Security
13 vendor-neutral ToolsPilot guides in this topic.
SaaS Backup Restore Drill: RTO, RPO, and Evidence Checklist for 2026
A vendor-neutral restore drill for proving that SaaS exports, backups, permissions, attachments, and business workflows can actually be recovered within an agreed time.
GitHub Actions pull_request_target Security Checklist for Fork PRs (2026)
Review fork pull requests without running untrusted code in a privileged GitHub Actions context: event choice, checkout boundaries, permissions, secrets, approval, artifacts, and rollback.
npm Install Script Approval Checklist: ignore-scripts vs allowScripts in CI (2026)
Decide when npm lifecycle scripts may run, review allowScripts safely, use ignore-scripts in restricted CI, and preserve reproducible builds and rollback.
npm Trusted Publishing Migration Checklist: Replace Long-Lived Tokens with OIDC in 2026
Migrate an npm release workflow from persistent registry tokens to trusted publishing with provider-bound OIDC, provenance, rollback, and maintainer controls.
AI Coding Agent Repository Safety Checklist for Small Teams in 2026
A practical 2026 checklist for sandboxing coding agents, limiting repository and network access, protecting secrets, reviewing changes, and keeping rollback simple.
SCIM Deprovisioning Exception Review Checklist 2026
A 2026 SaaS administration checklist for reviewing SCIM deprovisioning exceptions, stale groups, app owners, and safe rollback paths before access lingers.
Workspace Admin Offboarding App Permission Checklist 2026
A security-first 2026 workflow for removing a departing worker's SaaS access, delegated permissions, sessions, keys, and app ownership without losing business continuity.
Shared Inbox Phishing Triage Checklist 2026
A team-safe 2026 checklist for triaging phishing in shared inboxes without exposing credentials, breaking evidence, or losing ownership of follow-up.
Passkey Recovery for Shared Team Accounts Checklist 2026
A practical 2026 checklist for using passkeys on shared team accounts without losing recovery, auditability, offboarding control, or phishing-resistant protection.
AI File-Sharing Permission Audit: 2026 Checklist for Docs, Drives, Links, and Team Bots
Audit shared files, public links, AI connectors, bot access, retention, offboarding, and recovery evidence before private docs leak.
AI Browser Agent Permission Checklist for Small Teams in 2026
A practical control plan for browser-use AI agents: sandbox profiles, human approval points, data minimization, audit logs, payment limits, and rollout rules.
AI Connector Permission Audit 2026: Secure ChatGPT, Claude, Gemini, Copilot, and MCP Access
A practical 2026 workflow for auditing AI connectors, OAuth scopes, browser context, MCP servers, retention settings, and high-risk tool actions.
Client Browser Isolation Setup 2026: A Secure Workflow for Freelancers
Build a practical browser isolation workflow for freelancers handling client logins, admin panels, files, passkeys, and risky links in 2026.