â–¶ Watch (4:00)

Ayman Elsawah pointed to the “anyone with the link” icon as the bane of his existence. Google and Slack conveniently add this by default when sharing files in messages. He listed invoices, contracts, board meeting minutes, bank account numbers, and passports as examples he has seen shared publicly. Many users do not realize a file is shared until it is too late. A sane approach involves restricting sharing by OU or security group, but many orgs avoid it for fear of breaking workflows.

â–¶ Watch (7:55)

Elsawah described Google Admin as “ugly” and unfriendly. Searching for shared files returns only a resource ID with no clickable link to review the file. Exporting to Sheets still forces you to manually copy document IDs. The real power lives behind the Google Workspace API, used by tools like GAM or the newer CLI. Sleuthther was built to close this gap and provide a simple command line tool that works at scale.

Vibe Coding a Workspace Audit Tool

â–¶ Watch (9:21)

Last summer Elsawah caught the vibe coding bug and built Sleuthther. The requirements: simple, powerful like GAM, visibility into file types, and easy automation. The biggest hurdle was OAuth scopes – Claude wanted full Drive access. Elsawah insisted on least privilege, requiring directory read, drive metadata, and drive (for permission removal) as a necessary evil. He added error handling to guide users through enabling the three required APIs, avoiding the RTFM approach.

A Real Exposure Found – and Future Plans

â–¶ Watch (16:02)

While testing Sleuthther, Elsawah found a file he did not own: a letter of recommendation written by his former executive coach. The coach had reused an old onboarding document without deleting its content. He responsibly disclosed, and she removed access. Future updates include AI classification so security analysts do not need to view sensitive files, emailing users to self-remediate, scanning for dangerous OAuth tokens, and checking for public calendars and email forwarding.

Q&A

How does Gemini’s integration with Drive influence security controls for domainwide sharing? Elsawah noted Gemini is not available in all Workspace accounts and is unsure if it can scan at the super admin level; he suggested discussing offline. ▶ 21:02

Can we scope permissions better for a readonly report while testing Sleuthther? Yes, the default behavior is read-only; lockdown and revoke permissions are not enabled unless specifically invoked. â–¶ 21:54

Would you encourage others to write their own tool if Google offered similar functionality? Elsawah encouraged writing your own to learn; the big hero of the talk was Cloud Code and vibe coding. â–¶ 22:30

Notable Quotes

This little icon right here is the bane of my existence and it’s probably yours as well. Ayman Elsawah · ▶ 4:12

Oh, would you like to share this with the world? You know, it’s like, okay, no, please don’t. Ayman Elsawah · ▶ 4:55

We want something that’s simple. We want something that’s powerful, something like GAM, um, but gives me visibility into types of files, easy to run. Ayman Elsawah · ▶ 9:36

Oh my god, are you serious? Ayman Elsawah · ▶ 17:33

The big hero of this talk was was Cloud Code uh really and just Vive coding in general. Ayman Elsawah · ▶ 22:52

Key Takeaways

  • Sleuthther scans all Google Workspace users for publicly shared files and outputs a per-user Sheet with direct links.
  • The tool was built over a summer using vibe coding and least-privilege OAuth scopes.
  • Future releases will add AI classification, email notifications, OAuth token scans, and calendar audits.

About the Speaker(s)

Security leader passionate about empowering others. Also a coffee nerd, talk single origin to me!