Where to find it
Assets → Integrations → OAuth Grants (/assets/integrations/grants)
This section also contains two related pages:
- Risk Score (
/assets/integrations/risk-score) — workspace-level overview of grant risk distribution across your org - MCP Connections (
/assets/integrations/mcp-connections) — AI agent connections using the Model Context Protocol, discovered by the browser extension and desktop agent
How grants are discovered
OAuth grants are discovered through SSO sync:- Google Workspace — Admin SDK surfaces all third-party apps with OAuth access to your Google accounts
- Microsoft Entra — Microsoft Graph reports all enterprise app registrations and delegated permissions
- Okta — System logs and app catalog surface apps with OAuth-based access
Risk scoring
Each grant is scored based on a combination of factors:
Risk levels: Critical, High, Medium, Low
The Risk Score sub-page shows a distribution chart of grants by risk level so you can see your overall posture at a glance.
The grants view
The OAuth Grants page shows the full inventory with:- App name and icon
- Authorized users (count of employees who granted access)
- Permission scopes with human-readable descriptions
- Risk score and level
- Last activity date
- Grant age
Filtering
Filter by risk level, app, user, or grant status. Sort by risk level, user count, or grant age.Revoking a grant
1
Open the grant
Click any grant in the list to open its detail view — full scopes, authorized users, and risk explanation.
2
Review the impact
See which employees have this grant and what scopes will be revoked. Check whether any active workflows depend on this connection.
3
Revoke
Click Revoke Access. Porcia revokes via the IdP API immediately and logs the action in the audit trail.
MCP Connections
The Assets → Integrations → MCP Connections sub-page inventories AI agent connections discovered by the Porcia desktop agent and browser extension. This covers MCP servers, agent skills, and agent harnesses running on employee machines — giving you visibility into your AI supply chain.Grant findings
High-risk and stale grants automatically surface as Findings. This means they appear in the Findings page with severity, context, and remediation steps — the same workflow as other security issues.Connecting your IdP to populate grants
Grants are only discoverable if you’ve connected an identity provider. The more IdPs connected, the more complete your grant inventory. → Connect Google Workspace · Connect Microsoft Entra · Connect OktaNext steps
Findings
Review security issues including high-risk grants
Rules
Auto-alert on new risky grants
Playbooks
Include grant revocation in offboarding workflows
SSO setup
Connect your IdP to populate the grant inventory