-
Notifications
You must be signed in to change notification settings - Fork 2
Configuration
auth:
method: service_account # or "oauth"
credentials_file: credentials.json
credentials_dir: credentials # directory for multi-credential profiles
subject: admin@company.com # super admin email for impersonation
customer_id: auto # "auto" = discover from API, or explicit ID like "C049r06rk"
# profile: production # uncomment to use a named profile by default
profiles:
production:
credentials_file: credentials/prod-sa.json
subject: admin@company.com
staging:
credentials_file: credentials/staging-sa.json
subject: admin@staging.company.com
checks:
levels: [L1, L2] # [L1] for baseline only
sources: [CIS, OTHER, GOOGLE, CISA]
sections: all # or specific: [Gmail, "Drive and Docs"]
exclude: [] # exclude check IDs: [CIS-1.1.3, ADD-04]
exclude_sections: [] # exclude sections: ["Google Meet"]
output:
directory: ./reports
formats: [html, json, csv]
options:
cache_data: true
cache_directory: ./cache
org_units: all # or specific OUs: ["/Engineering", "/Sales"]
max_retries: 5
rate_limit_qps: 10
max_log_events: 50000 # cap on audit-log events fetched per log type
chat_inactive_days: 90 # ADD-29: Chat spaces with no activity
device_inactive_days: 90 # ADD-30/31/38: devices with no sync
user_inactive_days: 90 # ADD-42 / ADD-44: accounts with no sign-in
collect_mailbox_forwarding: false # ADD-51: opt-in, see below
mailbox_forwarding_max_users: 500
trust_rules_file: null # JSON export of Drive trust rules
external_sharing_ous: [] # OUs whose external sharing is deliberate
ai:
provider: anthropic # openai, anthropic, or bedrock
model: "" # blank = provider default
api_key: "" # prefer env vars: ANTHROPIC_API_KEY, OPENAI_API_KEY
temperature: 0.1
max_tokens: 4096
network:
proxy: null # HTTP proxy URL, e.g. http://proxy:8080
no_proxy: null # comma-separated bypass list
ca_cert: null # CA cert for proxy TLS interception
disable_ssl_verification: false # insecure, testing onlyMail forwarded to an outside address is a common persistence and exfiltration technique after an account is compromised, and it cannot be seen from tenant-level settings. collect_mailbox_forwarding: true makes the auditor read each active user's forwarding addresses and ADD-51 then fails on any address outside your verified domains.
It is off by default because of what it costs and what it touches:
- The service account impersonates every active user (domain-wide delegation, scope
gmail.settings.basic-- already in the standard scope list, so no re-authorization is needed). Only forwarding settings are read, never message content. - One Gmail API call per mailbox.
mailbox_forwarding_max_users(default 500) caps the run; when the cap is hit ADD-51 says so in its details rather than implying full coverage. - With collection off, ADD-51 reports MANUAL, not PASS.
Several checks read data that older cache files do not contain: admin roles (ADD-41, ADD-48, ADD-49), MTA-STS / TLS-RPT DNS records (ADD-50), per-user licence holders (ADD-52), Takeout policies (ADD-09) and the enterprise_service_restrictions / early_access_apps policy categories (GWS.COMMONCONTROLS.16.1 / 16.2). Re-scoring an old cache with --cached reports these as ERROR or MANUAL; run a live collection to evaluate them.
Store multiple service account keys in the credentials/ directory:
credentials/
production.json
staging.json
client-b.json
Define profiles in config.yaml, then switch between them:
gws-auditor --profile ? # list available profiles + scanned credentials
gws-auditor --profile production # use specific profile
gws-auditor --profile staging # switch tenantSet customer_id: auto (the default) and the tool resolves the real customer ID automatically using customers.get(customerKey="my_customer"). No need to look it up manually.
| Variable | Purpose |
|---|---|
ANTHROPIC_API_KEY |
Anthropic API key for AI analyst |
OPENAI_API_KEY |
OpenAI API key for AI analyst |
GWS_AI_PROVIDER |
Override AI provider |
GWS_AI_MODEL |
Override AI model |
CLI flags take precedence over config.yaml values:
gws-auditor --credentials other.json --subject other@co.com --customer-id C0xxxx