How I investigated an OAuth token approved by mistake in a sales account
It happened to me during a normal shift, working in operational security at a small company with Google Workspace and several SaaS apps: a salesperson approved an unknown OAuth app because it looked like a calendar extension. The symptom that made me investigate it seriously was that there was no weird login, but the scope requested permission to read email and send messages. I preferred not to…