The legal team is shipping software now. Who reviews its permissions?
Blog post from WorkOS
AI-assisted development tools are enabling non-engineers to rapidly create departmental applications that can access sensitive contracts, customer data, and internal systems, often outside traditional software review, deployment, and ownership processes. Using examples from GitHub legal staff who built contract and compliance workflows with Copilot CLI, the discussion argues that governance should focus less on reviewing generated code and more on controlling credentials, data access, tool ownership, and auditability before tools are deployed. It recommends user-scoped credentials for personal tools, narrowly permissioned organization credentials for shared workflows, and short-lived machine-to-machine tokens for unattended jobs, alongside per-tool data roles, default-deny network controls, and immutable audit records that connect each action to both an agent and a responsible human. While excessive governance could undermine the speed that makes these tools valuable, structured self-service access paths are presented as safer than unmanaged shadow IT, and deterministic permission boundaries are favored over AI-based safety reviews. Organizations are urged to identify informal internal tools, determine what credentials and data they use, and ensure accountability is clear when they act.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 2 | 276 | 77 | 47 | -83% |
| LLM | 2 | 1,189 | 251 | 109 | -83% |
| Platform Engineering | 2 | 154 | 51 | 23 | -88% |
| Secrets Management | 1 | 584 | 99 | 52 | -76% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.