Safeguard
Topic

Compliance

In-depth guides and analysis on compliance from the Safeguard engineering team.

100 articles

Compliance

Every SaaS Tool Nobody Approved Still Has Access

Someone signed up with a company card, connected it with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed. The integration did not. Adopting a tool costs nothing; removing one requires someone to remember it exists.

Sep 18, 20265 min read
Compliance

Your Cyber Insurance Application Can Void the Claim You Will Need It For

The application said MFA was enforced everywhere. The compromised account did not have it. The policy did not fail you. The application did, months earlier, answered quickly under a renewal deadline.

Sep 18, 20265 min read
Compliance

An Engineer's First Week Sets Their Access for Three Years

Whatever they are granted on day two, they keep, because nothing removes it and asking for less is not a thing people do. The decisions get made by whoever is unblocking them at the time.

Sep 18, 20265 min read
Compliance

Nobody Decided That Everyone Should Have Production Access

It was obviously right at eight people and nothing has forced a decision since. At some point the number who can read every customer's data stops being one you would say out loud, and nothing breaks to tell you.

Sep 18, 20265 min read
Compliance

Classify the Systems, Not the Documents

Four tiers, a training slide, and no effect on anything anyone does on a Tuesday. The failure is not carelessness: the scheme asks for a judgement and then does nothing with the answer.

Sep 18, 20265 min read
Compliance

A Customer Is Going to Penetration Test Your Product

Usually you find out afterwards, when a report with eleven findings arrives asking for remediation dates. It goes badly more often than it should, because nobody decided in advance who owns it or what happens when a finding is wrong.

Sep 18, 20266 min read
Compliance

Every Production System Has Accounts Nobody Created on Purpose

The demo tenant from the launch, the test user from a 2023 bug, the seed administrator that shipped with the first deployment. None appear on an access review, because reviews enumerate employees and these live in the product's own user table.

Sep 18, 20265 min read
Compliance

How to Actually Read a Vendor's SOC 2 Report

You skim the front, see an unqualified opinion, approve the vendor. The value is in four sections most reviewers never reach, and one of them lists the controls you are required to perform for the vendor's controls to work.

Sep 18, 20266 min read
Compliance

Your Pull Request Process Is Already Your Change Management

An auditor asks for change management evidence and the instinct is to build a change request form nobody will use. You already have the control, and it produces better evidence because it is generated by the work rather than alongside it.

Sep 18, 20266 min read
Compliance

The Contractor Offboarding Nobody Ever Did

Every offboarding process is triggered by a termination event in a directory. A contractor's engagement ending produces an invoice, not a directory change, so nothing downstream fires and the account stays live.

Sep 18, 20266 min read
Compliance

Disabling the SSO Account Did Not Remove Their Access

SSO centralises authentication. It does not end existing sessions, revoke tokens issued through other paths, or touch the tools that were never federated. Deprovisioning is a credential problem, and credentials outlive identities by design.

Sep 17, 20266 min read
Compliance

Your Quarterly Access Review Revoked Nothing

Managers approve everything because the task as presented cannot be done well: uninterpretable entitlement names, no usage data, and a default that costs nothing while the alternative breaks a colleague's Friday.

Sep 17, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.