Google Workspace Security Posture Auditor - CIS Benchmark & Best Practice Checks
Project description
GWS Security Auditor
Open-source Google Workspace security posture assessment tool
Audit your GWS tenant against CIS Benchmarks, CISA SCuBA Baselines, and industry best practices.
Description
GWS Security Auditor is a Python-based tool that automatically evaluates your Google Workspace configuration against four industry-standard security frameworks. It connects to your tenant via read-only API scopes, collects configuration data, evaluates 200 security checks (including 24 critical-severity checks), and generates actionable reports in HTML, JSON, and CSV formats.
Key Features
- 200 security checks across 4 frameworks (CIS, CISA SCuBA, Google, Other)
- Critical severity system -- 24 checks flagged as critical with impact explanations
- Interactive setup wizard --
gws-auditor setupautomates GCP project, API enablement, and service account creation - Multi-credential profiles -- switch between tenants with
--profile - Customer ID auto-discovery -- no manual ID configuration needed
- CI/CD integration --
--fail-on-criticalexits with code 2 for pipeline gates - Standalone executables -- single-file binaries for Linux and Windows (no Python required)
- Interactive dashboard -- Plotly Dash web UI with dark mode, charts, and drill-down
- AI security analyst -- natural language queries via OpenAI, Anthropic, or AWS Bedrock
CLI
$ gws-auditor
╭──────────────── CRITICAL SECURITY FINDINGS (13) ────────────────╮
│ CIS-4.1.1.1 2SV not enforced for admins │
│ CIS-3.1.3.2.3 DMARC policy is weak (p=none) │
│ ADD-33 7 apps with dangerous OAuth scopes │
╰─────────── These findings require immediate attention ──────────╯
Audit Summary
┌─────────────────────┬───────┐
│ Total Checks │ 200 │
│ Passed │ 96 │
│ Failed │ 64 │
│ Critical Failures │ 13 │
│ Pass Rate │ 60.0% │
└─────────────────────┴───────┘
HTML Report
At a Glance
| Framework | Full Name | Checks |
|---|---|---|
| CIS | CIS Google Workspace Foundations Benchmark v1.3.0 | 84 |
| CISA | CISA SCuBA Baselines for Google Workspace | 82 |
| Google Security Checklist for Medium & Large Businesses | 21 | |
| OTHER | Additional best-practice checks | 13 |
| Total | 200 |
[!TIP] Run
gws-auditor --list-checksto see the full check list with IDs, titles, levels, sources, and severity.
Installation
pip (Recommended)
# Core audit tool
pip install -e .
# With interactive dashboard
pip install -e ".[dashboard]"
# With AI analyst (choose one or all providers)
pip install -e ".[ai-anthropic]"
pip install -e ".[ai-openai]"
pip install -e ".[ai]" # all providers
# With standalone build support
pip install -e ".[build]"
# Everything
pip install -e ".[dashboard,ai,dev,build]"
Standalone Executable
Pre-built binaries are available on the Releases page -- no Python installation required.
# Linux
chmod +x gws-auditor-linux-amd64
./gws-auditor-linux-amd64 --credentials credentials.json --subject admin@company.com
# Windows
gws-auditor-windows-amd64.exe --credentials credentials.json --subject admin@company.com
[!IMPORTANT] Standalone binaries don't bundle a
config.yaml. You must pass at minimum--credentialsand--subjecton the command line.
To build from source:
pip install -e ".[build]"
python build.py # creates dist/gws-auditor
Requirements
- Python 3.9+ (not needed for standalone executable)
- Google Workspace Super Admin or delegated admin access
- Service Account with domain-wide delegation (recommended) or OAuth 2.0 credentials
Setup
Automated Setup (Recommended)
The setup wizard automates GCP project configuration, API enablement, service account creation, and config generation:
# Interactive wizard
gws-auditor setup
# With pre-set values
gws-auditor setup --project my-gcp-project --subject admin@company.com
# Use existing service account key
gws-auditor setup --existing-sa-key credentials.json --subject admin@company.com
The wizard handles 7 of 9 setup steps automatically. The only manual step is authorizing domain-wide delegation scopes in the Google Admin Console -- the wizard provides the Client ID, scope string, and a direct link.
Manual Setup
See docs/SETUP_GUIDE.md for step-by-step manual instructions covering:
- GCP Project -- create or select a project
- Enable APIs -- Admin SDK, Gmail, Drive, Calendar, Groups Settings, Cloud Identity, Chrome Policy, Chat, Alert Center, License Manager
- Service Account -- create with domain-wide delegation, download JSON key
- Domain-Wide Delegation -- authorize 21 read-only scopes in Admin Console
- Configuration -- create
config.yaml - Validation --
gws-auditor --validateto test connectivity
Configure
auth:
method: service_account
credentials_file: credentials.json
credentials_dir: credentials # folder for multi-credential profiles
subject: admin@company.com
customer_id: auto # auto-discover from API (or explicit ID)
profiles: # named credential profiles
production:
credentials_file: credentials/prod.json
subject: admin@company.com
staging:
credentials_file: credentials/staging.json
subject: admin@staging.company.com
checks:
levels: [L1, L2]
sources: [CIS, OTHER, GOOGLE, CISA]
sections: all
exclude: []
output:
directory: ./reports
formats: [html, json, csv]
options:
cache_data: true
cache_directory: ./cache
org_units: all
max_retries: 5
rate_limit_qps: 10
ai:
provider: anthropic # openai, anthropic, or bedrock
model: "" # blank = provider default
api_key: "" # prefer env: ANTHROPIC_API_KEY / OPENAI_API_KEY
Usage
Full Audit
gws-auditor # uses config.yaml
gws-auditor -v # verbose
gws-auditor -vv # debug logging
# Without config.yaml (minimum required arguments)
gws-auditor --credentials credentials.json --subject admin@company.com
[!IMPORTANT] When no
config.yamlis present, both--credentialsand--subjectare required. The--subjectflag specifies the super-admin email used for domain-wide delegation. Without it, all API calls will fail with permission errors.
Credential Profiles
gws-auditor --profile ? # list available profiles
gws-auditor --profile production # use named profile
CI/CD Pipeline
gws-auditor --fail-on-critical # exit code 2 if critical checks fail
Filter and Target
gws-auditor --check CIS-1.1.1 # single check
gws-auditor --level L1 # baseline checks only
gws-auditor --source CIS --source CISA # multiple frameworks
gws-auditor --section Gmail # specific section
gws-auditor --exclude CIS-1.1.3 # exclude checks
gws-auditor --cached ./cache/ # re-run on cached data
Validate Connectivity
gws-auditor --dry-run # quick auth test
gws-auditor --validate # detailed API probe
CLI Reference
gws-auditor [OPTIONS] [COMMAND]
Commands:
setup Interactive setup wizard
dashboard Launch web dashboard
analyst AI security analyst REPL
Options:
-c, --config PATH Configuration file (default: config.yaml)
--credentials PATH Credentials JSON file
--subject EMAIL Delegated admin email
--customer-id ID Customer ID (default: auto)
--profile NAME Use named credential profile (? to list)
--check ID Run single check
--level {L1,L2} Filter by level (repeatable)
--source {CIS,OTHER,GOOGLE,CISA} Filter by source (repeatable)
--section NAME Filter by section (repeatable)
--exclude ID Exclude check IDs (repeatable)
-o, --output-dir PATH Output directory
-f, --format {html,json,csv} Output format (repeatable)
--dry-run Validate auth only
--validate Detailed API/scope validation
--cached DIR Re-run on cached data
--list-checks List all checks
--fail-on-critical Exit code 2 on critical failures (CI/CD)
--resume Resume interrupted collection
--no-cloud-info Suppress Argus Cloud info message
--skip-update-check Skip version update check
--update Update to latest version and exit
-v, --verbose Increase verbosity
-q, --quiet Suppress output
Interactive Dashboard
pip install -e ".[dashboard]"
gws-auditor dashboard # http://127.0.0.1:8050
gws-auditor dashboard --port 9000 --host 0.0.0.0
Features: report selector, multi-filter dropdowns, metric cards, status donut chart, section bar charts, detailed findings table with search, compliance drill-down, dark/light mode toggle, CSV/HTML export.
AI Security Analyst
pip install -e ".[ai-anthropic]"
export ANTHROPIC_API_KEY="sk-ant-..."
gws-auditor analyst --provider anthropic
# Or with OpenAI
pip install -e ".[ai-openai]"
export OPENAI_API_KEY="sk-..."
gws-auditor analyst --provider openai
Query audit findings in natural language, get remediation plans, compare reports, and analyze compliance posture. Also available as a chat page in the dashboard.
Critical Checks
24 checks are tagged as CRITICAL -- failures represent severe security risks requiring immediate attention:
| Domain | Examples | Risk |
|---|---|---|
| Authentication | MFA not enforced, weak MFA methods, no session limits | Credential theft, account takeover |
| Missing SPF/DKIM/DMARC, auto-forwarding enabled | Domain impersonation, data exfiltration | |
| Data Protection | Public file publishing, 'anyone with link' sharing | Data breach, unauthorized access |
| Infrastructure | Dangerous OAuth apps, unrestricted third-party access | Silent data exfiltration, configuration tampering |
Each critical check includes a critical_reason explaining the business impact. The CLI shows a red banner for critical failures. Reports include severity and reason in JSON/CSV output.
Posture Score
Every audit produces a posture score (0-100) that weights findings by severity. Critical failures are squared, so they dominate the score:
| Grade | Score | Meaning |
|---|---|---|
| A | 90-100 | Excellent — minimal risk |
| B | 80-89 | Good — minor gaps |
| C | 70-79 | Fair — moderate risk |
| D | 50-69 | Poor — significant gaps |
| F | 0-49 | Critical — immediate action needed |
See the Posture Score wiki page for the full formula, examples, and improvement guidance.
Development
git clone <repo-url>
cd gws-security-auditor
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dashboard,ai,dev]"
pytest # 1162 tests
Building Standalone Executable
pip install -e ".[build]"
python build.py # dist/gws-auditor (~90 MB)
python build.py --onedir # faster startup
python build.py --clean # clean rebuild
Push a tag v* to trigger the GitHub Actions workflow that builds Linux + Windows executables and attaches them to the release.
Argus Cloud
Open source for individuals. Cloud-hosted for teams.
GWS Security Auditor is and will always be free and open source. For teams that need automation, collaboration, and compliance history, Argus Cloud extends the auditor with managed infrastructure:
| Open Source (Free) | Argus Cloud (from €12.50/mo) | |
|---|---|---|
| 200 security checks, 4 frameworks | ✓ | ✓ |
| HTML, JSON, CSV reports | ✓ | ✓ |
| Interactive dashboard | ✓ | ✓ |
| AI Analyst | BYO API key | Included |
| Automated daily/weekly scans | — | ✓ |
| Hosted dashboard with trends | — | ✓ |
| 12-month compliance history | — | ✓ |
| Regression alerts (Slack, email) | — | ✓ |
| Multi-tenant & team access | — | ✓ |
| JIRA, webhooks, RBAC | — | ✓ |
| Priority support | Community |
Sign up for free trial | Pricing
[!TIP] To suppress the CLI cloud info banner, pass
--no-cloud-infoor setGWS_AUDITOR_NO_CLOUD_INFO=1.
Acknowledgements
Inspired by Prowler, ScubaGoggles, and GAM.
License
This project is licensed under the GNU Affero General Public License v3.0 (AGPL-3.0). See the LICENSE file for details.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file gws_security_auditor-1.3.0.tar.gz.
File metadata
- Download URL: gws_security_auditor-1.3.0.tar.gz
- Upload date:
- Size: 294.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
a969f68dc855f9e792b0b8c521373e21b177fbc435d6b6ccbd052bb89816fe42
|
|
| MD5 |
963f30e801ee2cf85175d6284d61ed1a
|
|
| BLAKE2b-256 |
ba1d6f59f624e1d014ddf5abb585b7b2a5b59df8dce259fffeabeda9158a72d6
|
Provenance
The following attestation bundles were made for gws_security_auditor-1.3.0.tar.gz:
Publisher:
publish-pypi.yml on argusssec-cloud/gws-auditor
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
gws_security_auditor-1.3.0.tar.gz -
Subject digest:
a969f68dc855f9e792b0b8c521373e21b177fbc435d6b6ccbd052bb89816fe42 - Sigstore transparency entry: 1629350658
- Sigstore integration time:
-
Permalink:
argusssec-cloud/gws-auditor@a3024f637e65417203882503b9d2dbea5d52e9da -
Branch / Tag:
refs/tags/v1.3.0 - Owner: https://github.com/argusssec-cloud
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@a3024f637e65417203882503b9d2dbea5d52e9da -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file gws_security_auditor-1.3.0-py3-none-any.whl.
File metadata
- Download URL: gws_security_auditor-1.3.0-py3-none-any.whl
- Upload date:
- Size: 330.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9e7a45c2ea5ee113e4e28b74bbebe5f885f4ffd2104e8321c2232aaddcdc422a
|
|
| MD5 |
5f55caff289488d53edc43ec45e000a6
|
|
| BLAKE2b-256 |
9fa6bd1d5b4406a7fb7c75da8929c6edb70a4e9e7263e5d7c45ae3f6ca3c6e07
|
Provenance
The following attestation bundles were made for gws_security_auditor-1.3.0-py3-none-any.whl:
Publisher:
publish-pypi.yml on argusssec-cloud/gws-auditor
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
gws_security_auditor-1.3.0-py3-none-any.whl -
Subject digest:
9e7a45c2ea5ee113e4e28b74bbebe5f885f4ffd2104e8321c2232aaddcdc422a - Sigstore transparency entry: 1629350685
- Sigstore integration time:
-
Permalink:
argusssec-cloud/gws-auditor@a3024f637e65417203882503b9d2dbea5d52e9da -
Branch / Tag:
refs/tags/v1.3.0 - Owner: https://github.com/argusssec-cloud
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@a3024f637e65417203882503b9d2dbea5d52e9da -
Trigger Event:
workflow_dispatch
-
Statement type: