Features

Everything Overdrive watches — in one read-only connection.

One administrator connects in two minutes. From there, Overdrive monitors your Google Workspace™ for exposure and turns it into a short list you can clear. Here's what it does.

Connect & monitor

No agents, no per-user rollout — one read-only authorization covers the whole workspace.

Two-minute admin connect

One administrator authorizes Overdrive over Google's OAuth — read-only. No agents, no per-user setup.

Continuous monitoring

From the day you connect, Overdrive watches Google Drive™ sharing, app grants, and account posture. Nothing to schedule or remember.

Your whole team, one workspace

Invite other admins by email and share the same view, with roles for who can do what.

Read-only by design

The audit never requests write access and never reads file contents — sharing metadata only.

What it finds

The exposure that tends to go quiet: shared once, then forgotten.

Public links & web-indexed files

Anyone-with-the-link files, and the ones open enough to be found on the web.

Shared outside your org

Specific outside-company people with access — including shares everyone forgot about.

Reachable from personal accounts

Files a consumer account — Gmail™, Yahoo, and the like — can open.

Departed & suspended users

Accounts that are gone but whose shares are still live.

Risky third-party apps

OAuth apps with Drive or Gmail access, ranked by how much they can actually reach.

Admins without 2-step verification

Privileged accounts missing a second factor — a quiet way in.

Settings & posture drift

Org-level sharing settings that widen your exposure, surfaced before they become a habit.

Prioritize & clear

Exposure becomes an inbox — ranked, time-anchored, and built to be worked down.

Ranked by what matters today

Every exposure gets a severity, sharpened by signals like sensitive filenames, write access, suspended owners, and spread across many domains.

Exposure age, anchored

See how long something's been open — the shared-once-and-forgotten files surface, not just the newest ones.

A spotlight on what to do first

The single highest-priority finding, with its recommended next step, front and center.

Momentum

What you cleared and what's new in the last seven days, at a glance.

Statuses that respect your judgment

Snooze it, or mark it Expected when it's intentional — it only comes back if the exposure materially worsens.

New-this-scan view

Filter straight to what just appeared, so nothing new slips by.

Explore your exposure

Pivot the same findings by file, by outsider, by internal user, or by app.

Files

Every file with external or public exposure — owner, visibility, severity, and the signals behind it.

Outsiders

Everyone outside your org with access: their domain, what they can reach, their highest role, and a one-click way to trust a domain.

Internal people

Your users ranked by risk — department, role, 2-step status, account state, and their exposure counts.

Apps

Third-party OAuth apps authorized across the workspace, by user count, scopes, and severity.

Decide what's expected

Not every external share is a problem. Tell Overdrive what's intentional and keep the list honest.

Trusted domains

Mark partner and vendor domains as trusted so they stop generating high-severity noise. Common ones auto-trust on their own.

Accepted-risk register

Mark a finding Expected with a reason — tracked with who accepted it and when, and re-opened only if it materially worsens.

Transparent app suppression

Well-known apps that Overdrive auto-trusts stay visible, so nothing is hidden from you.

Act in Google's own tools

Overdrive is read-only, so every fix happens in Google — Overdrive just makes the right next step one click away.

Nudge the owner

A one-click, pre-composed Gmail™ draft asking the file's owner to restrict sharing.

Jump to the right place

Deep links straight to the relevant resource in the Google Admin Console™ — no hunting.

Resolve, snooze, or accept

Close the loop from the list, and let the next scan confirm the exposure is actually gone.

Report & export

Take the picture to your team, your leadership, or your spreadsheet.

Printable exposure summary

Severity counts, the top riskiest files, the top risky apps, and an honest note on coverage — ready to share or print.

CSV export

File-level findings as a spreadsheet-safe CSV, encoded to avoid formula-injection surprises.

What Overdrive doesn't do

We're a focused exposure lens, not a second admin console — and we're upfront about where the line is.

  • Change, move, or delete files — it has no write access.
  • Manage your users, passwords, or org units.
  • Read the contents of your files — sharing metadata only.
  • Replace the Admin Console — it's a focused lens, not a second console.

On the roadmap

One-click remediation

Removing a public link or an external grant — with a dry-run preview and an action log — straight from Overdrive. It's planned, opt-in, and clearly separated: the audit stays read-only until you choose to enable remediation.

See what's exposed — in two minutes.

Read-only access · never reads your file contents · free to start