Use Case

Cloud Activity Monitoring

ARIA ingests Google Workspace admin audit logs, Drive sharing events, and OAuth token lifecycle changes — detecting mass file exports, permission escalations, and token anomalies that the Admin Console surfaces but does not investigate.

Google Workspace Admin SDK Drive Activity Token Lifecycle M365 Available

Where the Signal Comes From

ARIA's cloud monitoring pipeline pulls from the Google Workspace Admin SDK — specifically the Reports API, which provides structured audit logs for Admin console actions, Drive file activity, login events, and OAuth grant changes. These are the same logs available in the Admin console's audit report views, but delivered continuously to ARIA's triage pipeline rather than requiring manual inspection.

For organizations using Microsoft 365, cloud activity monitoring is available through a separate integration. The specific event types and coverage differ from Google Workspace. If your environment is primarily M365, contact us to discuss what's supported before making assumptions about equivalent coverage.

ARIA does not inspect file content. It does not read the contents of Drive documents, email bodies, or attachments. Detection is based on the metadata that the Admin SDK makes available: who accessed what file, when, from where, and what action they took on it.

Admin Console Activity

Changes to the Google Workspace admin environment — domain settings, user provisioning, delegated admin grants, group membership changes, application access policies — are logged by the Admin SDK and ingested by ARIA continuously. Most of these events are routine; ARIA identifies the ones that are not:

Domain-Wide Delegation

Granting an OAuth client domain-wide delegation gives a service account the ability to impersonate any user in the tenant. This is a legitimate mechanism for certain integrations but represents a significant access scope change. ARIA fires immediately when domain-wide delegation is granted or modified. The investigation includes which OAuth client received delegation and what permission scopes it was given.

Bulk User Suspension or Deletion

An admin account that suspends or deletes a large number of user accounts in a short window — outside of a normal offboarding workflow — is a high-confidence indicator of either account compromise or a destructive insider action. ARIA detects the volume anomaly and investigates what account performed the actions and whether there are other anomalous indicators on that account.

App Access Policy Change

Enabling access for unchecked third-party applications across the org, or disabling existing access controls, changes the effective security posture of the Workspace environment. ARIA logs and investigates app access policy changes, particularly those that expand the set of applications that can connect to org data.

Drive Sharing and Export Activity

Google Drive activity logs record when files are shared externally, downloaded, or moved. ARIA monitors for patterns that suggest data staging or exfiltration:

  • A user account sharing a large number of Drive files to external addresses in a short time window
  • Files containing sensitive naming conventions (contracts, invoices, payroll, board, confidential) shared to personal email addresses
  • Bulk download events from a single account — large numbers of files exported in a concentrated burst
  • Sharing link changes that make previously restricted documents accessible to anyone with the link

A single external share is not an alert. The same user sharing fifty files externally in an hour, following a suspicious sign-in earlier in the day, is. ARIA correlates Drive activity with the identity events it already monitors — the combination of signals matters as much as the individual event.

ARIA surfaces these findings to a security engineer. Revoking file access or suspending the account is an action the engineer approves and ARIA executes through a separate, scoped API call. No containment runs automatically.

OAuth Token Lifecycle

The Admin SDK provides visibility into OAuth token events: when applications receive tokens, when tokens are revoked, and when applications request tokens with expanded scopes. ARIA monitors this feed for:

  • Tokens issued to applications not previously seen in the tenant — particularly those with broad scope (mail read/write, drive access)
  • Token scope expansions — an existing application requesting access to data categories it did not previously have access to
  • Tokens issued to applications that subsequently appear on threat intelligence feeds that ARIA monitors
  • Unusual token issuance patterns — high volumes of token requests from a single application in a short window, which may indicate an application behaving unexpectedly or a compromised integration

What Cloud Monitoring Does Not Cover

ARIA's cloud monitoring covers the audit log events the Google Workspace Admin SDK makes available. It does not cover cloud infrastructure — virtual machines, containers, storage buckets, databases — deployed under a separate GCP project that is not connected to the Workspace Admin SDK. Cloud infrastructure monitoring (GCP, AWS, Azure) is a distinct integration not included in the base service.

ARIA does not inspect file content. It cannot identify whether a specific Drive document contains personally identifiable information or regulated data. Detection is based on behavioral signals — who accessed what, when, and in what pattern — not on content scanning.

Common Questions
What permissions does ARIA need to monitor Workspace?
ARIA uses a service account with the following read-only Admin SDK scopes: admin.reports.audit.readonly (for admin console, Drive, login, and OAuth audit logs), admin.directory.user.readonly (for user and group data including MFA status), and Alert Center viewer. The service account does not have admin console access, cannot change settings, and has no write permissions to any Workspace resource. All containment actions that involve modifying the Workspace environment go through a separate, scoped API credential that requires explicit security engineer approval before use.
Does this work with Microsoft 365?
Microsoft 365 monitoring is available, but the integration is distinct from the Google Workspace path and the event types and coverage differ. If your environment is primarily M365, the right approach is a scoping conversation before onboarding to confirm what is and is not supported for your specific M365 configuration. Google Workspace is the primary supported platform for cloud activity monitoring and has the most complete coverage.
Can ARIA tell me if a file containing sensitive data was shared externally?
ARIA can tell you that a file was shared externally — who shared it, to which addresses, at what time, and whether the sharing event is anomalous in context. It cannot tell you whether the file contains specific types of data. Content inspection is not part of ARIA's pipeline. If a file's name or location suggests it may contain sensitive data (documents in a folder labelled "contracts," for example), ARIA will note that in the investigation context, but this is pattern matching on metadata, not reading the document. Data loss prevention based on content scanning is outside ARIA's scope.
How quickly does ARIA detect a suspicious Drive event?
The Admin SDK Reports API delivers audit log events with a delay that varies by event type — typically between a few minutes and a few hours for Drive activity, and closer to real-time for Admin console actions and Alert Center events. ARIA polls the API continuously and processes events as they arrive. For high-severity Admin console events (super admin grants, domain-wide delegation changes), Alert Center delivers near-real-time notifications that ARIA receives and processes ahead of the Reports API batch.

See Your Cloud Exposure

A read-only ARIA connection to your Workspace Admin SDK surfaces admin anomalies, Drive sharing patterns, and OAuth grant records within 48 hours — at no cost.

Book Free Assessment
No contract. No setup fee. Cancel anytime.

More Use Cases

Cloud activity is one signal in a pipeline that also covers email, identity, and endpoints.

View All Use Cases