Google Cloud visibility
Many Google Workspace customers also hold a Google Cloud estate nobody is watching: projects nobody remembers, grants nobody reviews. CrossTenant reads it, read-only, from the same console as the rest of the fleet.
Prefer email? Get in touch and we run onboarding with you.
What's included
Signals before any grant
Before the customer grants anything in Google Cloud, the console can flag consumer Gmail accounts holding organisation IAM roles, from data it already holds. A first look at shadow infrastructure, with no new permissions involved.
Project inventory
Every project in the customer's Google Cloud organisation, listed live. The estate that grew up beside the Workspace tenant (a developer's experiment, an agency's leftover, a forgotten integration) becomes visible from the console that already watches the rest of their Google footprint.
IAM posture findings
Who can act on the estate: principals outside the customer's domain, personal Gmail accounts flagged separately, and service accounts holding owner or editor roles. A bounded posture summary, built to surface the grants worth questioning rather than to dump every binding.
Billing visibility
Billing accounts and which projects link to them, so unowned projects have an owner trail to follow. Billing sits behind its own separate grant: the customer enables it independently, and the rest of the module works without it.
Keyless, read-only access
The customer grants read roles to the console's identity directly in Google Cloud IAM: no service-account key files, and no domain-wide delegation involved. Each section degrades independently, and when a role is absent the console shows the grant instructions in-product rather than a dead end.
Nothing persisted
Every request is a live read, the same as the rest of the console: no copy of the customer's cloud estate is kept, and results are fetched, rendered, and discarded. What you see is the estate as Google Cloud reports it right now.
Google Cloud is read-only by design today: the customer grants viewer-level roles at the organisation level, so nothing CrossTenant holds can change their cloud estate. Billing is a separate grant on purpose, which lets a customer approve estate visibility without approving spend. It does need the customer to hold a Google Cloud organisation, because that is what projects hang from: loose projects without one have nothing to enumerate. The IAM sweep is a bounded posture summary rather than a full export, which is what keeps it fast enough to run across a fleet. Cost optimisation advice is roadmap work, so today you get where the money flows, not what to cut.
Google Cloud
See the cloud estate nobody was watching
Projects, IAM posture, and billing links, read live from the console that already watches the Workspace side of every customer.