The practice of reviewing, restricting, and monitoring third-party applications that request access through OAuth. In Google Workspace, this matters because broad scopes can expose Gmail or Drive data without direct platform visibility. Effective governance includes inventory, approval workflows, scope restriction, default blocking, and periodic recertification.
Expanded Definition
OAuth App Governance is the operational discipline of controlling which third-party applications can request OAuth consent, what scopes they receive, and how their access is reviewed over time. In NHI security, the focus is not only on the app itself but on the delegated trust it creates across Gmail, Drive, and other SaaS data stores.
Definitions vary across vendors, but the practical boundary is consistent: governance begins before consent is granted and continues through approval, monitoring, and removal. That makes it different from generic app inventory or conventional access review, because OAuth scopes can authorize broad data access without a direct platform login. The same principle aligns with the least-privilege intent in the NIST Cybersecurity Framework 2.0 and with control families in NIST SP 800-53 Rev 5 Security and Privacy Controls.
The most common misapplication is treating OAuth app approval as a one-time admin task, which occurs when organisations allow blanket consent without recurring scope validation or ownership review.
Examples and Use Cases
Implementing OAuth App Governance rigorously often introduces friction for end users and help desks, requiring organisations to weigh fast self-service access against the cost of review, blocking, and recertification.
- Blocking unapproved third-party apps by default, then allowing only explicitly reviewed apps with documented business owners and minimal scopes.
- Recertifying high-risk OAuth grants quarterly so dormant or over-broad access is removed before it becomes a hidden pathway into mail or file data.
- Tracking connected applications that have access to a tenant and comparing them to user demand, a gap highlighted in the The 2024 ESG Report: Managing Non-Human Identities.
- Investigating phishing-led consent abuse after incidents such as the Salesloft OAuth token breach, where delegated access can outlive the initial compromise.
- Using enterprise app registries and conditional approval workflows to separate sanctioned integrations from shadow AI or shadow IT tools, as illustrated by the Klue OAuth Supply Chain Breach.
Teams often pair this with identity lifecycle controls described in the Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs, especially when app access is tied to service workflows.
Why It Matters in NHI Security
OAuth apps are a high-value NHI control point because they can bypass direct password theft and still expose sensitive data through delegated authorization. NHIMG research shows that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, with 38% reporting no or low visibility and 47% only partial visibility. That blind spot makes approval sprawl, stale grants, and over-scoped access a persistent governance problem.
This matters because OAuth access often persists after the original user, project, or vendor relationship has changed. When scopes are too broad, a compromised app can become an unintended data extractor even if the human account is protected. The issue also maps cleanly to audit and resilience concerns in the Ultimate Guide to NHIs — Regulatory and Audit Perspectives.
Organisations typically encounter the real cost only after a consent phishing event or vendor compromise exposes mailbox or document data, at which point OAuth App Governance becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 | OAuth app approvals and scope sprawl are core NHI secret and access governance concerns. |
| NIST CSF 2.0 | PR.AC | OAuth governance implements least-privilege access management and continuous access oversight. |
| NIST SP 800-63 | OAuth consent depends on identity assurance and trustworthy authorization decisions, though not a direct profile control. | |
| NIST Zero Trust (SP 800-207) | Zero Trust requires explicit verification of delegated access and continuous evaluation of trust. | |
| OWASP Agentic AI Top 10 | Agentic and third-party tools can request OAuth scopes that expand tool access and data exposure. |
Inventory, approve, and recertify OAuth grants so third-party apps only retain minimum required access.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org