Now in pilot — Google Workspace

Access reviews that
actually get done.

Least by Juste™ connects to your Google Workspace, finds risky access, and generates a signed audit-ready evidence bundle — in under 30 minutes.

Read-only OAuth — nothing written to your Workspace
Results in under 30 minutes
PDF + CSV evidence ready for auditors
app.getleast.io/dashboard
J
Least by Juste™
Workspace
Access Review
Evidence
Connections
Settings
Access Review
yourcompany.com · Last scan today at 2:05 PM
High Risk
4
Medium Risk
7
Reviewed
8 / 11
HIGH
Super Admin Account — flagged for explicit review
APPROVE
HIGH
Inactive Account — no sign-in for 127 days
REVOKE
MED
Shared Account Pattern — display name matches shared mailbox heuristic
REVIEW
The problem

Access reviews shouldn't take a week.

Most small businesses do access reviews manually — in spreadsheets, if at all. By the time the audit comes, the data is stale and the evidence doesn't exist.

⏱️

Hours of manual work

Exporting user lists, cross-referencing roles, building spreadsheets. Repeated every quarter for every client.

👻

Stale accounts go unnoticed

Employees leave. Accounts stay. Nobody reviews them until the breach or the audit — whichever comes first.

📋

No evidence when auditors ask

SOC 2, HIPAA, cyber insurance, and client questionnaires all require documented evidence of access reviews. "We checked it" isn't enough.

🔑

Too many super admins

Google Workspace tenants accumulate elevated privileges over time. No one audits who actually needs admin access.

How it works

From connection to
evidence in three steps.

1
~30 seconds

Connect Google Workspace

Authorize Least with read-only OAuth. No passwords stored. No data written to your Workspace. We request only the minimum scopes needed to read users, groups, and admin roles.

🔒 Read-only · Nothing is modified in your Workspace
2
~15–45 seconds

Run the access review

Least pulls your full directory and runs a 7-rule risk engine against every user, group, and admin role. Each finding gets an AI-generated explanation and a recommended action — no guesswork required.

🤖 AI explanations on every finding
3
~10–20 minutes

Review, decide, export

Work through each finding: Approve, Revoke, or flag for Needs Review. Add notes documenting your reasoning. When you're done, export a signed PDF report and CSV log — auditor-ready, timestamped, branded with your company name.

📄 PDF + CSV export · Local timezone · Your company name in the header
The risk engine

7 rules. Every user. Every scan.

Derived from least-privilege best practices and common audit requirements for SOC 2, HIPAA, and cyber insurance frameworks.

#1HIGH

Super Admin Account

Any super admin or global admin account is flagged for explicit review. Elevated privileges should be intentional, minimal, and documented.

#2HIGH

Inactive Admin

Admin accounts with no sign-in activity in 60+ days. Dormant privileged accounts are high-value targets — if no one's using them, they shouldn't exist.

#3HIGH

External Privileged Account

External or guest accounts holding admin or delegated roles. Third-party access that exceeds what was originally granted and may have outlasted the relationship.

#4MEDIUM

Stale Account

Any account — employee or contractor — with no sign-in in 90+ days. Former users with lingering access are a quiet, persistent risk in every tenant.

#5MEDIUM

Shared Account Pattern

Accounts whose display names match shared-use patterns (shared@, info@, team@, helpdesk@). Shared credentials produce no accountability and break the audit trail.

#6MEDIUM

Oversized Privileged Group

Privileged groups with more than 20 members. Broad group access is the easiest way for elevated privileges to spread silently across an organization.

#7MEDIUM

Stacked Privileges

Accounts that are both Admin and DelegatedAdmin simultaneously. Stacked roles signal privilege creep from accumulated assignments that were never cleaned up.

Evidence exports

Hand it to an auditor.
Import it into your ticketing system.

Every export is timestamped in your local timezone and branded with your company name.

📄

PDF Access Review Report

A formal, signed report listing every finding, severity, your decision, and any notes you added. Designed to be handed directly to a compliance auditor, cyber insurance reviewer, or client.

Company branded Timestamped Decision + notes AI explanations
📊

CSV Evidence Log

A structured log of every finding with all metadata: rule, severity, affected account, decision, and timestamp. Import into ConnectWise, Jira, ServiceNow, or any ticketing system.

Machine readable All fields exported Local timezone Importable
Pricing

Simple. Per workspace.

No per-seat pricing. No surprises. One flat price per Google Workspace tenant — scale as you grow.

Pilot
Free
Limited early access · No credit card
  • 1 Google Workspace tenant
  • Up to 25 users scanned
  • All 7 risk rules
  • PDF + CSV evidence export
  • Direct founder support
Get pilot access
Growth
$399 / mo
Up to 75 users · Per tenant · Billed monthly
  • Everything in Starter
  • Up to 75 users scanned
  • Priority support
  • Multi-workspace management
  • Scan history + delta reports
Contact us
Plus
$699 / mo
Up to 200 users · Per tenant · Billed monthly
  • Everything in Growth
  • Up to 200 users scanned
  • White-label PDF reports
  • SOC 2 / HIPAA control mapping
  • API access + integrations
  • Dedicated onboarding
Contact us
About Juste

Built by someone who felt the problem firsthand.

Juste LLC is a Tampa-based technology company building identity governance tools for organizations that can't afford to get it wrong.

Our first product, Least by Juste™, was built by a founder with a decade in enterprise technology, an information security degree, and direct experience watching organizations fail access reviews they didn't know they were taking.

Honest software

We show you why, not just what. Every finding has an explanation a non-technical person can act on.

Evidence you can defend

Reports designed to withstand auditor scrutiny — timestamped, signed, and structured for compliance workflows.

Built for the 98%

Enterprise IGA tools cost six figures. We're building governance for the companies that can't afford that — and need it just as much.

By the numbers
7
Risk rules in the engine
<30
Minutes to first evidence bundle
0
Writes to your Workspace
2026
Founded · Tampa, FL
"Governance software should be honest: it should show you why, not just what, and produce records a real auditor can review."

Run your first access review today.

Free during the pilot. No credit card. Takes under 30 minutes.

Start free →

Questions? Email [email protected]