Overview
All software used for company work must be on the approved list below or explicitly approved by IT. Using unapproved tools — especially for storing company or client data — creates security and compliance risks. If you need a tool that isn’t on the list, see Requesting a new tool below.Approved tools by category
Communication
| Tool | Purpose | Access | Notes |
|---|---|---|---|
| Slack | Team messaging, async collaboration | Provisioned on day one by IT | Primary internal comms platform |
| Gmail / Google Workspace | Email, calendar, video | Provisioned on day one by IT | Use company account only — not personal Gmail |
| Google Meet | Video meetings | Included with Google Workspace | Default for internal meetings |
| Zoom | Video meetings (external) | Provisioned by IT on request | Preferred for client calls |
- Download Slack at slack.com/downloads
- Sign in with your company email using SSO
- Join your team channels (IT will add you to defaults; join others via the channel browser)
- Review the Communication guide for Slack norms
Project management & documentation
| Tool | Purpose | Access | Notes |
|---|---|---|---|
| [Project management tool — e.g., Linear / Asana / Jira] | Task and project tracking | Provisioned by IT | Primary project tracker |
| [Documentation tool — e.g., Notion / Confluence] | Internal docs and wikis | Provisioned by IT | Supplementary to these docs |
| Google Drive | File storage, collaborative docs | Included with Google Workspace | Use for most documents |
| [This site] | Policies, SOPs, internal wiki | Public (internal) | You’re looking at it |
- Store all company documents in Google Drive or the designated document management system
- Do not store company documents in personal cloud storage (personal Dropbox, iCloud, etc.)
- Follow the folder structure defined by your team lead
Engineering & development
| Tool | Purpose | Access | Notes |
|---|---|---|---|
| GitHub | Source code management | Request from IT + engineering lead | SSO login required |
| [CI/CD tool — e.g., GitHub Actions / CircleCI] | Automated testing and deployment | Provisioned with GitHub | |
| [Cloud platform — e.g., AWS / GCP / Azure] | Infrastructure and hosting | Request from IT; role-based access | Least-privilege access only |
| [Monitoring — e.g., Datadog / Grafana] | System monitoring and alerting | Request from IT | |
| VS Code / JetBrains | Code editors | Self-install from approved source | Both are approved |
| Postman | API development and testing | Self-install |
Finance & HR
| Tool | Purpose | Access | Notes |
|---|---|---|---|
| [Payroll / HR system — e.g., Rippling / Gusto / BambooHR] | Payroll, benefits, PTO | Provisioned on day one by HR | Primary HR system |
| [Expense tool — e.g., Expensify / Ramp / Brex] | Expense reporting and reimbursement | Provisioned by Finance | See Expense Policy |
| [Accounting — e.g., QuickBooks / Xero] | Accounting and invoicing | Finance team only |
Security
| Tool | Purpose | Access | Notes |
|---|---|---|---|
| [Password manager — e.g., 1Password / Bitwarden] | Password management | Provisioned by IT | Required — see Security Policy |
| [MFA app — e.g., Duo / Google Authenticator / Authy] | Multi-factor authentication | Self-install | Required on all accounts |
| [VPN — e.g., Tailscale / Cisco AnyConnect] | Secure remote access | Provisioned by IT | Required when on public Wi-Fi |
| [EDR — e.g., CrowdStrike / SentinelOne] | Endpoint security | Pre-installed on company devices | Do not disable |
| [MDM — e.g., Jamf / Intune] | Device management | Pre-installed on company devices | Do not remove |
Design
| Tool | Purpose | Access | Notes |
|---|---|---|---|
| Figma | UI/UX design and prototyping | Request from IT | Approved for design team |
| [Other design tool] | [Purpose] | Request from IT |
Customer / client tools
| Tool | Purpose | Access | Notes |
|---|---|---|---|
| [CRM — e.g., HubSpot / Salesforce] | Customer relationship management | Provisioned by IT | Role-based access |
| [Support tool — e.g., Intercom / Zendesk] | Customer support | Provisioned by IT | Customer-facing teams only |
Requesting a new tool
Before requesting a new tool, check whether an existing approved tool can meet your need. If you still need a new tool:Submit a request
File a request via [IT helpdesk / request form — link to be added]. Include:
- Tool name and URL
- What you need it for
- How many people will use it
- Whether it will store company or client data
- Cost (if any)
IT security review
IT will review the tool for security posture, data handling practices, and compliance requirements. Tools that store company or client data go through a more thorough review.Typical timeline: 3–5 business days for standard tools; longer for tools with significant data access.
Legal / procurement review
If there’s a contract or significant cost, Legal and Finance will review. For tools over $[X]/month, manager approval is also required.
Removing access to a tool
When an employee leaves or changes roles, their tool access must be revoked. This is handled as part of the Offboarding SOP. If you notice that a former employee or someone who changed roles still has access they shouldn’t, report it to IT immediately.Device setup
New devices are provisioned by IT before your first day (or on day one for office-based hires). Your device will come with required security tools (MDM, EDR, password manager) pre-installed. Initial setup checklist:- Sign in with your company SSO credentials
- Verify MDM enrollment (IT will confirm)
- Enable full-disk encryption (FileVault on Mac / BitLocker on Windows) — IT will guide you
- Install and set up the company password manager
- Set up MFA on all accounts
- Install any additional approved tools from the list above as needed for your role
Last updated: [Date] — owned by IT