mail-forwarding | Mail forwarding & delegation | Auto-forwards, forwarding filters and mailbox delegates pointing outside the organization. | 5.1, 5.17 |
| group-exposure | Group exposure | External members and owners; groups anyone on the internet can join, read or post to. | — |
| admin-policy | Admin policy posture | Tenant-wide settings left risky: 2SV enforcement, password rules, session length, sharing defaults, POP/IMAP and more. | 1.1 – 5.17 |
| sign-in-activity | Sign-in & suspicious activity | What Google itself flagged in the last 30 days: suspicious sign-ins, leaked-password and hijack suspensions, failed-sign-in bursts. | — |
| admin-audit | High-risk admin changes | Access-expanding actions from the last 90 days: new super admins, admin-role grants, new domain-wide delegation, 2SV rollbacks. | — |
| email-auth | Email authentication | Missing or weak SPF, DKIM and DMARC records that let outsiders send mail as your domain. | — |
Evidence you can hand to an auditor. Or a customer.
Severity-weighted, so one critical exposure outweighs ten trivia. Trends show what appeared and what got fixed since the last scan.
Findings cite controls from the CIS Google Workspace Foundations Benchmark; the appendix lists every assessed control as CLEAR or OPEN.
Methodology, an accepted-risk register, and the log of every remediation action — each report is self-contained evidence.
Share the PDF, pipe the JSON into your tooling, keep the CSVs for the record.
2 new · 5 resolved since last scan
Running in minutes, not a services engagement.
A guided wizard walks through the one-time Google Admin steps with pre-filled links. There is no key file to download, store, or rotate — ever.
Install
Any machine with Node 18+ — Windows, macOS or Linux. Run snoka and the
wizard takes it from there.
Sign in with Google
A browser sign-in, then one click on a pre-filled delegation link in your Admin console. Read-only scopes by default; short-lived tokens only.
Scan, schedule, fix
Run snoka all, schedule it daily with the report emailed to you, and
revoke risky access from the review queue — confirmed, logged, reversible.
There is no Snoka cloud.
Snoka is a command-line tool, not a SaaS. Scans run on your computer against Google's own APIs; reports are written to your disk and emailed by your admin account through Gmail. None of it ever reaches us — there is no backend to breach.
- We never see your tenant, your files, your users, or your findings.
- Read-only by default — write access is a separate, explicit opt-in.
- Every remediation re-verifies live, asks for confirmation, is logged — and can be reverted.
Scanning is free. Evidence and automation are Pro.
Free
A first look at your posture
€0
- All ten security checks
- Security score in the terminal
- Findings triage & review queue
- One domain
Pro
IT admins who own one tenant
€19 / month
per domain · 14-day free trial
- Everything in Free
- Audit-ready PDF, CSV and JSON reports
- CIS benchmark mapping & appendix
- Email delivery & scheduled scans
- Remediation with one-command revert
MSP
Teams managing client tenants
€99 / month
up to 10 tenants · 14-day free trial
- Everything in Pro
- License covers 10 customer domains
- Priority support
- White-label reports — planned
prices exclude VAT · checkout and invoicing by Polar · cancel any time · 14-day refund policy
your license key arrives by email right after checkout — unlock Pro with snoka license activate <key>
What does "keyless" actually mean?
Most Workspace tools ask you to download a service-account JSON key — a permanent credential that can leak. Snoka never uses key files: you sign in with your Google account, and it mints short-lived tokens through domain-wide delegation. Nothing long-lived is ever written to disk.
What access does Snoka need?
Read-only scopes for scanning: directory, Drive metadata, Gmail settings, groups and policy data. Remediation and email delivery each need one extra scope, are off by default, and are enabled by you with a pre-filled Admin console link.
Does any of my data reach your servers?
No. Snoka has no backend. Scans, reports and history live on the machine you run it from. The only thing that ever talks to us is license validation — your key and plan, never tenant data.
Which Google Workspace editions does it work with?
Any edition with API access — Business Starter and up. You don't need the Enterprise tier: Snoka provides posture reporting Google reserves for its most expensive plans.
What do I need to run it?
A super-admin account, a machine with Node 18+ (Windows, macOS or Linux), and about ten minutes for the guided setup. On Windows, Snoka sets up a scheduled scan for you (Task Scheduler); on macOS or Linux it hands you a ready-to-paste cron line.
Is it safe to let it fix things?
Remediation is opt-in and conservative: every action re-checks the live state, asks for confirmation, and is written to an audit log with an undo payload — what Snoka removes can be restored with one command. The one exception is revoking an OAuth app grant, which only the user can re-authorize; Snoka tells you so before you confirm.
I subscribed — how do I activate Pro?
Your license key arrives by email from Polar right after checkout. On the
machine that runs the scans: snoka license activate <key> — before
or after setup, either works. snoka license shows what's active.
One key covers one domain (Pro) or up to ten (MSP).
Ten minutes from now, you could know.
One scan. Every quiet leak. A score you can track, a report you can hand over.