Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

← Platform overview

Platform capability

Access & Scope Governance

Declarative policy engine for OAuth grants — live match preview, one-click revoke, approval workflows, and SOAR-ready API.

Start a 30-day trial

03 · GOVERNANCE

Access & Scope Governance

An inventory is the prerequisite. Governance is the work. ScopeMantle ships a policy engine that turns the rules you'd otherwise enforce by Slack reminder into rules the platform enforces continuously. Every policy is a small, declarative statement — "if scope includes admin.directory and users > 25, require review" — that runs against the live inventory and against every new install the moment it appears.

Policies aren't a black box. The rule builder shows a live preview of which apps would match before you enable a rule, so you can ship governance without surprising 800 employees. When a rule fires, the action is yours: notify a channel, open a Jira ticket, require a one-click approval, or revoke the OAuth token outright. We expose the same primitives via a documented API so your SOAR playbooks can react too.

  • One-click and bulk-revoke OAuth tokens by policy or by query
  • Bulk-revoke by Vendor Risk Score (e.g., all vendors with Score < 40)
  • Auto-tag risky scopes (send_mail, modify_drive, admin.directory.*)
  • Approval workflows for new app installs via Slack, email, or Jira
  • Alerts on scope escalation, admin grants, and apps unused for >90 days
  • Rule builder with live match preview before enable
  • Programmatic API for SOAR integration — every action is callable
Talk to an engineer
scopemantle.app/governance/rules/new
ScopeMantleGovernanceRule builder

Conditions

WHENSourceisGoogle Workspace
ANDScopeincludesmail.modify
ANDUsers>25

Action

THEN Require review · notify #sec-governance

Preview · matches in current inventory

3 / 847
ZAZapier67 users
High
MIMixpanel86 users
High
REReplit12 users
Critical

+ 0 historical violations · Rule will not retroactively block.

Frequently asked

Platform — common questions

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.