Features
Everything Overdrive watches — in one read-only connection.
One administrator connects in two minutes. From there, Overdrive monitors your Google Workspace™ for exposure and turns it into a short list you can clear. Here's what it does.
Connect & monitor
No agents, no per-user rollout — one read-only authorization covers the whole workspace.
Two-minute admin connect
One administrator authorizes Overdrive over Google's OAuth — read-only. No agents, no per-user setup.
Continuous monitoring
From the day you connect, Overdrive watches Google Drive™ sharing, app grants, and account posture. Nothing to schedule or remember.
Your whole team, one workspace
Invite other admins by email and share the same view, with roles for who can do what.
Read-only by design
The audit never requests write access and never reads file contents — sharing metadata only.
What it finds
The exposure that tends to go quiet: shared once, then forgotten.
Public links & web-indexed files
Anyone-with-the-link files, and the ones open enough to be found on the web.
Shared outside your org
Specific outside-company people with access — including shares everyone forgot about.
Reachable from personal accounts
Files a consumer account — Gmail™, Yahoo, and the like — can open.
Departed & suspended users
Accounts that are gone but whose shares are still live.
Risky third-party apps
OAuth apps with Drive or Gmail access, ranked by how much they can actually reach.
Admins without 2-step verification
Privileged accounts missing a second factor — a quiet way in.
Settings & posture drift
Org-level sharing settings that widen your exposure, surfaced before they become a habit.
Prioritize & clear
Exposure becomes an inbox — ranked, time-anchored, and built to be worked down.
Ranked by what matters today
Every exposure gets a severity, sharpened by signals like sensitive filenames, write access, suspended owners, and spread across many domains.
Exposure age, anchored
See how long something's been open — the shared-once-and-forgotten files surface, not just the newest ones.
A spotlight on what to do first
The single highest-priority finding, with its recommended next step, front and center.
Momentum
What you cleared and what's new in the last seven days, at a glance.
Statuses that respect your judgment
Snooze it, or mark it Expected when it's intentional — it only comes back if the exposure materially worsens.
New-this-scan view
Filter straight to what just appeared, so nothing new slips by.
Explore your exposure
Pivot the same findings by file, by outsider, by internal user, or by app.
Files
Every file with external or public exposure — owner, visibility, severity, and the signals behind it.
Outsiders
Everyone outside your org with access: their domain, what they can reach, their highest role, and a one-click way to trust a domain.
Internal people
Your users ranked by risk — department, role, 2-step status, account state, and their exposure counts.
Apps
Third-party OAuth apps authorized across the workspace, by user count, scopes, and severity.
Decide what's expected
Not every external share is a problem. Tell Overdrive what's intentional and keep the list honest.
Trusted domains
Mark partner and vendor domains as trusted so they stop generating high-severity noise. Common ones auto-trust on their own.
Accepted-risk register
Mark a finding Expected with a reason — tracked with who accepted it and when, and re-opened only if it materially worsens.
Transparent app suppression
Well-known apps that Overdrive auto-trusts stay visible, so nothing is hidden from you.
Act in Google's own tools
Overdrive is read-only, so every fix happens in Google — Overdrive just makes the right next step one click away.
Nudge the owner
A one-click, pre-composed Gmail™ draft asking the file's owner to restrict sharing.
Jump to the right place
Deep links straight to the relevant resource in the Google Admin Console™ — no hunting.
Resolve, snooze, or accept
Close the loop from the list, and let the next scan confirm the exposure is actually gone.
Report & export
Take the picture to your team, your leadership, or your spreadsheet.
Printable exposure summary
Severity counts, the top riskiest files, the top risky apps, and an honest note on coverage — ready to share or print.
CSV export
File-level findings as a spreadsheet-safe CSV, encoded to avoid formula-injection surprises.
What Overdrive doesn't do
We're a focused exposure lens, not a second admin console — and we're upfront about where the line is.
- Change, move, or delete files — it has no write access.
- Manage your users, passwords, or org units.
- Read the contents of your files — sharing metadata only.
- Replace the Admin Console — it's a focused lens, not a second console.
On the roadmap
One-click remediation
Removing a public link or an external grant — with a dry-run preview and an action log — straight from Overdrive. It's planned, opt-in, and clearly separated: the audit stays read-only until you choose to enable remediation.
See what's exposed — in two minutes.
Read-only access · never reads your file contents · free to start