Initial triage outputs
A documented decision: full review / light review / direct rejection, with justification. And notification to the requester with the expected window.
PLAYBOOK
Every organization has tools awaiting a decision: some waiting months because the path is unclear. This playbook makes the decision predictable and documented.
The tool approval playbook has four stations: initial triage (does it merit full review?), the security and legal review (checklist + processing contract), the approval decision (documented with reasons), and post-launch tracking (register measures actual usage versus declared justification). Each station has an owner and a window.
THE PATH
Every tool passes the same path, and speed varies by sensitivity level, not by the requester's name.
Five quick questions: does it process sensitive data? does it send data outside the system? does it need system privileges? is the category subject to regulatory restrictions? has it been requested by more than one department? Two "yes" answers open the full review.
The ten-item tool security checklist + terms of service review + processing contract (if required). Every unmet item is documented with a decision: accepted with condition / rejected for this reason.
The decision documents four elements: approved / not approved, for these reasons, under these conditions, and the next review has a date. A document that is stored, not a debate that is forgotten.
One month after launch, the register is read: does actual usage match the declared justification? And did unexpected use cases emerge requiring additional security review?
Durations are illustrative: light-review paths may be faster depending on tool sensitivity level.
IN DETAIL
What is documented prevents repeated debate: every tool ends with a document, not a memory.
A documented decision: full review / light review / direct rejection, with justification. And notification to the requester with the expected window.
The security checklist report, the legal team's position on the terms, and the processing contract signed or with justification for its absence.
A signed decision document, notification to the requester and approvers, and addition of the tool to the approved or rejected registry.
A monthly actual-usage report, a decision to review approval if reality diverges from justification, and notification to users of any change.
ROLES
Three roles suffice for most organizations, and the path works even with a small team.
CLOSE
Organizations that spend months on a single tool decision don't suffer from over-rigor: they suffer from a missing path. Standardized questions and a documented decision make a rejection respectable and an approval reassuring, and make the discussion start from facts, not fears.
Run it through the four-station path with us, and we find exactly where the blocker is.
IMPLEMENTATION QUESTIONS
No, initial triage classifies tools: full review for high-sensitivity, light review for others. The criterion is the five questions, not the requester's name.
The refusal is documented in the decision document. Any approval that ignores unanswered items is a decision with accepted risk: it must be intentional and documented.
Print the playbook and apply its stations to the first tool waiting, then bring whatever you got stuck on.
Durations are illustrative: the path is adapted to your organization's size and decision speed.