Connected apps and third-party grants
Review observed application grants, scopes, activity, vendor registration, and privacy relevance.
Connected apps
The report at /privacy/grants shows third-party application grants observed by connected identity or
platform sources. It helps answer which applications have access, which scopes they hold, whether access is
active or dormant, whether personal data may be reached, and whether the application exists in the vendor
register.
What the report shows
- application/display name, provider, client ID, and scopes
- severity derived from the observed access signal
- in-use or dormant activity
- whether a vendor record is linked
- data-category or personal-data reach signals where available
- first/last observation and authentication context where supplied by the connector
Filter dimensions are combined across severity, vendor registration, activity, and personal-data reach; multiple choices inside one dimension are alternatives. Use search for application names, client IDs, scopes, or category terms.
Recommended workflow
- Investigate high/critical, unregistered, and dormant grants first.
- Confirm the grant owner, business purpose, publisher, consent path, scopes, and last use in the source system.
- Revoke unnecessary access at the authoritative provider; Noru reports the observation but is not the access-control plane.
- Add legitimate third parties to the vendor register and complete risk/privacy review.
- Link appropriate vendors/recipients to RoPA activities through the Review queue.
- Record exceptions and verify revocation or changed scopes on a later sync.
Observed access is not the same as approved use, and “dormant” is not proof that a credential cannot be used. Conversely, an unregistered application can be internal or first-party; verify ownership before classifying it as a vendor.
Compliance relevance
This report supports access review, shadow-IT discovery, vendor inventory completeness, processor/recipient mapping, least privilege, and offboarding. It is evidence about connected sources only; unconnected identity providers, personal accounts, browser extensions, and direct API keys can remain outside coverage.