Skip to main content
Run any Skill in Manus
with one click

detect-admin-role-grant-workspace

Stars3
Forks0
UpdatedJuly 6, 2026 at 04:25

Detect Google Workspace protected admin role grants, especially Super Admin, that occur outside an operator-maintained break-glass granter allow-list. Reads OCSF 1.8 Account Change (3001) or native events emitted by `ingest-workspace-admin-ocsf` with `application_name=admin`, role assignment parameters, and assignee details; emits OCSF Detection Finding (2004) tagged with MITRE ATT&CK T1098.003. Use when the user mentions Workspace admin role grants, Super Admin escalation, or break-glass governance. Do NOT use on raw Admin SDK payloads before normalization, on non-Workspace role events, or as a remediation skill.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
5 files
SKILL.md
readonly