
You found the AV tool that solves your problem. Then you asked IT to approve it, and the project quietly stalled for six weeks. Getting AV software approved by IT does not have to be a black box, but it does require showing up with answers to questions you may not have thought to ask yourself. This is a practical guide to that process, from both sides of the table.
Whether you are the event producer trying to get a tool approved, or the IT admin trying to review one quickly and properly, the same preparation shortens the process for everyone involved.
- Reviews stall on low visibility and real risk together, not because the tool itself is actually risky.
- Bring five things up front: a data flow diagram, an architecture overview, authentication answers, network requirements and a named contact.
- A well-prepared request with documentation ready typically clears review in one to two weeks.
Why AV tools get stuck in review
AV and presentation software often falls into an odd gap in procurement. It is not obviously "core business software" like a CRM, so it does not always have a clear owner pushing it through. But it touches devices, networks and sometimes sensitive content, so it cannot be waved through as harmless either. That combination, low visibility and real risk, is exactly what stalls a request.
The fix is not to argue the tool is low-risk and skip the review. It is to make the review fast by bringing the answers before anyone has to ask, which is a smaller ask than it sounds once you know what a reviewer is actually looking for.
What a security review actually checks
Most IT and security reviews of a new tool cover roughly the same ground, whatever the specific checklist template looks like:
| Area | What they are checking | Where to find the answer |
|---|---|---|
| Data flow | What data moves where, and what gets stored | Vendor's data flow diagram |
| Encryption | Whether connections are encrypted in transit and at rest | Solution architecture documentation |
| Authentication | How users sign in, and whether SSO is supported | Identity and access section of the docs |
| Network requirements | What ports and hosts the app needs, inbound or outbound | Networking documentation |
| Client integrity | Whether the installed app itself is signed and verified | Vendor's security page |
| Data residency and subprocessors | Where data is hosted and who else touches it | Vendor's contact or legal team, often under NDA |
If you can hand your IT team a link that answers each row before they ask, you have just turned a multi-week email chain into a single read-through.

What to bring to the conversation, as the requester
A written data flow diagram
A written data flow diagram , not a sales deck. Cliqer's is at docs/security/data-flows, built specifically for this purpose.
A solution architecture overview
A solution architecture overview covering deployment model, identity and tenancy, such as the solution blueprint.
Answers on authentication
Does the tool support SSO? Cliqer's does, on the Enterprise plan, alongside SCIM provisioning and team roles.
Network requirements in plain terms
Confirm whether inbound rules are needed (they should not be) and which outbound connections the tool makes; see the Security & Networking documentation.
A named contact for follow-up questions
Contact us directly if your reviewer has a question the docs do not answer, including anything that needs an NDA.
Bringing all five up front, rather than one at a time as IT asks, is the single biggest thing you can do to speed up approval.
What IT reviewers should actually be looking for
From the other side of the table, a fast and rigorous review focuses on a small number of high-value questions rather than a hundred low-value ones:
- Does the tool upload sensitive content anywhere, or does it stay on the presenter's own device? This is usually the single most consequential architectural question.
- Is every connection encrypted, with no unencrypted fallback mode?
- Can access be centrally controlled and revoked, ideally through your existing identity provider?
- Does the client software update through a signed, verified channel, or something less controlled?
- Are the vendor's answers backed by documentation, or only by a sales conversation?
A tool that answers all five well, in writing, deserves a fast yes. One that cannot answer them at all deserves a slow no, regardless of how good the demo looked, and no amount of enthusiasm from the requesting team should shortcut that judgement.

A realistic timeline
| Stage | Typical duration | What speeds it up |
|---|---|---|
| Initial request | 1 day | Submitting the data flow diagram with the request, not after |
| Security review | 3 to 10 business days | A vendor with documentation ready, not a sales call needed to get answers |
| Procurement and contracts | 1 to 3 weeks | Enterprise plans with clear seat and pricing terms already published |
| Rollout | 1 to 2 days | Self-service SSO and team role setup, no vendor onboarding call required |
Cliqer's Enterprise features are all self-service from Dashboard → Team → Security once approved, which is worth flagging early: rollout does not require another round of vendor calls after the review clears.
Related reading
If your review is turning up specific questions, these go deeper on the pieces that usually come up: our full security checklist for presentation software, is WebRTC secure for the connection technology itself, and single sign-on for AV and event teams if identity is the sticking point. If networking is the sticking point instead, why corporate firewalls block presentation tools covers exactly what a network reviewer usually asks. If the tool is destined for sensitive material specifically, presenting confidential content covers that case directly.
FAQ
It varies widely by organisation, but a well-prepared request with documentation ready typically clears review in one to two weeks. Missing documentation is the most common cause of multi-month delays.
A data flow diagram. It answers the question every reviewer asks first, what happens to our data, faster than any other document.
Not usually. Formal review tends to apply once a tool touches company devices, networks or an identity provider at scale, which is more common on Enterprise deployments than a single presenter's Pro account.
Ask the vendor directly. A vendor confident in its own security posture should be able to answer a specific follow-up quickly, including under NDA where the question involves subprocessor detail.
Get started
If you are preparing a request right now, start with the security overview and the solution blueprint, then contact us with any question your reviewer still has. For teams ready to move forward, Enterprise covers SSO, SCIM and custom roles as one package.
How to Advance Slides for a Speaker in Another Country
Advance slides for a speaker in another country: setup, what latency to expect and the backup plan if the link drops.
Integrating DSAN Limitimer Speaker Timers with Your Slides
Connect a DSAN Limitimer to your slides: two-way sync, master or slave mode, and which settings matter on show day.
Run your next show with Cliqer
Keep reading
More security & it for your next show


Passkeys Explained: Passwordless Sign-In for Busy Teams

TURN Servers Explained: How Video Gets Through Restrictive Networks
Get the next guide before your next show
Practical guides for presenters, AV crews and event teams, plus the Cliqer releases that matter. No spam, one click to leave.
