Google Workspace security monitoring for small businesses

InboxGuards checks supported Google Workspace audit records approximately every 5 minutes and turns configured account-takeover signals into plain-English alerts. Google ingestion delays and API coverage still apply.

N°001sectiongoogle workspace accounts get hijacked quietly

Section 01

Google Workspace accounts get hijacked quietly

A compromised Google Workspace account may be used for suspicious sign-ins, malicious app consent, forwarding, or impersonation. Google records some relevant activity, subject to edition, configuration, retention, and API coverage.

That's the gap InboxGuards addresses. We check available Google Workspace admin audit records approximately every 5 minutes and raise an alert when a configured account-takeover rule matches. Google ingestion delays and API coverage still apply.

N°002sectionsecurity verdicts google may expose

Section 02

Security verdicts Google may expose

Google security systems may expose hijacked-account or suspicious-sign-in verdicts in supported audit records. Availability depends on the Google Workspace edition, tenant configuration, and provider processing.

InboxGuards checks for those verdicts and turns supported results into alerts. Delivery depends on when Google records and exposes the event and when the next InboxGuards check completes.

N°003sectionwhat we watch for in your google workspace

Section 03

What we watch for in your Google Workspace

Our monitor is tuned for the specific patterns behind real-world email fraud and account takeover:

  • Suspicious sign-ins flagged by Google, or logins from unapproved countries
  • New third-party apps granted access to Gmail or Drive (OAuth grants)
  • Email forwarding or delegation set up to an external address
  • New super-admin roles or security setting changes
  • Two-step verification being disabled on any account
  • Gmail mailbox delegation changes and app passwords being created — both MFA-bypass moves
  • Daily 2-Step Verification coverage check: see exactly which users still aren't enrolled
  • Impossible travel — one account signing in from two places it couldn't travel between
  • Dormant accounts suddenly waking up, and risky changes made after hours
N°004sectiondaily dark-web check of every mailbox

Section 04

Daily dark-web check of every mailbox

Stolen passwords are how most takeovers start. Once a day InboxGuards reads the list of user email addresses from your Workspace directory (the same read-only admin.directory.user.readonly scope used for the 2-Step Verification check) and checks each one against Have I Been Pwned and LeakCheck — including LeakCheck's info-stealer malware logs, which show credentials copied off an infected device. Every email domain your users have is also swept for leaked addresses that have never signed in, such as former staff or shared mailboxes.

New findings become one alert per person, graded by what was exposed: an address alone, a password, or a fresh stealer-log capture. Leaked values themselves are never stored or shown. The Dark Web tab on your dashboard lists every address checked, when, and what was found, and has a Scan now button for an immediate recheck.

N°005sectiona google workspace visibility limit

Section 05

A Google Workspace visibility limit

The Google audit records currently used by InboxGuards do not expose user-created Gmail filter changes, such as "delete anything containing invoice." InboxGuards cannot detect those changes; evaluate other tools against their exact authorized data sources.

A filter can be one part of a larger compromise, but related activity does not always produce a record available to InboxGuards. Supported forwarding changes, OAuth grants, and sign-in records are checked when Google exposes them; the service cannot guarantee that activity surrounding a hidden filter will be visible.

N°006sectionread-only, plain-english, and priced for small business

Section 06

Read-only, plain-English, and priced for small business

InboxGuards connects with read-only access to supported Google Workspace audit records — it does not request mailbox-content access and cannot modify your account. Alerts describe available evidence in plain English and include general response guidance; your administrator or IT provider remains responsible for tenant changes.

You also get a monthly letter-grade scorecard covering your alerts, response, and 2-Step Verification coverage — an informational snapshot, not a certification. It's $4 per user per month, no minimum, with a 30-day money-back guarantee. InboxGuards supplies alerts and general response steps; your administrator or MSP remains responsible for tenant changes and incident response.

Put an alarm on my inbox

$4 per user / month · 30-day money-back guarantee