Skip to main content

Getting started

Most teams see their first discovered apps within 5–10 minutes of connecting email intelligence or SSO. A full initial sync — covering the past several months of email signals — typically completes within 30 minutes to a few hours depending on org size.The governance features (findings, OAuth grants, shadow IT) populate as soon as SSO sync completes.
No — you can start with one and add more later. But the more sources you connect, the more complete your picture:
  • Email only — app spend and renewal data, good for finance visibility
  • SSO only — app catalog, user access, OAuth grants, good for IT governance
  • Both — correlated profiles with spend + access + usage
  • + Browser extension — fills in apps that aren’t in your IdP and don’t send invoices
Start with whichever you have admin access to.
  • Google Workspace email scanning — Super Admin (to set up service account + domain-wide delegation)
  • Microsoft 365 email scanning — Global Administrator (to grant admin consent)
  • Google Workspace SSO — Super Admin
  • Microsoft Entra SSO — Global Administrator
  • Okta SSO — Super Admin (to generate an API token)
  • Browser extension — No admin required for individual users; Chrome Enterprise admin for org-wide deployment
Yes. You can connect Okta for SSO discovery and Google Workspace for email intelligence simultaneously. Porcia deduplicates apps found across both sources.

Email intelligence

No. Porcia runs targeted search queries against your org’s mailboxes looking for vendor communication patterns — invoices, renewals, signups, OAuth notifications. Emails that don’t match these patterns are never fetched or processed.Personal emails, internal company emails, and general correspondence are ignored.
No. Raw email content is processed in memory — metadata (vendor name, pricing, dates) is extracted, and the raw content is immediately discarded. Nothing from inside the email body is persisted beyond the extracted structured data.
Domain-wide access (via a service account for Google or app-only auth for Microsoft) scans all org mailboxes automatically — no per-user setup, full historical coverage, and continuous updates. It’s the recommended approach.Email forwarding is a legacy option where individual users manually forward app emails to their unique Porcia address. It only processes emails that match the forwarding rules, has no historical coverage, and requires ongoing maintenance as new apps are added. Use it only if domain-wide access isn’t available.

SSO & directory

Directory user data (name, email, department, group memberships, MFA status) is used to:
  • Show who has access to which apps
  • Calculate license utilization (access vs active usage)
  • Target pulses to the right people
  • Power offboarding playbooks
  • Attribute discovery events to specific users or teams
User-level data is only visible to workspace admins. Member-level users see aggregated data only.
No. All IdP integrations are strictly read-only. Porcia cannot add users, remove users, change app assignments, or modify any configuration in your Google Workspace, Microsoft Entra, or Okta tenant.The only write action Porcia can take (with explicit admin confirmation) is revoking OAuth grants via the IdP’s revocation API.
Porcia syncs Okta groups and group memberships fully. Full per-user directory attribute sync (department, title, manager) is partially supported and improving. If you need specific Okta directory fields, contact support.

Governance

Findings are security posture issues surfaced automatically by Porcia — for example, a high-risk OAuth grant, an employee using an app outside of SSO, a sideloaded browser extension, or a deprovisioned user who still has active app access.Each finding has a risk level, context, and guided remediation steps. You can resolve them, accept the risk (with a justification note), or assign them to a team member.
A rule evaluates an incoming event against conditions and triggers an action (notification, finding creation, assignment) automatically. It’s real-time and reactive.A playbook is a multi-step workflow run manually (or triggered by a rule) to complete a structured process — like offboarding, where you need a sequence of steps completed by different people over minutes or hours.Think of rules as automatic alerts and playbooks as checklists with accountability.
You can cancel a pulse before the deadline if no one has responded yet. Once responses come in, the pulse can’t be unsent — but you can add a follow-up note visible to all recipients.
Employees can snooze individual pulses (ask to be reminded later). Workspace-level opt-out is available for employees who want to stop receiving pulses entirely — this is tracked as a preference and respected by future pulse sends.

Browser extension

The extension detects login events — specifically: form submissions on login pages, OAuth button clicks (Sign in with Google/Microsoft), and SSO redirects. For each event it records:
  • The domain (e.g. “slack.com”)
  • The detection method (login_form, oauth_google, etc.)
  • Whether a work email was used (boolean — the address itself is never stored)
  • The timestamp
It does not track page content, page URLs beyond the domain, keystrokes, passwords, form values, or general browsing. Consumer domains (google.com, youtube.com, reddit.com, etc.) are automatically excluded.
Yes. Clicking the extension icon shows a “Pause Detection” toggle. When paused, no data is collected until the employee resumes.
No, by default. Detection in incognito/private browsing is disabled. If you need work logins in private mode to be tracked (e.g. for shared device scenarios), it can be enabled per-user in the extension settings.
Separate from tracking logins, the Porcia extension also reports all other browser extensions installed on each device — their name, version, permissions, host permissions, and how they were deployed (store, sideloaded, admin policy).This powers the Security → Browser view, where admins can see extension risk scores across the org, set allow/deny policies, and trigger managed actions (disable, uninstall) to enrolled devices.

Privacy & security

Data is stored in AWS infrastructure in the US. EU data residency is planned for Enterprise customers. Contact sales@porcia.org for details on timeline.
Porcia is built following GDPR principles — data minimization, purpose limitation, right of access, right to deletion, and data portability. Data processing agreements (DPAs) are available on request for Enterprise customers.
No. Your workspace data is never sold or shared with third parties for commercial purposes. We may use anonymized, aggregated signals to improve app intelligence — for example, app-category trends and risk-pattern detection. Your workspace’s sensitive details are never shared with other customers.
No. Porcia is focused on SaaS and Shadow AI discovery, governance, and security posture. Porcia does not contact vendors or act on your behalf in any commercial capacity.
Email Intelligence access is read-only and is only used for scanning vendor signals. Porcia does not send email from your connected mailboxes.Pulses are delivered via a separate channel — Slack, Microsoft Teams, or email sent from Porcia’s own email system (not your mailbox). Pulse delivery has nothing to do with your Email Intelligence integration. If you choose email as a Pulse delivery channel, employees receive the message from a Porcia sender address, not from your domain.
Go to Settings → Data → Export to download everything first. Then go to Settings → General → Danger Zone → Delete Workspace. All data is permanently deleted within 30 days.For an individual user’s data deletion, contact privacy@porcia.org.

Billing

Active directory users are users synced from your connected identity providers (Google Workspace, Microsoft Entra, Okta) who have an active status in that IdP. Suspended, deprovisioned, or excluded users don’t count.You can see the exact count and breakdown at Settings → Billing → Usage.
The 200/monthfloorapplies.Youwontpaylessthan200/month floor applies. You won't pay less than 200/month regardless of how few active directory users you have. This is the minimum for the Standard plan.
Yes. Cancel from Settings → Billing → Cancel Subscription. Access continues to the end of your current billing period. Data is retained for 30 days after that, then permanently deleted.

Still have questions?

Contact support

Email us at support@porcia.org — we reply within 24 hours

In-app chat

Use the chat icon in the bottom-right corner of the app

Schedule a demo

Talk through your use case with our team

Email sync issues

Detailed integration troubleshooting