Practitioner's guide to the future of identity — new maturity model
Access the guide

An online legal services company secures its data and AI pipelines across GCP, Snowflake, and Google workspace

688 OAuth apps had access to corporate data without central approval. Oleria mapped resource-level access across Google Cloud, Snowflake, and Google Workspace, brought every one of those apps under governance, and moved engineers from standing privileges to time-boxed just-in-time access.

Watch video

856,000

Drive files

Plus 111 GCP resources and ~5,700 Snowflake assets, mapped to every human and non-human identity

238M+

Activities per week

Normalized across GCP (233M+) and Snowflake (5M+) to power usage-aware reviews

688

OAuth apps

Discovered, risk-scored, and brought under formal governance

Industry

Legal technology

SaaS

Use Cases

Cloud data pipeline access security

OAuth app governance

Just-in-time access

Size

Mid-market

~500 employees

Millions of users

About the organization

The company makes legal services accessible and affordable for businesses and individuals through digital contracts, online attorney consultations, incorporation services, and AI-driven document analysis. It processes confidential client documents on cloud data pipelines across Google Cloud, Snowflake, and Google Workspace.

The challenge

Growth in AI-driven legal products expanded service accounts, storage buckets, and data warehouses faster than access controls could follow. Existing visibility tools showed parts of the picture with no path to remediation, so security engineers worked through slow manual review cycles.

  • Data pipeline exposure. Fine-grained access across Cloud Storage buckets, BigQuery tables, and Snowflake warehouses grew complex, raising exposure risk for client legal records and AI training data.
  • OAuth app sprawl. Employees had authorized 688 third-party OAuth applications through Google Workspace without central security approval.
  • Reviews without usage context. Quarterly access reviews ran on spreadsheet exports with no data on actual use, so managers approved access they could not evaluate.
  • Standing privileges. Access requests went through manual IT tickets, so engineers kept broad standing access in place of temporary, task-specific access.

"Oleria changed how we approach identity security across our multi-cloud environment. Connecting permissions to real activity in GCP and Snowflake let us remove standing privileges and govern shadow IT without slowing our engineering teams, and it replaced manual spreadsheet audits with automated access governance."

Head of Information Security and Compliance, online legal services company

“People are really, really good at sharing things — but not so good at revoking those privileges once they’re no longer needed.”

Peter Clay
CISO, Aireon

The solution

The company deployed Oleria across Google Workspace, Google Cloud, Snowflake, Okta, and Google Admin. Oleria maps every human and non-human identity to the resources it can reach and to how it uses them.

  • Resource-level access graph maps permissions down to individual Cloud Storage buckets, BigQuery tables, Snowflake schemas, and Drive files.
  • Activity normalization processes 238 million+ weekly events across GCP and Snowflake and compares entitlements with actual use to expose dormant and over-provisioned access.
  • OAuth app governance connects to Google Admin to discover and risk-score third-party apps, with policy-driven token revocation.
  • Just-in-time access requests replace standing developer privileges with self-service, time-boxed access that includes automatic expiration, peer usage benchmarks, and context-aware approval routing.
  • Oleria Integration Studio connects proprietary internal platforms and AI services without custom integration code.

Business outcomes

The company governs access to its data and AI infrastructure with continuous evidence in place of quarterly spreadsheets.

  • Activity-backed access reviews. Managers certify access with usage metrics, peer benchmarks, and live HR status.
  • Least privilege on data pipelines. Access to GCP and Snowflake matches actual need, reducing exposure for legal documents and model training data.
  • OAuth risk governed. All 688 OAuth apps are under central control, and the team can revoke elevated third-party tokens on policy.
  • Fewer access tickets. Engineers request time-boxed access on their own and keep their delivery pace.
  • Continuous audit evidence. Every access change is logged, which simplifies SOC 2 and GDPR evidence collection.

Key takeaways

  • Resource-level visibility is what makes least privilege enforceable on cloud data pipelines.
  • OAuth apps authorized by employees are an access path that deserves the same governance as user accounts.
  • Time-boxed just-in-time access lets engineers move fast without carrying standing privileges.

“If you ask any CISO, ‘How many files have you shared outside the company?'. . . most don't have answers — or they don’t have easy ways to answer those questions. In Oleria, I can answer those questions with a click.”

Mark Carter
CIO and CISO
Vimeo

“Having visibility and the ability to remove that share or that file access...is a real differentiator.”

Kevin Towey
Director, Security GRCP
Vimeo

“Oleria allows our business to focus on driving revenue, and less on checking compliance boxes.”

Kevin Towey
Director, Security GRCP
Vimeo