Skip to main content

Identity and administrator activity

Google Workspace audit log monitoring for unusual activity

Run an on-demand review of unusual Google Workspace login, administrator, and OAuth activity with ranked findings and selected audit-log evidence.

Early access. Check availability for your account in Connectors. Manual analysis only.

How it works

Turn Google Workspace audit activity into an investigation queue

Reads login, admin and token Reports API activities for one verified Workspace customer. Does not read Gmail or Drive content, other Reports applications or a full directory. Available history and reporting delays depend on Google.

01

Connect read-only

Connect a Workspace administrator with audit-report and customer-profile access. Flare verifies the customer ID you enter and requests only read-only report and customer scopes.

02

Review ranked findings

Flare assesses current-window evidence with available historical context, then ranks noteworthy activity by severity and explains why it matters.

03

Investigate the evidence

See which streams were fetched, any truncation and selected event excerpts. Ask follow-up questions against the retained result. Findings are investigative leads, not proof that all activity is safe.

Built for small teams

Useful audit-log answers without a SIEM project

Start with real evidence

See what changed in Google Workspace.

Connect your verified account, choose a time window and run an analysis. Scheduled runs, deploy webhooks and file uploads under this source are not supported.

Start free