Checklist
The IT security review checklist
What to bring to your security team so a plant pilot is approved in days rather than quarters.
4 min read
Bring these before the first meeting
Deployment options (cloud, private cloud, self-hosted). Data flow diagram showing what leaves the network and what does not. Authentication method and SSO support. Role and permission model. Audit logging scope. Subprocessor list. Data retention and deletion behaviour.
Answer the three questions that actually block pilots
Can the tool write to our systems? (Read-only by default; write-back is explicit, scoped and logged.) Does plant data leave our network? (Not if you self-host.) What happens if we stop? (Connections are yours, exports are yours, nothing is locked in.)
Scope the pilot so it is approvable
One source, read-only, one team, no PII, a defined end date. A pilot that needs an enterprise architecture decision is not a pilot.
Read next
Explainer
The real decision cadence of a plant — daily, weekly, monthly, quarterly
Most plant decisions are not made in a system. They are made in a meeting, from a spreadsheet someone rebuilt the night before.
9 min read
Explainer
Spreadsheet debt: the hidden operating system of manufacturing
The models that actually run scheduling, costing and planning are undocumented, unversioned and owned by one person.
8 min read
Start here
Ask one question. Get one answer. Today.
Start on the free tier with a single connection, or bring a real question to a working session and we will build the first answer with you.
Free tier · No credit card · Cloud or self-hosted