Software and SaaS Approval Policy

Purpose

This policy controls the introduction of software, SaaS services, browser extensions, AI tools, and other technology that may access company systems or information.

The objective is to reduce shadow IT, data leakage, insecure integrations, unnecessary subscriptions, and unmanaged technology risk.

When Approval Is Required

Approval should be required where a tool will:

  • Store company information
  • Process sensitive information
  • Connect to company accounts
  • Receive OAuth permissions
  • Install software on company devices
  • Access email, files, CRM, source code, or other systems
  • Use company credentials
  • Create public-facing services
  • Use AI to process company information

Approval Review

Before approval, consider:

  • What information will the tool access?
  • Where is the information stored?
  • Who owns the vendor relationship?
  • Does it support MFA?
  • Can access be removed easily?
  • What permissions does it request?
  • Does it integrate with other company systems?
  • Can data be exported or deleted?
  • Does the company have appropriate contractual protections?
  • What happens when the company stops using it?

SaaS Integrations

OAuth applications and integrations should receive particular attention.

Avoid granting broad access such as:

  • Read all company email
  • Read or modify all files
  • Access all users
  • Manage directory settings
  • Access administrative functions
  • Permissions should match the business need

AI Tools

Before using AI tools for company work, consider:

  • Whether prompts are retained
  • Whether submitted information may be used for training
  • Whether sensitive data is permitted
  • Whether customer or employee data is involved
  • Whether generated output requires human verification
  • Whether company intellectual property is being submitted

Employees should not assume a publicly accessible AI service is approved for confidential company information.

Browser Extensions

Browser extensions can access significant amounts of information.

Extensions should be limited to approved business needs and periodically reviewed.

Trial Accounts

Free trials and temporary services should still be reviewed if company data or credentials will be involved.

Removal

When a tool is no longer required:

  • Cancel unnecessary accounts
  • Remove user access
  • Revoke OAuth permissions
  • Remove integrations
  • Export required company information
  • Delete company data where appropriate
  • Remove browser extensions or software

Inventory

Approved significant applications and SaaS services should be recorded in the Applications and Services Inventory.

Practical Rule

If a tool will access company data or systems, understand what it can access before approving it.