Getting AV Software Approved by IT: A Practical Guide

What an IT security review of AV software actually checks, and how to prepare so your tool gets approved first time.

Cliqer Team

23 September 2026 · 6 min read

An IT manager and an event producer reviewing a procurement form together at a desk

You found the AV tool that solves your problem. Then you asked IT to approve it, and the project quietly stalled for six weeks. Getting AV software approved by IT does not have to be a black box, but it does require showing up with answers to questions you may not have thought to ask yourself. This is a practical guide to that process, from both sides of the table.

Whether you are the event producer trying to get a tool approved, or the IT admin trying to review one quickly and properly, the same preparation shortens the process for everyone involved.

Key takeaways
  • Reviews stall on low visibility and real risk together, not because the tool itself is actually risky.
  • Bring five things up front: a data flow diagram, an architecture overview, authentication answers, network requirements and a named contact.
  • A well-prepared request with documentation ready typically clears review in one to two weeks.

Why AV tools get stuck in review

AV and presentation software often falls into an odd gap in procurement. It is not obviously "core business software" like a CRM, so it does not always have a clear owner pushing it through. But it touches devices, networks and sometimes sensitive content, so it cannot be waved through as harmless either. That combination, low visibility and real risk, is exactly what stalls a request.

The fix is not to argue the tool is low-risk and skip the review. It is to make the review fast by bringing the answers before anyone has to ask, which is a smaller ask than it sounds once you know what a reviewer is actually looking for.

Request the review at least two to three weeks before you need the tool live, not the week of the event. Security reviews compress badly under deadline pressure, for everyone.

What a security review actually checks

Most IT and security reviews of a new tool cover roughly the same ground, whatever the specific checklist template looks like:

AreaWhat they are checkingWhere to find the answer
Data flowWhat data moves where, and what gets storedVendor's data flow diagram
EncryptionWhether connections are encrypted in transit and at restSolution architecture documentation
AuthenticationHow users sign in, and whether SSO is supportedIdentity and access section of the docs
Network requirementsWhat ports and hosts the app needs, inbound or outboundNetworking documentation
Client integrityWhether the installed app itself is signed and verifiedVendor's security page
Data residency and subprocessorsWhere data is hosted and who else touches itVendor's contact or legal team, often under NDA

If you can hand your IT team a link that answers each row before they ask, you have just turned a multi-week email chain into a single read-through.

What to bring to the conversation, as the requester

A written data flow diagram

A written data flow diagram , not a sales deck. Cliqer's is at docs/security/data-flows, built specifically for this purpose.

A solution architecture overview

A solution architecture overview covering deployment model, identity and tenancy, such as the solution blueprint.

Answers on authentication

Does the tool support SSO? Cliqer's does, on the Enterprise plan, alongside SCIM provisioning and team roles.

Network requirements in plain terms

Confirm whether inbound rules are needed (they should not be) and which outbound connections the tool makes; see the Security & Networking documentation.

A named contact for follow-up questions

Contact us directly if your reviewer has a question the docs do not answer, including anything that needs an NDA.

Bringing all five up front, rather than one at a time as IT asks, is the single biggest thing you can do to speed up approval.

What IT reviewers should actually be looking for

From the other side of the table, a fast and rigorous review focuses on a small number of high-value questions rather than a hundred low-value ones:

  • Does the tool upload sensitive content anywhere, or does it stay on the presenter's own device? This is usually the single most consequential architectural question.
  • Is every connection encrypted, with no unencrypted fallback mode?
  • Can access be centrally controlled and revoked, ideally through your existing identity provider?
  • Does the client software update through a signed, verified channel, or something less controlled?
  • Are the vendor's answers backed by documentation, or only by a sales conversation?

A tool that answers all five well, in writing, deserves a fast yes. One that cannot answer them at all deserves a slow no, regardless of how good the demo looked, and no amount of enthusiasm from the requesting team should shortcut that judgement.

A realistic timeline

StageTypical durationWhat speeds it up
Initial request1 daySubmitting the data flow diagram with the request, not after
Security review3 to 10 business daysA vendor with documentation ready, not a sales call needed to get answers
Procurement and contracts1 to 3 weeksEnterprise plans with clear seat and pricing terms already published
Rollout1 to 2 daysSelf-service SSO and team role setup, no vendor onboarding call required

Cliqer's Enterprise features are all self-service from Dashboard → Team → Security once approved, which is worth flagging early: rollout does not require another round of vendor calls after the review clears.

If your review is turning up specific questions, these go deeper on the pieces that usually come up: our full security checklist for presentation software, is WebRTC secure for the connection technology itself, and single sign-on for AV and event teams if identity is the sticking point. If networking is the sticking point instead, why corporate firewalls block presentation tools covers exactly what a network reviewer usually asks. If the tool is destined for sensitive material specifically, presenting confidential content covers that case directly.

Presentation software security checklist

The full checklist a security reviewer works through, line by line.

Is WebRTC secure?

The connection technology itself, explained for a non-specialist reviewer.

Data flow diagram

The data flow diagram to hand over before anyone has to ask.

Single sign-on for AV teams

Why SSO is usually the fastest way through the authentication question.

FAQ

Get started

If you are preparing a request right now, start with the security overview and the solution blueprint, then contact us with any question your reviewer still has. For teams ready to move forward, Enterprise covers SSO, SCIM and custom roles as one package.

IT approvalprocurementsecurity reviewAV software

Written by the Cliqer Team

We build Cliqer, the internet presentation clicker used on stages, in classrooms and in boardrooms around the world.

Run your next show with Cliqer

Any slides, any phone, anywhere. The desktop app hosts the room, presenters just open a link.

Keep reading

More security & it for your next show

A boardroom table with a laptop showing an abstract blurred chart, empty chairs waiting for a meeting to begin
Security & IT

Presenting Confidential Content: Data Protection for Board Meetings

Keep board presentations confidential: what should never leave your device and how to check where a tool sends data.
A person unlocking a laptop with a fingerprint sensor instead of typing a password
Security & IT

Passkeys Explained: Passwordless Sign-In for Busy Teams

Passkeys explained simply: how passwordless sign-in works, why it resists phishing and how to turn it on for your team.
An abstract diagram of two devices connecting through a relay server node, representing a TURN relay path
Security & IT

TURN Servers Explained: How Video Gets Through Restrictive Networks

TURN servers explained in plain language: how they relay encrypted video and control through firewalls that block you.
Newsletter

Get the next guide before your next show

Practical guides for presenters, AV crews and event teams, plus the Cliqer releases that matter. No spam, one click to leave.