Google approved CellCog’s OAuth app verification on September 13, 2026. The approval covers the seven Google scopes behind two connectors, Gmail and Google Analytics, and it came after a CASA Tier 2 security assessment completed through TAC Security, an App Defense Alliance authorized lab. From now on, connecting Gmail or Google Analytics to a CellCog AI employee shows no unverified-app warning from Google, and the 100-user cap Google places on unverified apps no longer applies to those connects. Nothing changes for connections you already made.
This post is the record of what was assessed, what it changes, and what it does not mean. No email went out for this update; the change is invisible when it works, which is the point.
On this page · 7 sectionsOpen
Google approved CellCog’s OAuth app verification on September 13, 2026, for the Gmail and Google Analytics scopes behind the Gmail and Analytics connects. The gate was a CASA Tier 2 (Assurance Level 1) security assessment by TAC Security, an App Defense Alliance authorized lab.
What changes for you: connecting Gmail or Google Analytics to a CellCog AI employee no longer shows Google’s unverified-app warning, and the 100-user cap Google places on unverified apps is gone. Existing connections keep working; nobody reconnects.
Why the bar exists: Gmail’s full-access scope is one of Google’s restricted scopes. Google’s own rule is that apps handling restricted data through a third-party server complete an annual security assessment by a Google-approved assessor. An AI employee that reads and sends your mail is exactly that kind of app.
The assessment is built on the OWASP Application Security Verification Standard and covers the application itself: how it authenticates, controls access, protects data and handles secrets. The evidence pack CellCog submitted on August 14, 2026 answered 48 checks.
Plain words, on purpose: this is an assessment, not a certification, and there is no badge for it. We say ‘assessment completed’ and ‘Google approved’, dated, and nothing more. It is reassessed every year.
Scope is narrow and stated: Gmail and Google Analytics on CellCog’s own Google client. Drive, Calendar, Docs, Sheets and the other Google connectors run through a managed integration partner’s app and are outside this assessment.
§ 01Why an AI employee needs a verified door into Gmail
A chatbot that drafts an email for you to paste never touches your mailbox. An AI employee does. It reads the thread, replies from its own address or works yours, files what it learns, and comes back tomorrow. For that job to be real, the Gmail connection has to be a full one, and Google classifies full Gmail access as a restricted scope. Google’s rule for restricted scopes is direct: “Apps accessing restricted data from or through a third-party server must undergo an annual security assessment by a Google-approved third party.” An organization of AI employees that reads and sends mail on your behalf is exactly the kind of app that sentence describes, so the assessment was never optional for the product we are building. It was the cost of building it honestly.
§ 02What was assessed
| Item | What the record says |
|---|---|
| What Google approved | OAuth app verification for CellCog’s own Google client, September 13, 2026 |
| Scopes | Full Gmail (mail.google.com); contacts read; other contacts read; profile email read; Google Analytics read, edit and full access |
| The gate | CASA Tier 2 (Assurance Level 1), required by Google’s notice of August 11, 2026 |
| The assessor | TAC Security, an App Defense Alliance authorized lab |
| The evidence | 48 checks against the CASA requirements, submitted on the lab’s portal on August 14, 2026 |
| The cycle | Reassessed annually |
CASA is built on the OWASP Application Security Verification Standard. At Tier 2 the developer tests and documents the application against those requirements and the authorized lab validates the evidence; at Tier 3 the lab tests the application, its deployment infrastructure and its data storage itself. The requirements sit in the categories anyone who has read the ASVS would expect: authentication, session handling, access control, protection of data in transit and at rest, handling of secrets, configuration. What CellCog changed while working through them stays inside the company. The categories are public; the specifics of any one application’s defenses are not something a security-minded company publishes, and we are not going to start.
§ 03What changes when you connect
| Before September 13, 2026 | Now | |
|---|---|---|
| Connecting Gmail | Google’s unverified-app warning; 100-user cap on the app | Standard Google consent screen; no cap |
| Connecting Google Analytics | Same warning, same cap | Same consent screen, no cap |
| Existing connections | Working | Unchanged; nobody reconnects |
| Drive, Calendar, Docs, Sheets, Search Console, YouTube | Connect through a managed integration partner’s Google app | Unchanged; outside this assessment |
The last row matters. This assessment covers Gmail and Google Analytics on CellCog’s own Google client. The other Google connectors run through an integration partner’s app, with that partner’s own verification, and nothing on this page speaks for them.
§ 04What we say, and what we do not
The line we use, everywhere it appears, is this: Google OAuth app verification approved, September 2026; CASA Tier 2 security assessment completed through an App Defense Alliance authorized lab, reassessed annually. Dated, and specific to the scopes above.
On the marketing pages the same fact reads in plainer words, and the two surfaces use one sentence so nobody has to reconcile them: “Google reviewed how CellCog connects to your Gmail and Google Analytics and approved it in September 2026, after an independent App Defense Alliance authorized lab assessed our application security; both are repeated every year.”
What we do not say: certified. CASA is an assessment, the lab validates evidence, and Google does not audit anyone. There is no badge at this tier; the App Defense Alliance’s public disclosure language is for its lab-validated Tier 3 process, and Google’s Workspace Marketplace security badge requires Assurance Level 2. We hold neither and claim neither. We also do not say SOC 2, ISO 27001, enterprise-grade, or any phrase that borrows the weight of a certification we have not earned.
§ 05How the other platforms word it, from their own pages
Two companies in our category publish a CASA line, and both are worth reading for what the words carry. Coworker.ai’s Google Workspace page says “Coworker is SOC 2 Type II certified, GDPR compliant, and CASA Tier 2 certified.” 11x’s security overview says “11x holds SOC 2 Type II and CASA Tier 3 certification and complies with GDPR and CCPA.” Both are real assessments and both companies did the work; 11x’s Tier 3 is the deeper of the two, with the lab testing the infrastructure as well as the application, and it is a fair thing to be proud of. The word we would quarrel with is “certified”, which the App Defense Alliance’s own pages do not use for CASA. We passed the same Tier 2 gate Coworker did; we call it an assessment because that is what it is. Buyers who care about this should ask any vendor, us included, for the tier, the assessor, the date and the scopes covered, and read the answer against the App Defense Alliance’s assurance-level page rather than against the adjective.
§ 06What comes next
The assessment renews every twelve months, and the next cycle is on our calendar. A security page on cellcog.ai, with this record and the rest of what we publish about how the product handles your data, is in progress; this post will link it when it is live. The Gmail connection itself needs nothing from you.
§ 07Sources
Google, Restricted scope verification and Gmail API scopes, read September 16, 2026; App Defense Alliance, CASA overview, assurance levels and self-initiated assessment, read September 16, 2026; Google, Get your app featured in the Google Workspace Marketplace, read September 16, 2026; Coworker.ai, Google Workspace connector page, read September 16, 2026; 11x, Security and compliance overview, read September 16, 2026. Internal records: Google’s approval notice of September 13, 2026 and the assessor’s portal submission of August 14, 2026.
Q1What is CASA?
The Cloud Application Security Assessment, run by the App Defense Alliance. It applies the OWASP Application Security Verification Standard to apps that handle certain categories of Google user data, at tiers that differ by how the evidence is tested and verified. Google requires it for apps that access restricted scopes such as full Gmail through a third-party server, and it must be repeated every twelve months.
Q2What is the difference between Tier 2 and Tier 3?
At Tier 2, now called Assurance Level 1, the developer tests and documents the application against the CASA requirements and an authorized lab validates the evidence. At Tier 3, or Assurance Level 2, the lab itself tests the application, its deployment infrastructure and its data storage. Google’s Workspace Marketplace badge requires AL2; CellCog completed AL1, which is the level Google’s approval required for these scopes.
Q3Who assessed CellCog?
TAC Security, one of the App Defense Alliance’s authorized labs. The evidence pack was submitted on their portal on August 14, 2026, and Google’s approval arrived on September 13, 2026.
Q4Which scopes were approved?
Full Gmail access (mail.google.com), read access to contacts and other contacts, read access to the account’s email address, and Google Analytics read, edit and full access. These are the scopes behind CellCog’s Gmail and Google Analytics connects.
Q5Do I need to reconnect anything?
No. Existing Gmail and Google Analytics connections keep working exactly as before. New connections skip the warning screen.
Q6What does CellCog not claim?
That it is certified, audited by Google, SOC 2 or ISO 27001 compliant, or that any badge applies. CASA is an application security assessment with an annual cycle; that is the claim, dated, and the only one.
