Who can use this feature
Supported on Foundation, Growth, and Scale plans
Managing third-party vendors starts with knowing what's already in your environment. By integrating with your organization's SSO provider — Google Workspace or Azure AD — Scrut automatically fetches all the apps in use across your organization.
Instead of relying on team members to self-report the tools they use, Scrut gives you a real-time, integration-driven view of your vendor landscape — directly from the source of truth. This is particularly useful for surfacing shadow IT or tools that weren't formally procured.
Why does this matter?
For frameworks such as SOC 2, ISO 27001, GDPR, and others, maintaining an accurate, up-to-date vendor inventory is a core requirement. Gaps in your vendor list — whether due to shadow IT or simple oversight — can create compliance risks. By connecting Scrut to SSO tools, you ensure that newly authorized applications are automatically synced, keeping your vendor list up to date with minimal manual effort.
Supported Integrations
Scrut currently supports vendor discovery through:
Google Workspace: Discovers apps authorized via your Google Workspace account
Azure AD: Discovers apps connected through your Azure Active Directory tenant
How It Works
Step 1: Integrate with Google Workspace or Azure AD
Once you integrate Scrut with Google Workspace or Azure AD, Scrut automatically pulls in the third-party applications that are active in your account. These appear on the Risks → Vendors → Onboarding → Discovered from Integration page, where you can review and act on each one.

Heads Up!
The Source column specifies from where the vendor originates: Google Workspace or Microsoft Entra (Azure AD).
Step 2: Mark as Vendor
Review the discovered applications and click Mark as Vendor for the applications you want to officially track.

Enter the vendor details, including Status, URL, Category, Service Description, Assignee, and Entities. Include the vendor POC details (optional).

Review the details and click Save.

The vendor is now included in the official vendor list in the Vendor table.

Heads Up!
For vendors discovered via Google Workspace or Azure AD SSO integrations, the Source in the vendor table will be: SSO Discovery.
Step 3: Exclude an Application
If an application isn't a vendor you want to track, click Not a Vendor.

Provide a brief justification for your action.

The application stays on the Discovered from Integration page for reference, but won't appear in your Vendor table.
To reverse this decision, click Add as Vendor to move a previously ignored application to the Vendor table.
Heads Up!
Any actions you take on the Discovered from Integrations page are automatically captured in the corresponding Audit Logs.
