Skip to content

[M0-D05 follow-up] Record the authoritative application-list source and first applications #352

Description

@smiggleworth

Note

Follow-up discovery issue created 2026-09-22 when M0-D05 #62 closed. It gathers organization facts; it does not block R1-10 delivery, which uses the decided record shape.

Decision needed

Name the first client's authoritative application-list source and record its first application list.

Questions to answer

  • Name the authoritative source for the application list (IdP app catalog, spreadsheet, or SaaS-spend tool) and any corroborating sources.
  • Record the first application list with system owner and access owner for each.
  • Record real alias and duplicate examples to confirm the decided rules.

Constraint

No import or connector is built from this. Data import and integrations are deferred by product direction on 2026-09-22.

Involve

Compliance lead, system owners.

Done when

  • The source, the list, and the owners are recorded with owner and date, or recorded as unknown.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:applicationsApplication inventory, reviewed systems, and access scopepriority:P1Important after the critical path is usabletype:discoveryProduct or domain decision required before implementation

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions