Employees should check with IT before adopting a new tool, choose reputable apps from trusted sources, and review requested permissions carefully. If the app is approved, they should use strong unique credentials, avoid putting sensitive information into the tool unless allowed, and delete or close the account when it is no longer needed.
How to Approve a New Work App Without Creating Shadow IT
The right first step is process discipline: employees should not self-authorise a new app just because it looks useful or widely used. A short check with IT or security helps confirm whether the tool is already approved, whether it fits company data handling rules, and whether there is a safer sanctioned alternative.
Trusted sourcing matters because app stores, vendor sites, and browser extensions can all be abused by lookalike products or tampered downloads. The approval step should also confirm the business use case, ownership, and whether the tool introduces data sharing, integration, or retention behaviour that the company has not reviewed.
Permissions, Credentials, and Data Use Need a Careful Review
Employees should treat requested permissions as a security decision, not a convenience step. A note-taking app asking for contacts, inbox access, filesystem visibility, or broad workspace permissions may be collecting more than the job requires, and that increases both exposure and downstream misuse if the app is compromised.
If the app is approved, users should still minimise what they place into it. Strong, unique credentials reduce the blast radius if the service or account is later exposed, and they help avoid reusing a password that could unlock other business systems. If the tool supports single sign-on or enterprise login, that is usually preferable to creating another unmanaged account.
Data handling deserves equal attention. Employees should avoid uploading confidential client details, regulated data, or internal material unless the company has explicitly allowed that use and the app’s storage, sharing, and retention rules are understood.
What to Do When the App Is No Longer Needed
New tools often stay active long after the project ends, which is where unnecessary exposure grows. Employees should close the account, remove the integration, and delete local or cloud-stored content when the tool is no longer needed, especially if it was used for a temporary task or trial.
That cleanup step matters because dormant accounts and old integrations can keep access paths alive even when the app is no longer in active use. A simple offboarding habit reduces the chance that an overlooked login, token, or shared workspace becomes a future entry point.
Risk and Threat Considerations
Unapproved apps create a classic shadow IT problem: security, legal, privacy, and records rules can be bypassed before anyone notices. The biggest exposure is not the app itself, but the combination of unknown permissions, unreviewed data storage, and accounts that remain active after the work need has ended.
Failure mechanism: Users grant broad access, paste sensitive content into an unvetted service, or leave an account and its connected permissions in place after the project ends. If the app or its provider is compromised, that stored data and those access paths can be abused without needing to break into the company directly.
Impact: The result can be data leakage, account takeover through reused credentials, unauthorised sharing, or loss of control over business information that was never meant to sit in a third-party tool.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-20 — Use of External Information Systems | Covers use of unsanctioned or external apps for work. |
| IA-5 — Authenticator Management | Supports strong, unique credentials and account cleanup for new work apps. | |
| Recommendation — Restrict external app use to approved conditions and review access before sharing work data. Require unique authenticators and revoke them when the app is no longer needed. | ||
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | New apps affect asset inventory and ownership of data-handling tools. |
| A.5.15 — Access control | Covers limiting app access and reviewing requested permissions before approval. | |
| Recommendation — Record approved work apps in the asset inventory before employees use them. Apply access control rules to limit app permissions to the minimum required. | ||
| CIS Controls v8 | CIS-5 — Account Management | Addresses approval, account creation, and removal when the app is no longer needed. |
| Recommendation — Manage app accounts centrally and remove them promptly when business need ends. | ||
Practitioner Guidance
What to verify: Before a new app is used for work, verify the approval path, the data class it will touch, and whether the login method is company-managed. If the app needs broad permissions or access to production data, treat that as a higher-risk request than a simple productivity tool.
Common mistake: The usual failure mode is approving the tool but not governing the account lifecycle. If the app is temporary, make offboarding part of the same decision, including account closure, access removal, and deletion of stored content where policy allows.
Practitioner takeaway: The safest pattern is to approve the use case, not just the app name, then keep the permission set, data exposure, and account lifetime as small as possible.
Related resources from NHI Mgmt Group
- How should employees protect work and personal accounts when they use the same devices and networks?
- How should organisations evaluate mobile app privacy risk before allowing employees to use social media apps on work devices?
- How should security teams use IAST and RASP in NHI governance?
- What breaks when employees use browser sync for work credentials?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org