CrossTenant
Home / Features / Google Cloud visibility

Google Cloud visibility

Many Google Workspace customers also hold a Google Cloud estate nobody is watching: projects nobody remembers, grants nobody reviews. CrossTenant reads it, read-only, from the same console as the rest of the fleet.

Prefer email? Get in touch and we run onboarding with you.

What's included

Signals before any grant

Before the customer grants anything in Google Cloud, the console can flag consumer Gmail accounts holding organisation IAM roles, from data it already holds. A first look at shadow infrastructure, with no new permissions involved.

zero grants consumer accounts

Project inventory

Every project in the customer's Google Cloud organisation, listed live. The estate that grew up beside the Workspace tenant (a developer's experiment, an agency's leftover, a forgotten integration) becomes visible from the console that already watches the rest of their Google footprint.

live listing per organisation

IAM posture findings

Who can act on the estate: principals outside the customer's domain, personal Gmail accounts flagged separately, and service accounts holding owner or editor roles. A bounded posture summary, built to surface the grants worth questioning rather than to dump every binding.

external principals owner / editor bounded summary

Billing visibility

Billing accounts and which projects link to them, so unowned projects have an owner trail to follow. Billing sits behind its own separate grant: the customer enables it independently, and the rest of the module works without it.

billing accounts separate grant

Keyless, read-only access

The customer grants read roles to the console's identity directly in Google Cloud IAM: no service-account key files, and no domain-wide delegation involved. Each section degrades independently, and when a role is absent the console shows the grant instructions in-product rather than a dead end.

no key files direct iam degrades per section

Nothing persisted

Every request is a live read, the same as the rest of the console: no copy of the customer's cloud estate is kept, and results are fetched, rendered, and discarded. What you see is the estate as Google Cloud reports it right now.

live reads nothing stored

Google Cloud is read-only by design today: the customer grants viewer-level roles at the organisation level, so nothing CrossTenant holds can change their cloud estate. Billing is a separate grant on purpose, which lets a customer approve estate visibility without approving spend. It does need the customer to hold a Google Cloud organisation, because that is what projects hang from: loose projects without one have nothing to enumerate. The IAM sweep is a bounded posture summary rather than a full export, which is what keeps it fast enough to run across a fleet. Cost optimisation advice is roadmap work, so today you get where the money flows, not what to cut.

Google Cloud

See the cloud estate nobody was watching

Projects, IAM posture, and billing links, read live from the console that already watches the Workspace side of every customer.