Software Nobody Approved
Tools arrive because the approved ones do not do the job. The install is a symptom and treating it as misconduct guarantees more of it.
Approved software
Never enforced
As written
Only software from the approved list may be used for company business.
What happens
The approved list has not been updated in years and does not contain anything people actually need.
Teams use what works, pay for it personally or on a card, and do not mention it.
The operative rule is: do not spend company money on it without asking, and do not put customer data in it.
Every organisation has software it did not approve, running on machines it owns, holding data it is responsible for. The question is what the presence of it indicates.
The control described in “Software Nobody Approved” becomes easier to defend when technical state and day-to-day work evidence are not confused. A team considering employee monitoring software for employee monitoring software should document the purpose, visible settings, manager permissions and correction route, while device-management records remain the source of truth for configuration and enforcement.
Why it arrives
The approved tool does not do the thing. A file will not convert, a format is unsupported, a feature is missing.
For a separate benchmark relevant to “Software Nobody Approved”, consult the CISA insider-threat mitigation resources. Use it to test purpose, notice, permissions, retention and response procedures against the proposed operating model rather than treating a generic checklist as proof that the rule works.
The approved tool is too slow to get. A request takes three weeks and the work takes two days.
Nobody knows what the approved tool is. The list exists, is not findable, and has not been updated since the systems changed.
Or there is no approved equivalent at all, which is common for anything new.
In each case the install is a workaround, and the person doing it is solving a problem the organisation created.
Why treating it as misconduct fails
It stops people telling you.
An organisation that disciplines for an unapproved tool learns about the next one during an incident rather than when somebody mentions it. The tool is still there; the visibility is gone.
Which converts a manageable inventory problem into an unmanageable one, and the inventory problem was the real issue.
What the presence of it tells you
The list of unapproved tools in use is a precise specification of what the approved estate fails to provide.
Produced honestly, it is the most useful procurement document the organisation will see. It is also unobtainable from any audit, because an audit finds what is installed and not why.
The arrangement that works
A route that answers quickly. Days rather than weeks for anything low-risk.
A self-service catalogue of things anybody can install without asking.
An amnesty, once: tell us what you are using, nothing happens, we will either approve it or find you an alternative.
And a clear line about what is never acceptable regardless of convenience: customer data in an unassessed service, anything requiring a payment commitment, anything that needs access to company systems.
That last line is the clause worth having, and it is narrower and more enforceable than a general prohibition.
The procurement finding
Run the amnesty and the list is usually short: a file converter, a diagramming tool, a transcription service, a scheduling tool.
Four or five items, cheap, and approving them removes most of the unapproved estate permanently.
What the amnesty produces
A short list: a file converter, a diagramming tool, a transcription service, a scheduling tool. Four or five items, cheap, and approving them removes most of the unapproved estate permanently.
The line worth keeping
Customer data in an unassessed service, anything requiring a payment commitment, anything needing access to company systems. Narrower than a general prohibition and actually enforceable.
Why the amnesty beats the audit
An audit finds what is installed. It cannot find why, and the why is the procurement specification the organisation has been missing.
Why discipline makes it worse
The tool stays and the visibility goes. The organisation learns about the next one during an incident, which converts a manageable inventory problem into an unmanageable one.
The line that is worth keeping
Customer data in an unassessed service, anything requiring a payment commitment, anything needing access to company systems. Three prohibitions, each specific, each enforceable, each explicable to somebody who wants to install a file converter.
That is a narrower rule than a general prohibition on unapproved software and it is the one people will follow, because it draws the line where the risk actually is rather than where the administration is easiest.