New
Governance Workflows Reference

How ThreatLynx structures SaaS governance, review workflows, and evidence capture

ThreatLynx helps organisations structure SaaS governance workflows, evidence collection, and application review processes across connected cloud environments. This reference explains the governance lifecycle, policy-driven review, audit logging, and compliance evidence capabilities.

Lifecycle managementAudit trailEvidence exportPolicy-drivenOwner accountability

Governance workflows are configurable operational processes designed to support review and decision-making activities. ThreatLynx provides the workflow structure — governance outcomes depend on consistent human review and organisational process discipline.

Governance workflow overview

ThreatLynx provides a structured governance layer over SaaS application discovery — turning an inventory of connected applications into a managed, auditable review and decision process.

Governance lifecycle management

Every discovered application moves through a defined lifecycle: discovered, under review, approved, restricted, blocked, or exception granted. Each transition is logged with actor, timestamp, and recorded rationale.

Ownership and accountability

Applications can be assigned a business owner and a dedicated reviewer. Ownership is tracked in the governance record and reflected in the risk score — unowned applications carry an elevated ungoverned weighting.

Review cadence and scheduling

Review dates can be set per application. Applications with overdue scheduled reviews receive a stale-governance signal in the risk score, surfacing accountability gaps before the next audit cycle.

Evidence capture and export

Point-in-time evidence snapshots capture the inventory state, governance decisions, scope records, and audit log at any given date. Exports are suitable for internal audits, access reviews, and regulator evidence requests.

Immutable audit trail

Every governance action — status change, owner assignment, reviewer update, rationale capture — is written to an append-only audit log. Entries include actor, timestamp, prior state, and new state.

Policy-driven workflow support

Governance policies define conditions that trigger review requirements or alert workflows. Policies assist human review processes — they are not autonomous enforcement engines.

Governance lifecycle states

Every application in the ThreatLynx inventory carries a governance status. Status transitions are actor-attributed, timestamped, and permanently recorded in the audit trail.

Discovered

Under Review

Decision

Approved · Restricted · Blocked · Exception

Each transition is logged · All states support re-review · Blocked applications retain audit record

Discovered

Entry state

Application is present in the inventory following workspace sync. No governance action has been taken. Default entry state for all newly discovered applications.

Next states:Under Review

Under Review

Active review

Review has been initiated. An owner or reviewer has been assigned and assessment is in progress. Applications should not remain in this state beyond the governance review cycle.

Next states:ApprovedRestrictedBlocked

Approved

Score reduced

Application has been reviewed. Its use case and scope access have been confirmed as appropriate. Approval rationale and reviewer are recorded. Risk score is reduced.

Next states:Under ReviewRestrictedBlocked

Restricted

Conditional

Application is permitted under defined conditions. The restriction basis and approval authority are documented. Restriction does not clear risk — underlying score remains active.

Next states:ApprovedBlocked

Exception Granted

Time-limited

A formal exception has been recorded with rationale, approval authority, and a defined expiry date. Exceptions are temporary governance postures requiring scheduled re-review.

Next states:ApprovedRestrictedBlocked

Blocked

Flagged — remediate

Block decision has been recorded with documented rationale. Governance record remains for audit evidence. Token revocation must be executed separately by a workspace administrator.

Next states:Exception Granted

Ownership and accountability

Effective governance requires clear accountability. ThreatLynx supports owner and reviewer assignment per application — with governance signals that surface unowned or stale applications before they become audit gaps.

Business owner

The individual accountable for the application's use within the organisation. Owner assignment moves the application out of the unowned governance queue and reduces the ungoverned score modifier.

Role: Accountable party

Designated reviewer

The security or IT team member responsible for conducting the governance review. The reviewer is attributed in the audit trail against each governance decision they record.

Role: Review authority

Review cadence

Review dates can be set per application. Applications with overdue review dates receive a stale-governance score modifier, surfacing accountability gaps within the active risk inventory.

Signal: Overdue flag
Example application governance record

Business owner

james.park@corp.com.au

Marketing — Head of Digital

Assigned reviewer

sarah.chen@corp.com.au

Security Operations

Review cadence

Every 90 days

Next due: 2026-08-22

Governance status

Restricted

Set 2026-05-24 · 11:02 AEST

Last reviewed

2026-05-24

sarah.chen@corp.com.au

Risk score

62 / High

Reduced from 82 on restriction

Policy-driven governance workflows

Governance policies define conditions that identify applications requiring priority review. Policies surface relevant applications automatically — human review and decision-making remain central to the governance process.

AI tool with document access

High priority

Condition

Application classified as AI vendor AND scope includes Drive or Files access

Triggered action

Flag for governance review — assign to security team

Governance rationale

AI tools with file access may process sensitive business content. Governance review confirms whether access is justified and scoped correctly.

Admin scope detection

Critical priority

Condition

OAuth grant includes admin.directory.*, Directory.ReadWrite.All, or equivalent

Triggered action

Immediate escalation — assign to IT/security lead

Governance rationale

Directory admin scopes are rarely required by legitimate SaaS integrations. Unexplained admin-level access represents a high-priority governance gap.

Persistent access without owner

High priority

Condition

Application holds offline_access AND no business owner is assigned

Triggered action

Add to ungoverned queue — require owner assignment within review cycle

Governance rationale

Persistent access without documented ownership represents an unmanaged ongoing exposure. Owner assignment is the first governance step.

New application — broad scopes

High priority

Condition

Application discovered in current sync AND scopes span mail + files + directory

Triggered action

Auto-assign to Under Review — notify security team

Governance rationale

Newly discovered applications with broad multi-category access are the highest-priority onboarding governance items.

Vendor jurisdiction flag

Medium priority

Condition

Vendor country is outside Australia AND application accesses mail or personal data scopes

Triggered action

Flag for data sovereignty review — Privacy Act consideration

Governance rationale

Applications processing Australian personal information via a non-Australian vendor may raise Privacy Act and data sovereignty considerations.

Overdue review date

Medium priority

Condition

Application has a scheduled review date that has passed without a new governance decision

Triggered action

Escalate to assigned reviewer — update governance status

Governance rationale

Stale reviews indicate governance posture has not been maintained. Applications with overdue reviews receive an elevated stale-governance score modifier.

Policy conditions shown are illustrative examples of governance workflow configurations. Actual policy configuration requires administrator setup and should be aligned to your organisation's risk appetite, governance policies, and specific regulatory obligations.

Audit trail and evidence capture

Every governance action produces an immutable audit log entry. Evidence exports capture a point-in-time view of the inventory, decisions, and rationale — suitable for access reviews, internal audits, and regulator evidence requests.

Audit log — AI Document Assistant2026-05-24 · AEST
StatusGovernance status changed

Ungoverned → Under Review

09:14 AEST·sarah.chen@corp.com.au·AI Document Assistant · Risk score 82
OwnerBusiness owner assigned

Owner: james.park@corp.com.au (Marketing)

09:15 AEST·sarah.chen@corp.com.au·Review cadence: 90 days
NoteRationale documented

Tool used for internal document drafting. Gmail access reviewed — send/delete not required.

10:47 AEST·james.park@corp.com.au·Scope reduction request submitted to vendor
StatusGovernance status changed

Under Review → Restricted

11:02 AEST·james.park@corp.com.au·Restriction: readonly scopes only pending vendor scope reduction
SystemEvidence snapshot created

Point-in-time governance export generated

11:03 AEST·system·Export ID: GEX-2026-0482 · Format: CSV + PDF

Point-in-time snapshots

Generate an evidence snapshot at any point in time. Snapshots capture the full application inventory, governance decisions, scope records, risk scores, and audit trail as at the export date.

Actor attribution

Every entry in the audit trail records the authenticated user who performed the action, the timestamp in ISO 8601 format, and the prior and new state. Suitable for regulator evidence submission.

AI and agent governance workflows

Non-human identities, AI tools, and autonomous integrations require dedicated governance workflows. ThreatLynx surfaces these identities from OAuth metadata and provides structured review processes.

AI-powered SaaS tools

Applications classified as AI-capable via metadata pattern analysis. Governance workflows require documented use-case justification and periodic re-review, particularly where mail or file access scopes are held.

Copilots and inline assistants

Browser or application-embedded AI assistants identified via vendor patterns. Governance review should confirm whether real-time workspace data access is justified and whether scope can be narrowed.

Workflow automation platforms

Applications operating as automation orchestrators with broad, persistent access across mail, calendar, and files. Governance review should confirm each automated workflow is documented and owned.

MCP-connected systems

Model Context Protocol integrations identified via metadata heuristics. Confidence-based classification — governance review should verify whether MCP-connected access is active and intentional.

Service principals (M365)

Non-human Entra ID identities with application-level permissions. Governance review should confirm each service principal has a documented owner, defined business purpose, and active monitoring.

Autonomous integrations

Applications holding persistent tokens without a clearly identified human owner. Governance review should confirm whether access is still required — or whether credentials have been orphaned.

Agent and AI classification is metadata-driven and confidence-based — not endpoint monitoring, content inspection, or behavioural analysis. Governance workflows for AI identities follow the same lifecycle as standard applications. Human review of classification confidence is recommended before formal governance decisions.

Compliance framework alignment

Governance workflow records support evidence requirements across Australian regulatory frameworks. ThreatLynx provides workflow tooling and audit records — not compliance certification or legal determination.

ASD Essential Eight — Application Control

Governance evidence

ML2 / ML3 · User Application Hardening

ThreatLynx governance workflows produce documented records of application review decisions — supporting Application Control maturity evidence requirements. Governance logs can be used to demonstrate ongoing oversight of authorised and unauthorised OAuth-connected applications.

APRA CPS 234 — Information Security

Readiness support

Information Assets · Third-party Risk

Governance workflows provide structured documentation of third-party SaaS application decisions — relevant to information asset registers and third-party information security capability assessments. Audit logs with timestamps, actors, and rationale support CPS 234 evidence requirements.

Privacy Act 1988 — APP 11

Process visibility

Security of Personal Information

Governance records provide a documented trail of review decisions for applications with access to personal information. This supports demonstrating reasonable steps to protect personal information as required by APP 11.

Regulatory references are informational. ThreatLynx does not provide legal advice, compliance certification, or guaranteed compliance outcomes. Governance workflow records are inputs to compliance processes, not compliance outcomes. Consult qualified legal, compliance, and security advisors for specific regulatory obligations.

Example governance investigation

An end-to-end walkthrough of a governance workflow — from initial discovery through to evidence capture. All details are illustrative and for reference only.

Hypothetical scenario

AI Document Assistant

Gmail full access · Drive full access · offline_access · 54 users · No governance record · Score 82 / Critical

01
DiscoveryApplication appears in inventoryDiscovered

Workspace sync identifies "AI Document Assistant" with Gmail full access, Drive full access, and offline_access. 54 users authorised. No governance record exists.

02
Policy triggerReview condition metPolicy matched

Application matches policy: "AI vendor classification AND document access scope". Governance workflow triggered. Assigned to security team queue.

03
InitiationReview initiated — owner assignedUnder Review

Security team member initiates review. Business owner james.park@corp.com.au assigned. Status moves to Under Review. 14-day review target set.

04
AssessmentScope review and use-case confirmationScope reviewed

Owner confirms legitimate use for document drafting. Gmail send/delete access identified as over-scoped — readonly sufficient. Scope reduction request submitted to vendor.

05
DecisionRestriction applied — rationale documentedRestricted

Governance status set to Restricted. Rationale: "Approved for readonly document access pending vendor scope reduction. Mail write/delete not justified." 90-day review date set.

06
EvidenceEvidence snapshot exportedEvidence captured

Point-in-time governance export generated. Includes: application metadata, scope record, governance decision, audit trail, and reviewer attribution. Archived for access review evidence.

This scenario is illustrative only. Actual governance workflows, timings, and outcomes depend on your organisation's process configuration and team review discipline.

Workflow automation boundaries

ThreatLynx supports governance workflows. It does not replace human governance judgement or automate legal and compliance decisions.

01

Governance actions require human authorisation

Status transitions, owner assignments, and rationale capture are performed by authorised users — not autonomous agents. ThreatLynx records governance decisions; it does not make them.

02

Token revocation requires workspace admin action

ThreatLynx records a block or restriction decision but does not directly revoke OAuth tokens. Enforcement must be executed by an administrator in the Google Workspace Admin Console or Microsoft Entra ID.

03

Policy workflows are advisory by default

Governance policies surface applications that meet trigger conditions — they do not automatically apply governance states. Human review and decision-making remain part of the governance process.

04

Governance effectiveness depends on user engagement

The quality of governance outcomes depends on the completeness and timeliness of human review activity. ThreatLynx provides the workflow structure — governance maturity is built by using it consistently.

Confidence and limitations

Governance workflows are only as effective as the processes and metadata that support them. These constraints apply to all ThreatLynx deployments.

01

Metadata-driven discovery

Governance workflows operate on applications discovered through OAuth metadata APIs. Applications not visible via the identity provider admin APIs may not appear in the governance inventory.

02

Microsoft 365 discovery depends on Graph metadata

M365 discovery, service principal visibility, and permission data completeness depend on the metadata returned by Microsoft Graph. Governance records for M365 applications reflect what was available at the time of sync.

03

Governance does not equal compliance

Documented governance workflows and audit logs are inputs to compliance processes — not compliance outcomes. Whether specific governance records meet a regulatory requirement depends on the applicable standard and your organisation's compliance programme.

04

Review quality depends on available metadata

Governance decisions are only as good as the information available. Where vendor metadata is incomplete or OAuth scope strings are ambiguous, the review process should include additional verification steps.

05

Workflow configurations require organisational setup

Policy conditions, review cadences, and escalation paths require configuration by an administrator. Default configurations are provided as starting points — organisations should align them with their own governance policies and risk appetite.

06

Governance maturity is a process outcome

ThreatLynx supports governance workflows. The maturity of an organisation's governance posture reflects consistent application of those workflows over time — it is not a technical feature that can be activated.

About ThreatLynx governance workflows

ThreatLynx provides governance tooling designed to support operational review and audit workflows. Organisations should validate governance decisions against their own policies, legal obligations, and risk frameworks. Governance records produced by ThreatLynx are inputs to compliance processes — not standalone compliance outcomes. Qualified security, legal, and compliance advisors should be consulted for specific regulatory obligations.

See governance workflows on your inventory

Request a guided walkthrough to explore ThreatLynx governance lifecycle management, policy-driven review, and evidence capture across your Google Workspace or Microsoft 365 environment.