Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

The legal team is shipping software now. Who reviews its permissions?

Blog post from WorkOS

Post Details
Company
Date Published
Author
Zack Proser
Word Count
2,090
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

AI-assisted development tools are enabling non-engineers to rapidly create departmental applications that can access sensitive contracts, customer data, and internal systems, often outside traditional software review, deployment, and ownership processes. Using examples from GitHub legal staff who built contract and compliance workflows with Copilot CLI, the discussion argues that governance should focus less on reviewing generated code and more on controlling credentials, data access, tool ownership, and auditability before tools are deployed. It recommends user-scoped credentials for personal tools, narrowly permissioned organization credentials for shared workflows, and short-lived machine-to-machine tokens for unattended jobs, alongside per-tool data roles, default-deny network controls, and immutable audit records that connect each action to both an agent and a responsible human. While excessive governance could undermine the speed that makes these tools valuable, structured self-service access paths are presented as safer than unmanaged shadow IT, and deterministic permission boundaries are favored over AI-based safety reviews. Organizations are urged to identify informal internal tools, determine what credentials and data they use, and ensure accountability is clear when they act.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 2 276 77 47 -83%
LLM 2 1,189 251 109 -83%
Platform Engineering 2 154 51 23 -88%
Secrets Management 1 584 99 52 -76%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.