Compliance
In-depth guides and analysis on compliance from the Safeguard engineering team.
100 articles
Every SaaS Tool Nobody Approved Still Has Access
Someone signed up with a company card, connected it with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed. The integration did not. Adopting a tool costs nothing; removing one requires someone to remember it exists.
Your Cyber Insurance Application Can Void the Claim You Will Need It For
The application said MFA was enforced everywhere. The compromised account did not have it. The policy did not fail you. The application did, months earlier, answered quickly under a renewal deadline.
An Engineer's First Week Sets Their Access for Three Years
Whatever they are granted on day two, they keep, because nothing removes it and asking for less is not a thing people do. The decisions get made by whoever is unblocking them at the time.
Nobody Decided That Everyone Should Have Production Access
It was obviously right at eight people and nothing has forced a decision since. At some point the number who can read every customer's data stops being one you would say out loud, and nothing breaks to tell you.
Classify the Systems, Not the Documents
Four tiers, a training slide, and no effect on anything anyone does on a Tuesday. The failure is not carelessness: the scheme asks for a judgement and then does nothing with the answer.
A Customer Is Going to Penetration Test Your Product
Usually you find out afterwards, when a report with eleven findings arrives asking for remediation dates. It goes badly more often than it should, because nobody decided in advance who owns it or what happens when a finding is wrong.
Every Production System Has Accounts Nobody Created on Purpose
The demo tenant from the launch, the test user from a 2023 bug, the seed administrator that shipped with the first deployment. None appear on an access review, because reviews enumerate employees and these live in the product's own user table.
How to Actually Read a Vendor's SOC 2 Report
You skim the front, see an unqualified opinion, approve the vendor. The value is in four sections most reviewers never reach, and one of them lists the controls you are required to perform for the vendor's controls to work.
Your Pull Request Process Is Already Your Change Management
An auditor asks for change management evidence and the instinct is to build a change request form nobody will use. You already have the control, and it produces better evidence because it is generated by the work rather than alongside it.
The Contractor Offboarding Nobody Ever Did
Every offboarding process is triggered by a termination event in a directory. A contractor's engagement ending produces an invoice, not a directory change, so nothing downstream fires and the account stays live.
Disabling the SSO Account Did Not Remove Their Access
SSO centralises authentication. It does not end existing sessions, revoke tokens issued through other paths, or touch the tools that were never federated. Deprovisioning is a credential problem, and credentials outlive identities by design.
Your Quarterly Access Review Revoked Nothing
Managers approve everything because the task as presented cannot be done well: uninterpretable entitlement names, no usage data, and a default that costs nothing while the alternative breaks a colleague's Friday.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.