The token is the lateral movement
We spent a decade talking about identity as the new perimeter and then measured identity as human logins. MFA adoption charts went up. Grant counts went up faster. Each refresh token is a persistent delegate. It does not care that the laptop is off. It does not prompt MFA. It looks like the integration working, because it is.
Attackers noticed. They still phish, but they also break vendor vaults. Salesloft Drift, Context.ai, connector platforms next to Snowflake tenants: the blast radius was a consent screen, not a firewall rule. This is the why-now behind ScopeMantle. It is not a vibe. It is a data path. Read shadow OAuth for the packet flow and the playbook for the five public patterns.
Why procurement and CASB both miss it
Finance sees invoices. Freemium extensions and chat widgets often create none. Procurement sees POs. OAuth creates a consent click. CASB sees proxied browsing. After Allow, the interesting traffic is vendor-to-Google or vendor-to-Salesforce from a data center you do not own. Impossible-travel SIEM rules do not fire. There was no travel.
You cannot watch this at the edge without inventory at the IdP. That sentence is the architecture note I want in your last review deck.
What changed since 2020
SaaS sprawl was already here. AI copilots and browser extensions asked for mail and Drive because summaries are empty without content. Grant volume per employee climbed. I will not invent a multiplier and call it research. Look at your own Admin list versus a 2021 export if you have one. The direction is not subtle.
Remote work removed the "ask IT for a license" friction. OAuth replaced the ticket. Department budgets funded RevOps tools outside the catalog. Shadow IT became shadow identity. Worse, because the token works when the device is in a drawer.
Board metric that does not waste the hour
Pair MFA adoption with live grant count and below-threshold count. Directors already understand MFA. The gap (MFA high, grants higher) is the story. Actions this quarter belong on the same slide or you look like a dashboard, not a program. Use the template. Example figures there are examples, not our customer metrics. We do not publish those.
Cyber-insurance questionnaires have started asking about OAuth or "third-party API access." An inventory export answers without claiming a certification you do not hold. Do not tick "CASB covers OAuth" unless you have seen client IDs come out of that product.
Red team and IR
Ask the red team for an "assume vendor vault" TTP, distinct from the phishing budget line. Tabletop it quarterly. Target hours to workforce revoke of a fictional client ID. Under four hours is reasonable once inventory exists. Without inventory, you will miss Monday. That drill is also CC9.2 monitoring evidence.
Control loop
Inventory, score, govern, DSAR. Same data. Platform is the productization. Google and Okta GA. Entra Beta. $5 / $6, no seat min, custom 500+, trial. HIPAA not attested. No fake logos on customers.
What to do this week
- Export Google Admin third-party apps. Put the count next to last quarter's MFA slide in a draft.
- Write the architecture sentence: refresh bypasses CASB and ZTNA.
- Add the vault-theft inject to the next tabletop.
- Read Drift, Context.ai, and Snowflake breakdowns before the next board prep.
A 45-minute briefing you can give a director
Minute 0 to 5: show one consent screen with gmail.readonly highlighted. Say the token works when the laptop is off. Minute 5 to 15: Drift in two slides (widget, vault, Salesforce API, hundreds of tenants in public reporting). Minute 15 to 25: your Admin grant count versus last year if you have it, or versus headcount if you do not. Minute 25 to 35: MFA chart next to that count. Minute 35 to 45: ask for a policy (extension allow-list plus 90-day attestation) and a tool budget. Sit down.
Do not spend the hour on our origin story. Do not invent a TAM slide. Do not claim we were in Vercel's tenant. The Context.ai write-up is explicit about that.
What "closed loop" means in practice
- See the grant the day it appears.
- Score it so a human knows whether to care this week.
- Attest or revoke.
- When a vendor discloses, revoke by client ID, not by brand search.
- When a human leaves, revoke their grants, not only their password.
- When a subject asks, write to the vendors the inventory actually lists.
That is audit, score, govern, DSAR. Prevention at consent time is Roadmap. Until then, browser policy is your prevent. Inventory is your detect and respond. Teams that only prevent will still own yesterday's tokens. Teams that only inventory will still watch new grants appear every Monday. Do both.
Insurance, red team, and the SOC
If the questionnaire asks about third-party API access, attach an export. If it asks whether you have a CASB, say yes if you do, and add a sentence that CASB does not inventory refresh tokens. Lying here is how claims get ugly later.
SOC use cases: page on breach-feed match and on admin.directory from an unknown publisher. Do not page on every new calendar scope. You will train people to ignore the channel. Event stream to Splunk or Datadog is GA if you want the metadata in the SIEM. Elastic is Beta. Chronicle is Roadmap.
Red team: give them a fictional client ID and a four-hour clock. If they cannot find the revoke button, the program is a blog post.
What this is not
It is not a claim that passwords are dead. It is not a claim that MFA was a waste. It is not a TAM slide. It is not a promise that inventory prevents the next vault theft. Inventory plus revoke reduces time-to-contain and gives you a processor list when privacy wakes up. Prevention at consent is Roadmap. Browser allow-lists are available today without us.
It is also not a reason to buy endpoint agents. We do not ship one. Google and Okta APIs are enough for the grant list. Entra is Beta. If a vendor tells you they see OAuth by sitting on the laptop, ask them to show a client ID that was authorized from a personal Chrome profile on a managed device. Then ask again about vendor-to-IdP refresh.
Reading order for a new CISO
- This page, for the sentence you will reuse.
- Shadow OAuth, for the data path.
- Drift, then Context.ai, then Snowflake, for the three flavors.
- Playbook, for the binder.
- Board template, so the next committee is not a TED talk.
$5 / $6, no seat min, custom 500+, trial. No fake customer counts. HIPAA not attested.
Field guide: writing the architecture note
One page. Title: OAuth refresh is out of band from CASB and ZTNA. Paragraph 1: consent hop versus vendor-to-IdP refresh. Paragraph 2: why MFA charts mislead when grant counts climb. Paragraph 3: which IdP exports you will keep. Paragraph 4: Friday revoke target. Paragraph 5: honest gaps (Entra Beta, Salesforce Connected Apps, warehouse keys). Attach it to the last architecture review. Then export Admin so the note is not poetry.
Insurance questionnaires get the export, not a yes-CASB-covers-it tick. Red team gets a fictional client ID and a clock. Board gets the one slide. $5 / $6, no seat min. Reading order above still stands. Trial.
Mistakes I keep seeing after the first workshop
People export once and call it culture. People revoke by display name after a rebrand. People promise Entra completeness. People put OAuth rows in the user-access matrix. People send DSAR mail without a case ID. People treat a CASB invoice as grant inventory. People change a score threshold the night before audit. People staff an MSSP sprint with someone who cannot read a scope string. Each of those has a fix already on this page. The failure is skipping the fix because the demo looked polished.
Write the one thing you will not skip this week. Put it on a calendar. If you want the inventory to stay current, the 30-day trial is the productized version of the export. Five dollars per employee per month billed annually, or six dollars monthly. No seat minimum. Custom terms at 500+ employees. Microsoft Entra stays labelled Beta. HIPAA is not attested. Templates stay operator-reviewed. No fabricated customer counts on the customers page.
If you are evaluating us next to a GRC tool, keep both jobs honest. If you are evaluating us next to a consent-intercept tool, stack prevention and inventory. If you are an MSP, register the deal before the demo and keep the counsel gate in the SOW. If you are writing a board slide, use last quarter as the only benchmark we will stand behind. That is enough program for a quarter. The next quarter is whether the leftover-grant count actually moved.
A note for the CISO writing next quarter's narrative
Pair MFA with grant count. Ask for a policy and a tool budget in the same forty-five minutes. Put assume-vendor-vault on the red-team calendar. Attach an export to the insurance questionnaire. Do not tick CASB-covers-OAuth unless you have seen client IDs come out of that product. We will not invent a TAM slide or a customer count to make the narrative prettier.
What you can do without buying anything
Export the IdP list. Deduplicate on client ID. Revoke three rows you cannot explain. Write the CC9.2 versus CC6.7 sentence for your auditor. Add OAuth grants equals zero to offboarding. Put an extension allow-list in one OU. Schedule a Friday tabletop with a fictional client ID. Hash a file and put it in GRC. Those steps do not require ScopeMantle. They do require a calendar and a human who will not skip them.
When those steps start to rot (and they will, usually by week six), the productized version is daily Google and Okta sync, scores, attestation expiry, bulk revoke, and DSAR snapshot on the same inventory. Price is public. Beta labels stay on the page. We will not invent a case study to make the last paragraph feel finished. Start the trial if the calendar is already losing.
Draft the one-page architecture note this week even if the diagram is ugly. Attach last quarter's grant count. Ugly plus dated beats pretty plus theoretical. Insurance and red team can reuse the same page.
Related reading stays on the internal paths already linked above: platform, integrations, demo, and the companion resources or blog posts for this topic. Use those links when you brief a colleague so they get the same product truth: public $5 / $6 pricing, no seat minimum, custom at 500+, Entra labelled Beta, DSAR templates operator-reviewed, no HIPAA attestation, no invented logos. That is the briefing. Everything else is the procedure you can run this week.