Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

The platform

Close the OAuth loop. Audit, score, revoke, deprovision, prevent.

ScopeMantle is the end-to-end platform for governing third-party OAuth access. Five capabilities, one identity connection, zero spreadsheets.

01 · OAUTH AUDIT

Continuous OAuth Audit

Most security teams are flying blind on third-party OAuth. The grants weren't really shadow, it's just that no tool was responsible for keeping the list current. ScopeMantle fixes that by treating your IdP as the source of truth and continuously pulling every OAuth grant, every connected service, every domain-wide install, without agents, without proxies, without anything you have to maintain.

We start with Okta and Google Workspace because that's where 80% of the signal lives. Within minutes of connecting, you have a complete inventory: app name, source, user count, scopes granted, first-seen timestamp, privacy-policy URL, and a risk tag derived from what each scope actually lets the app do. Microsoft Entra is on the roadmap; we'll connect to it the same way, read-only, revocable, no agents.

  • Continuous OAuth grant inventory across Okta, Google Workspace, and Entra (roadmap)
  • Full scope extraction, every grant, every user, every timestamp
  • Per-app user rosters with role and last-active context from your IdP
  • Policy-aware duplicate detection across sources (one Slack, not three)
  • Privacy-policy URL captured and version-tracked per vendor
  • Stale-token sweeps, flag unused 90+ day grants automatically
  • CSV, JSON, and direct SIEM export of the live inventory
Talk to an engineer
scopemantle.app/third-party-apps/zapier
ScopeMantleThird-Party AppsZapier
synced 12 min ago
ZP

Zapier

zapier.com High
Source: Google WorkspaceFirst seen: Jul 11, 2023Category: iPaaS / AutomationPrivacy policy: zapier.com/privacy

OAuth scopes · 21 granted

drive.readonlyMar 14, 2024Medium
gmail.sendMar 14, 2024High
calendar.eventsMar 14, 2024Low
admin.directory.user.readonlyAug 02, 2024High
chat.spacesMar 14, 2024Low
people.contacts.readonlyMar 14, 2024Medium

+ 15 more scopes

Users with access · 1,247

ARAnya Reyes2h ago
MPMark Patel4h ago
TLTom Liu1d ago
JDJane Doe1d ago
+1+ 1,243 more

Privacy analysis · refreshed 6d ago

Data categoriesIdentity · Email · Files · Calendar
Sub-processorsAWS, GCP, Stripe, Datadog
Cross-borderUS ⇄ EU (SCCs)
Retention24 months post-cancellation

02 · RISK SCORING

Vendor Risk & Privacy Posture Scoring

Every vendor in your inventory, including the long tail of small AI SaaS tools that manual vendor databases never cover, gets an automatic risk score within minutes of discovery. ScopeMantle's LLM analysis engine reads each vendor's privacy policy, security page, sub-processor list, and known breach history, and produces a confidence-scored posture assessment broken into four axes: Security, Privacy, Scope Sanity, and Breach History.

This is not a static database. Every score re-evaluates monthly, and a change in policy or a new breach disclosure pushes an alert into your event stream, Slack, or SIEM the same day.

  • SOC 2 / ISO 27001 / HIPAA presence detection per vendor
  • Scope-sanity red-flagging (the Context.ai signal)
  • AI-training-on-customer-data clause detection
  • Sub-processor graph per vendor
  • Correlation with HIBP, CISA, and public breach sources
  • Monthly re-score with change alerts
  • Source-cited, every score links to the policy passages that produced it
Talk to an engineer
scopemantle.app/vendors/context-ai
ScopeMantlePrivacy IntelligenceNotion
Claude Opus 4

Notion · privacy posture

notion.so/privacy
Last refreshed: 18 Apr 2026Doc revision: 2025-11-04Source pages parsed: 7
Data categories collected
94%

Identity · Communications · File contents · Behavioral telemetry

Sub-processors disclosed
97%

AWS (us-east-1, eu-west-1) · Stripe · Datadog · Twilio · Snowflake

Cross-border transfers
88%

EU → US under SCCs (2021/914) · UK IDTA · No data transferred to China

Retention windows
79%

Account data: 30d post-cancellation · Logs: 12 months · Backups: 35 days

Notification SLA (incident)
91%

72 hours from confirmed breach (Article 33-aligned)

Extracted facts are evidence-linked back to the source URL · re-runs monthly or on policy change detection

03 · GOVERNANCE

Access & Scope Governance

An inventory is the prerequisite. Governance is the work. ScopeMantle ships a policy engine that turns the rules you'd otherwise enforce by Slack reminder into rules the platform enforces continuously. Every policy is a small, declarative statement: "if scope includes admin.directory and users > 25, require review", that runs against the live inventory and against every new install the moment it appears.

Policies aren't a black box. The rule builder shows a live preview of which apps would match before you enable a rule, so you can ship governance without surprising 800 employees. When a rule fires, the action is yours: notify a channel, open a Jira ticket, require a one-click approval, or revoke the OAuth token outright. We expose the same primitives via a documented API so your SOAR playbooks can react too.

  • One-click and bulk-revoke OAuth tokens by policy or by query
  • Bulk-revoke by Vendor Risk Score (e.g., all vendors with Score < 40)
  • Auto-tag risky scopes (send_mail, modify_drive, admin.directory.*)
  • Approval workflows for new app installs via Slack, email, or Jira
  • Alerts on scope escalation, admin grants, and apps unused for >90 days
  • Rule builder with live match preview before enable
  • Programmatic API for SOAR integration, every action is callable
Talk to an engineer
scopemantle.app/governance/rules/new
ScopeMantleGovernanceRule builder

Conditions

WHENSourceisGoogle Workspace
ANDScopeincludesmail.modify
ANDUsers>25

Action

THEN Require review · notify #sec-governance

Preview · matches in current inventory

3 / 847
ZAZapier67 users
High
MIMixpanel86 users
High
REReplit12 users
Critical

+ 0 historical violations · Rule will not retroactively block.

04 · DSAR

DSAR & Privacy Automation

DSARs used to be a forensic exercise. A request would come in, someone in privacy would ping IT, IT would ping the data team, the data team would email vendors, and four weeks later, somewhere around day 28 of the GDPR clock, a partial answer would land in a shared drive. ScopeMantle replaces that with a workflow that closes itself.

The intake portal is hosted, branded, and accessible. When a request lands, we match the requester against your IdP and connector user rosters to identify every internal system that holds their data. We then dispatch pre-composed Article 15 / 17 / 20 outreach to every vendor with a record of the subject, track acknowledgements and fulfilments against the 30-day clock, and assemble an evidence package the day the request closes. Audit-ready, regulator-ready, board-ready.

  • Public-facing DSAR intake portal, hosted, branded, and accessible
  • Auto-match requesters to internal systems via IdP + connector rosters
  • Pre-composed Article 15 / 17 / 20 outreach per vendor template
  • 30-day GDPR clock tracking with deadline alerts to legal
  • Evidence package auto-assembled at close. JSON + signed PDF
  • Vendor reply parsing, acknowledgements, follow-ups, completion logged
Talk to an engineer
scopemantle.app/dsar/DS-2026-0412
ScopeMantleDSARDS-2026-0412
Day 4 of 30

Request #DS-2026-0412 · Access

jane.doe@acme.com
Type: Article 15 (Right of access)Received: 18 Apr 2026Deadline: 18 May 2026

Vendor outreach · 23 vendors

SLSlack
Day 1 · 14:22Fulfilled
NONotion
Day 1 · 16:08Fulfilled
HUHubSpot
Day 2 · 09:41Acknowledged
MIMixpanel
Day 2 · 11:17Acknowledged
ZAZapier
Day 3 · 08:30Sent
ANAnthropic Console
Day 3 · 08:30Sent
CACalendly
Day 3 · 08:31Sent
FIFigma
QueuedPending
LOLoom
QueuedPending

Progress

Fulfilled2 / 23
Acknowledged2
Sent3
Pending16
Evidence pack auto-assembled on completion.

05 · DEPROVISIONING

Deprovisioning & Offboarding

When someone leaves, the question isn't whether IT remembered to disable their email. It's whether anyone remembered the 23 SaaS apps they touched directly via OAuth, none of which appeared in the standard offboarding checklist because nobody knew they existed. ScopeMantle closes that gap by triggering offboarding from the source of truth (your HRIS or IdP) and walking the cross-SaaS checklist automatically.

Each step in the checklist produces proof, a token revocation receipt, an ownership transfer record, a removed-from-team log line. That proof goes into an offboarding evidence bundle that satisfies SOC 2 CC6.1, ISO 27001 A.5.18, and the auditor question that always lands at the worst time: "show me the last ten offboardings."

  • Trigger from HRIS (BambooHR live, Workday on roadmap) or directly from your IdP
  • Cross-SaaS checklist auto-generated from the user's actual app footprint
  • Per-app proof-of-removal, token receipts, ownership transfer logs
  • Owner-reassignment for orphaned files, repos, calendars, and pages
  • SLA tracking from termination event to last-app-cleared timestamp
  • Evidence bundle exportable to your GRC platform (Vanta, Drata, Secureframe)
Talk to an engineer
scopemantle.app/deprov/DEPROV-2026-0078
ScopeMantleDeprovisioningDEPROV-2026-0078
triggered by HRIS

Offboard · Sarah Chen

sarah.chen@acme.com
Source: BambooHR · Last day: 22 Apr 2026Manager: Mark PatelStarted: 09:14 · 23 apps in checklist
4 / 10 appsest. complete · 09:18
OktaSuspend identity · revoke all sessions09:14:02
Google WorkspaceSuspend account · revoke OAuth tokens (47)09:14:05
SlackDeactivate · transfer DM ownership to manager09:14:11
GitHubRemove from 8 repos · revoke 3 PATs · rotate deploy keys09:14:18
NotionTransfer 142 owned pages → Mark Patelrunning…
LinearReassign 23 active issues → team triagerunning…
1PasswordRevoke vault access · trigger secret rotationqueued
ZoomReassign 4 scheduled meetings → host substitutequeued
DatadogRemove from 2 teams · revoke API keys (5)queued
AWS SSOSuspend · disable 12 role assumptionsqueued

06 · EVENTS

Normalized Event Stream

Every connector emits events. Every IdP and every SaaS app speak slightly different dialects of those events. ScopeMantle normalizes them into a single schema, actor, action, target, scopes, source, risk, so your SIEM doesn't have to. The schema is documented at /docs/event-schema, versioned, and stable across connector updates.

Delivery is your choice: webhook for low-latency, batched HTTP for systems that prefer pulls, or direct S3 sink for cold storage and your data lake. Splunk, Datadog, Elastic, and Sumo Logic have first-class destinations; everything else gets a documented JSON contract. Twelve months of retention is the default, configurable up or down per workspace.

  • Single normalized schema across Okta, Google Workspace, and (soon) Entra
  • Webhook, batched HTTP, and S3 sink delivery, pick what your stack prefers
  • Splunk, Datadog, Elastic, Sumo Logic, first-class SIEM destinations
  • Risk tagging on every event from the same engine that drives policy
  • 12-month retention by default, configurable per workspace
  • Slack and PagerDuty alerting filtered by policy tags or scope patterns
Talk to an engineer
scopemantle.app/events
ScopeMantleEvents
live12,488 / day
filter:risk:high|criticalsource:anylast 60s · 8 results
14:12:03GoogleJane Doe granted Zapier access to drive.readonly + gmail.readonlyHighevt-2486
14:08:41Googlesystem auto-revoked Replit OAuth token (policy: stale > 90d)Mediumevt-2485
14:02:17GoogleMark Patel installed Loom for Workspace · 5 scopesMediumevt-2484
13:58:22OktaAnya Reyes elevated Notion to admin.directory.user.readonlyHighevt-2483
13:51:09Googlesystem discovered new vendor: Linear · 4 usersLowevt-2482
13:47:51GoogleTom Liu removed HubSpot scope crm.objects.contacts.writeLowevt-2481
13:33:04Googlesystem Mixpanel scope expanded: + projects.writeHighevt-2480
13:21:18Oktasystem Calendly synced 912 user grants from OktaLowevt-2479

ARCHITECTURE

How ScopeMantle is built.

IDENTITY SOURCESOktaWorkforce identityGoogle WorkspaceWorkspace + OAuthMicrosoft EntraRoadmap · Q3 2026HRISBambooHR, Workday (roadmap)SCOPEMANTLE CONNECTORSConnector layerRead-only OAuthAES-GCM vaultHMAC-signed stateRate-limited pollingNORMALIZATION + LLMScopeMantle coreUnified inventoryNormalized event schemaPrivacy intelligencePolicy engineYOUR WORKFLOWSDSAR portalSIEM exportSplunk · Datadog · ElasticGRC evidenceVanta · Drata · SecureframeSlack · JiraAlerts and approvals

Read-only by default

Every connector requests the minimum scope set required to inventory and govern. We never request write scopes for read paths. Customers can revoke at the IdP at any time.

Credentials vaulted

OAuth refresh tokens are sealed with AES-GCM at rest using per-tenant keys. State is HMAC-signed end-to-end. Connector secrets never leave the encryption boundary in cleartext.

Single-tenant VPC option

Multi-tenant SaaS by default. Enterprise plans can deploy into a single-tenant VPC in AWS us-east-1, eu-west-1, or eu-central-1 with customer-managed KMS keys.

HONEST SCOPE

What ScopeMantle isn't (yet).

Confident vendors say what they don't do. Here is ours.

  • ×Not an IdP

    We integrate with yours. Bring Okta, Google Workspace, or Entra and ScopeMantle reads from it.

  • ×Not a CASB

    We don't do inline traffic inspection. We govern access grants, not packet payloads.

  • ×Not a SIEM

    We feed yours. Splunk, Datadog, Elastic, Sumo Logic, and a documented JSON schema for the rest.

  • ×Not a DLP tool

    We tell you who has access to what. We don't block payloads in transit or scan file contents.

  • ×Not a CMP

    We integrate with consent management platforms. OneTrust today, Transcend on the roadmap.

  • ×Not a consent firewall todayRoadmap · Q4 2026

    We surface and revoke. Native prevention at grant-time requires policy-engine integration with Okta and Google Workspace.

  • ×Not a corporate account-deletion service todayRoadmap · Q3 2026

    We'll auto-fire GDPR Article 17 and CCPA deletion requests to vendors on revocation.

Frequently asked

Platform — common questions

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Trusted by security and privacy teams at 50+ organizations.