Join our Newsletter — 33% off our NHI Course

Approved Alternatives

Approved alternatives are IT-sanctioned applications or services offered when a user requests access to an unapproved tool. They reduce friction by giving employees a compliant way to complete work without bypassing policy. In practice, they are most effective when paired with blocking, warnings, or redirection.

What approved alternatives are meant to do in access governance

Approved alternatives are a control choice, not just a user convenience. They give people a sanctioned path to accomplish work when an unapproved application or service is requested, so security teams can reduce policy circumvention while keeping the business moving. The strongest programs treat them as part of a broader access strategy, not as a standalone user-experience feature.

The practical value is that the alternative is usually safer than a hard refusal with no usable replacement. When users are redirected to a compliant tool, organisations can preserve visibility, logging, contractual controls, and retention requirements instead of creating shadow usage in email, personal accounts, or informal file-sharing.

Where approved alternatives fit in the control stack

Approved alternatives sit between demand and enforcement. They work best when paired with blocking, warning, or redirect behaviour, because the control must change the user’s next step rather than merely advise against the unapproved option. In that sense, the mechanism is closer to policy enforcement plus guided substitution than to education alone.

They also help separate “business need” from “uncontrolled tool choice.” If the request is legitimate, the alternative can absorb it through a governed platform, standard contract, or centrally supported service. That lowers the chance that employees bypass procurement, security review, or data-handling rules just to complete ordinary work.

For examples of the broader access-control and policy-enforcement logic, NIST’s Security and Privacy Controls and the NIST Cybersecurity Framework 2.0 both support the idea that governance, protection, and response need to work together.

Why approved alternatives are often more effective than denial alone

A simple block can create workarounds if the user still has a legitimate task to finish. Approved alternatives reduce that pressure by making the compliant route obvious and immediate. That matters in organisations where productivity friction often drives unsafe tool adoption long before security teams notice it.

The most successful pattern is usually behavioural: warn, block, and immediately offer the sanctioned option in the same workflow. Without the replacement, the control can become a dead end; with it, the organisation can guide users toward a managed service that already meets security, legal, and operational requirements. When the alternative involves identity or credentials, the same principle also applies to protecting access paths and reducing unmanaged secret sprawl, as highlighted in the OWASP Non-Human Identity Top 10 and NIST SP 800-63 Digital Identity Guidelines.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.PO — Policy Approved alternatives implement policy-backed user choice and enforcement.
PR.AA — Identity Management, Authentication, and Access Control Approved alternatives often replace unmanaged access paths with governed access.
Recommendation — Define sanctioned tool alternatives and enforce them through policy-driven access decisions. Route users to approved services that preserve controlled access and auditability.
CIS Controls v8 6 — Access Control Management Approved alternatives reduce unauthorized software use by controlling permitted access paths.
15 — Service Provider Management Alternatives are often vendor-sanctioned services that need governance and oversight.
Recommendation — Restrict unapproved tools and publish sanctioned alternatives users can adopt. Approve replacement services through formal third-party risk and oversight processes.
OWASP Non-Human Identity Top 10 NHI-02 — Secrets and Credential Management Sanctioned alternatives can prevent users from moving work into unmanaged secret-bearing tools.
Recommendation — Use approved tools that keep credentials and secret handling under managed controls.

Practitioner Guidance

Governance implication: Treat approved alternatives as a policy-design problem, not a help-desk workaround. The alternative has to be credible enough that users will choose it instead of finding a bypass, which means it needs clear ownership, acceptable functionality, and a low-friction request path.

What to watch for: If users repeatedly request the unapproved tool anyway, the alternative is probably missing a feature, too hard to find, or not aligned to the real work pattern. In practice, the control succeeds when the sanctioned option is easier than exception hunting, not merely more compliant on paper.

Risk and Threat Considerations

Approved alternatives reduce shadow IT risk, but they can also fail quietly if the replacement is incomplete, obscure, or slower than the forbidden tool. When that happens, users may route sensitive work through unmanaged services, creating exposure for data, auditability, and third-party oversight.

Failure mechanism: The control breaks when policy blocks a tool without offering a usable substitute, or when the substitute is so poor that users move to personal accounts, browser extensions, file-sync services, or other unsanctioned channels. That behaviour restores convenience at the cost of visibility and control.

Impact: Loss of control over data handling, retention, logging, and access boundaries can follow, especially when the unsanctioned path involves external sharing or weak account governance. Over time, the organisation may also accumulate fragmented tooling, duplicated records, and unreviewed access paths that are harder to detect and remediate.