Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

Tool

Board report template: Third-party OAuth exposure in one slide

The single slide CISOs use to put a defensible figure in front of the board, with a quarter-over-quarter trend.

Directors will not read your vendor PDF

Boards ask a simple question: are we more exposed to third-party access this quarter than last? They do not want forty pages of SIG questionnaires. They want one defensible figure, a trend, and evidence you did something. CISOs who show raw app counts get a polite nod and a follow-up that never lands. CISOs who show grant count vs MFA adoption, plus a revoke tally, get a decision.

This template is a single-slide narrative. The numbers are examples so you can see the shape. They are not ScopeMantle customer metrics. We do not publish fabricated counts. You will replace every figure with your export.

If you run ScopeMantle, the dashboard export is the source. If you do not, you can still build the slide from Google Admin and Okta. It will take longer and it will be stale by week six.

The slide (copy, then replace the numbers)

Third-party OAuth exposure | Q2 2026 (example figures)

Live OAuth grants (Okta + Google Workspace): 847
Grants with Scope Sanity below 40: 62 (up 11 QoQ)
Grants with no owner attestation older than 90 days: 118
Critical findings open: 4 (2 past SLA)

Actions this quarter
- Revoked 23 stale AI-tool grants
- Blocked admin.directory scopes without approval
- DSAR median close time: 18 days (target 30)

Footnotes
- Microsoft Entra inventory is Beta / partial
- Source: dated IdP export or ScopeMantle dashboard, hashed in GRC
- Standard list price reference: $5/employee/mo annual, 30-day trial

Full board gets this slide only. Audit committee can have a technical appendix: top twenty client IDs, scope strings, owners. Do not dump the appendix on the full board and call it transparency. They will remember the wrong number.

Metric definitions you can defend

MetricDefinitionCommon lie to avoid
Live grantsUnique client IDs with at least one active user authorizationCounting display names, so acquisitions double-count
Below fortyScope Sanity under the default threshold (or your documented custom bar)Changing the threshold the night before the meeting
Unattested 90 daysNo owner sign-off inside the SLACounting a Slack emoji as attestation
Critical findingsBreach-feed match, admin.directory on an unknown vendor, or terminated user with live grantsMixing these with CVE counts from a scanner
DSAR medianCalendar days from valid request to subject letterStarting the clock at "when we felt ready"

Grant growth faster than headcount is the sprawl sentence. Pair it with MFA adoption if directors already love that chart. High MFA plus rising grants is the gap: you locked the front door and left vendor tokens in the mail slot. That is the why-now point without a TED-talk paragraph.

Quarter-over-quarter narrative

Explain the uptick. "AI tool sprawl" is fine if the export shows new AI-category client IDs. "We finally inventoried Okta" is also fine, and more honest. Do not blame Drift or Context.ai unless those client IDs appear in your tenant. Fearmongering with other companies' incidents wears out in one meeting.

The actions section is the slide. Counts without revokes look like surveillance. Revokes without a policy look like panic. Show both. If you blocked admin.directory.* without approval, say so. If DSAR median is 18 days against a 30-day target, say so. If you missed, say that too. Boards smell a perfect quarter.

Export procedure

  1. First business day after quarter close, export the dashboard PDF (or rebuild the four metrics from IdP CSVs).
  2. Hash the source file. Store it in the GRC folder next to last quarter. This is management-review evidence for SOC 2 CC9.2.
  3. Paste numbers into the slide. Legal reviews if exposure ties to active litigation or a disclosure threshold your counsel already defined. That is a counsel gate, not a CISO solo call.
  4. Record the slide in management-review minutes with one sentence on OAuth, not a buried appendix.
  5. Keep the weekly operational digest out of the board pack. Directors do not need Monday's new-install list.

If you attach evidence to Vanta or another GRC tool, use a boring filename: oauth-CC9.2-YYYY-QX.csv. Predictable names survive staff turnover. See Vanta vs ScopeMantle.

What to tell the audit committee

OAuth grants are CC9.2 vendor relationships, not CC6.7 user access. You will still run user-access reviews. Do not let the auditor treat them as substitutes. Offer this slide plus the hashed export. Walk one revoke case (termination cascade or breach-feed match). Walk one exception that expired and was renewed with a sponsor signature.

If Entra is in scope, footnote Beta. Partial inventory presented as complete is worse than a labelled gap. Same rule for HIPAA: we are not attested, no BAA, do not imply otherwise in a minutes file.

Failure modes

  • Forty pages of vendor PDFs instead of one slide.
  • Metrics that cannot be reproduced from a file in GRC.
  • A trend that resets every quarter because someone changed the join key from client ID to display name.
  • Actions that are actually hopes ("we will look at AI tools").
  • Inflating ScopeMantle as if it were a certification. It is an inventory and workflow product. Price is public. Customer count is not a vanity metric we invent.

How ScopeMantle fits

Daily sync from Google Workspace and Okta. Scores from the scoring framework. Attestation expiry at ninety days. Board export on demand. DSAR median from the same tenant if privacy uses the DSAR module. $5 annual / $6 monthly, no seat min, custom 500+, 30-day trial.

Building the slide from Admin consoles only

If you are not on ScopeMantle yet, you can still ship Q1. Export Google third-party app access to CSV. Export Okta OAuth clients. Concatenate, dedupe on client ID, count rows. That is live grants. For below-forty, apply a crude rule: unknown publisher plus mail or Drive scope counts as below forty. It is not the product rubric, and you should label it "manual proxy for Scope Sanity" on the slide. For unattested 90 days, use created date older than 90 days with no ticket in Jira (GA) tagged oauth-attest. Crude, reproducible, better than a vibe.

Critical findings: terminated users with grants, plus any client ID that appeared in a public disclosure this quarter. You can maintain that watch list in a spreadsheet if you must. The failure is not the spreadsheet. The failure is not dating the file.

Spend one hour with the CFO staffer who builds the board pack. Agree the slide title will not change quarter to quarter. Changing titles is how trends die. Agree the footnote house style (source, date, Entra Beta if needed). Then you stop negotiating fonts every March.

Individual contributors sometimes want a personal-productivity OAuth story on this slide. Leave it off. Personal Gmail grants on a BYOD profile are an ops topic. Directors are here for corporate identity blast radius. Point curious readers at the shadow OAuth guide in the appendix, not on slide one.

If a director asks for "industry benchmark," you do not have one from us. We will not invent a grants-per-employee average across unnamed customers. Compare yourself to last quarter. That is the only honest benchmark in a design-partner phase. If they want a peer anecdote, use public incidents (Drift, Context.ai) as mechanics, not as a claim that you were or were not a victim.

Worked walkthrough: turning an ugly export into a slide

Take a 600-person company on Google Workspace plus Okta. The raw Admin list shows 210 "apps." After you collapse by client ID you have 164 live grants. Forty-one have mail or Drive scopes. Nineteen have no owner you can map to an active HRIS row. Eleven score below forty if you apply the Scope Sanity rubric by hand. Those four numbers are the slide. Do not show 210. Directors will remember 210 and ask why IT is asleep.

Write three sentences under Actions. Example: "Revoked 9 unattested AI extensions. Closed 6 leftover grants on terminated users. Opened tickets for 11 below-forty rows with 30-day owners." If you cannot name owners, the action is "named marketing and engineering attestation DRIs," not "we will look at AI."

Footnote Entra if you have Microsoft users whose grants you cannot see yet. A labelled gap is a control narrative. A silent gap is a finding later.

Sample Q&A you will actually get

"Is this like a CVE count?" No. CVEs are vendor software bugs. This is standing permission we handed out. Different budget line, different owner.

"Why did grants go up if we hired slowly?" Because OAuth is not licensed seats. One new campaign tool times 40 AEs is 40 grants. Headcount is the wrong denominator unless you also show grants per employee.

"Can we just ban OAuth?" You can block third-party app access and watch people use personal Gmail. Then you have no inventory and the same data leaving. Offer sanctioned tools and a 48-hour review SLA instead.

"Are we in the Drift / Context.ai victim set?" Answer from your client-ID list, not from the news. If those IDs never appeared, say so. If they did and you revoked, show the timestamp. Do not speculate about unnamed customers of ScopeMantle. We do not publish that list.

Committee pack vs leak risk

The appendix can include client IDs. The board PDF that sits in a director's email should not include scope strings that amount to a targeting guide. Redact owner emails if the pack is widely forwarded. Keep the hashed full export in GRC, not in the slide footer.

If grant exposure ties to active litigation, counsel gates the slide. That is not theater. Minutes are discoverable. Use the example numbers on this page until your export exists. Never paste another company's hypothetical 847 as if it were yours.

KPI hygiene for the year

  • Q1: establish baseline and definitions. Expect the number to jump when you add Okta or clean duplicates. Label the methodology change on the slide.
  • Q2: show first revoke tally. If the below-forty count did not move, the program is a dashboard, not a control.
  • Q3: add DSAR median if privacy is on the same inventory. Split the slide if the committee wants privacy separate.
  • Q4: tabletop result (hours to revoke a fictional client ID) as a resilience metric next to the counts.

Jira is GA for ticketing if you want each below-forty row to become a ticket. ServiceNow is Beta. Slack notifications are Beta. Do not promise ServiceNow workflows in the minutes if you are still on the Beta label.

What to do this week

  1. Pick last quarter's end date. Rebuild the four metrics from a current export so you know the gap.
  2. Write metric definitions in the wiki using the table above. Lock the client-ID rule.
  3. Decide committee vs full board. One slide vs appendix.
  4. Schedule the first-business-day export as a recurring ticket, not a calendar hope.
  5. Read compliance mapping so the minutes sentence maps to a clause.

Keep a one-line glossary on the appendix: live grant, below forty, unattested, critical finding. Directors will ask what the words mean once. After that they track the trend. If you change a definition mid-year, label the break on the slide the way finance labels an accounting-policy change. We will not invent a peer benchmark to fill the silence.

Field guide: first slide with ugly numbers

Ship it. Label methodology. Do not sand the below-forty count down by changing the threshold the night before. Directors can smell a perfect quarter. Actions section must name revokes and owners, not hopes. Hash in GRC. Entra footnote if needed. No peer benchmark from us. $5 / $6, no seat min. Trial.

FAQ

Common questions

About ScopeMantle

ScopeMantle is an OAuth-grant audit and DSAR-automation platform for mid-market SaaS companies, sold primarily through an open MSSP partner program (70/30 wholesale split, deal registration, no direct-sale conflict in partner territories) and secondarily direct. Built in 2026.

Explore the partner program →

70 / 30 wholesale · deal registration honoured · no direct-sale conflict

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.