Semantius Logo

SMP Discovery and Catalog

1. Overview

Discovery of sanctioned and shadow SaaS, app inventory, ownership, integrations, lifecycle staging, catalog publication, and operational signal/alerts. The discovery substrate of an SMP deployment.

2. Entity summary

Namedata_objectDescription
App Catalog Listingssmp_app_catalog_listingsPublished listings of sanctioned SaaS apps that employees can browse and request, with description, owner, request route, and approval flow.
App Lifecycle Stagessmp_app_lifecycle_stagesPortfolio-rationalization stages of a SaaS app such as evaluate, pilot, sanctioned, sunset, and retired.
SaaS Alertssmp_alertsSystem-raised alerts on the SaaS portfolio: shadow-IT signups, projected license overages, opening renewals, or vendor-risk changes.
SaaS App Integrationssmp_app_integrationsConfigured connections between the SaaS management platform and an app’s APIs for sign-on, provisioning, finance, and usage data.
SaaS App Ownerssmp_app_ownersTyped owner assignments linking a user to a SaaS app as its business, IT, finance, or security owner.
SaaS Applicationssaas_applicationsSaaS applications in the company portfolio, with vendor, category, criticality, owner, and whether each is sanctioned or shadow IT.
Shadow IT Appsshadow_it_appsSaaS apps found in use but not officially sanctioned, discovered through expense data, sign-on logs, browser, or network signals.
flowchart TD
  classDef master fill:#d4f4dd,stroke:#27ae60,color:#0b3d20;
  classDef platform_builtin fill:#e0e0e0,stroke:#424242,color:#1a1a1a;
  saas_applications["SaaS Applications"]
  shadow_it_apps["Shadow IT Apps"]
  smp_app_owners["SaaS App Owners"]
  smp_app_integrations["SaaS App Integrations"]
  smp_app_catalog_listings["App Catalog Listings"]
  smp_alerts["SaaS Alerts"]
  smp_app_lifecycle_stages["App Lifecycle Stages"]
  users["Users"]
  saas_applications -->|"owns"| smp_app_owners
  saas_applications -->|"integrates_with"| smp_app_integrations
  saas_applications -->|"publishes"| smp_app_catalog_listings
  saas_applications -->|"raised_for"| smp_alerts
  shadow_it_apps -->|"raised_for_shadow"| smp_alerts
  saas_applications -->|"tracks_stage"| smp_app_lifecycle_stages
  shadow_it_apps -->|"promotes_to"| saas_applications
  users -->|"assigned_owner"| smp_app_owners
  users -->|"configures"| smp_app_integrations
  users -->|"curates"| smp_app_catalog_listings
  users -->|"triages"| smp_alerts
  users -->|"owns"| saas_applications
  users -->|"triggered"| shadow_it_apps
  class saas_applications master;
  class shadow_it_apps master;
  class smp_app_owners master;
  class smp_app_integrations master;
  class smp_app_catalog_listings master;
  class smp_alerts master;
  class smp_app_lifecycle_stages master;
  class users platform_builtin;

3. Entities catalog

#data_objectcanonical codesingularpluralrolemastered inmastered labelnecessitypersonal_contententity_typewrite tiernotes
1smp_app_catalog_listingssmp_app_catalog_listingsApp Catalog ListingApp Catalog Listingsmaster--required-catalog:admin-
2smp_app_lifecycle_stagessmp_app_lifecycle_stagesApp Lifecycle StageApp Lifecycle Stagesmaster--required-operational_workflow:manage-
3smp_alertssmp_alertsSaaS AlertSaaS Alertsmaster--required-operational_workflow:manage-
4smp_app_integrationssmp_app_integrationsSaaS App IntegrationSaaS App Integrationsmaster--required-operational_workflow:manage-
5smp_app_ownerssmp_app_ownersSaaS App OwnerSaaS App Ownersmaster--required-junction:manage-
6saas_applicationssaas_applicationsSaaS ApplicationSaaS Applicationsmaster--required-operational_workflow:manage-
7shadow_it_appsshadow_it_appsShadow IT AppShadow IT Appsmaster--required-operational_workflow:manage-

4. Aliases and industry synonyms

(none: no industry-scoped aliases for this scope)

5. Relationships

5.1 Intra-scope edges

fromverbtocardinalitykindnecessityowner_sidedelete_modefk_formatnotes
saas_applicationsownssmp_app_ownersmany_to_manyreferencerequiredsourcerestrictreference-
saas_applicationsintegrates_withsmp_app_integrationsone_to_manyreferencerequiredtargetrestrictreference-
saas_applicationspublishessmp_app_catalog_listingsone_to_onereferencerequiredsourcerestrictreference-
saas_applicationsraised_forsmp_alertsone_to_manyreferenceoptionaltargetclearreference-
shadow_it_appsraised_for_shadowsmp_alertsone_to_manyreferenceoptionaltargetclearreference-
saas_applicationstracks_stagesmp_app_lifecycle_stagesone_to_onereferencerequiredtargetrestrictreference-
shadow_it_appspromotes_tosaas_applicationsone_to_onereferenceoptionalsourceclearreference-

5.2 Built-in edges (users and other platform built-ins)

fromverbtocardinalitynecessityowner_sidedelete_modefk_formatnotes
usersassigned_ownersmp_app_ownersmany_to_manyrequiredsourcerestrictreference-
usersconfiguressmp_app_integrationsone_to_manyrequiredtargetrestrictreference-
userscuratessmp_app_catalog_listingsone_to_manyoptionaltargetclearreference-
userstriagessmp_alertsone_to_manyoptionaltargetclearreference-
usersownssaas_applicationsone_to_manyrequiredtargetrestrictreference-
userstriggeredshadow_it_appsone_to_manyoptionaltargetclearreference-

5.3 Cross-scope edges

5.3a Outbound from this scope’s masters and contributors

Edges this scope drives: the in-scope endpoint has role of master or contributor.

fromverbtocardinalitynecessitydelete_modefk_formatnotes
enterprise_applicationsaliased_assaas_applicationsone_to_oneoptionalnonen/a-
saas_applicationslifecycle events forasset_lifecycle_eventsone_to_manyoptionalnonen/a-
asset_contractscoverssaas_applicationsmany_to_manyoptionalnonen/a-
saas_applicationsentitles_toiga_user_entitlementsone_to_manyrequirednone (required-if-present)n/a-
saas_applicationsrecommends_for_appsmp_optimization_recommendationsone_to_manyoptionalnonen/a-
saas_applicationsbenchmarks_forsmp_app_benchmarksone_to_manyrequirednone (required-if-present)n/a-
saas_applicationsassesses_appsmp_vendor_risk_assessmentsone_to_manyrequirednone (required-if-present)n/a-
saas_applicationsautomates_appsmp_automation_workflowsone_to_manyoptionalnonen/a-
smp_app_catalog_listingsrequests_listingsmp_app_requestsone_to_manyrequirednone (required-if-present)n/a-
saas_applicationshassaas_subscriptionsone_to_manyoptionalnonen/a-
saas_applicationsmeasured_bysaas_usage_metricsone_to_manyrequired⚠ audit: required composed child out of scopen/a-
saas_applicationsassigned_viasmp_license_seat_assignmentsone_to_manyrequired⚠ audit: required composed child out of scopen/a-
saas_applicationsis registered asenterprise_applicationsone_to_oneoptionalnonen/a-
saas_applicationsraises_incidentservice_incidentsone_to_manyoptionalnonen/a-
shadow_it_appstriggers_requisitionpurchase_requisitionsone_to_manyoptionalnonen/a-

5.3b Context edges on embedded shells and consumed entities

Edges the canonical owner drives, shown for context: the in-scope endpoint has role of embedded_master, consumer, or derived.

(none: no context cross-scope edges on this scope’s embedded shells or consumed entities)

6. Cross-domain context

6.1 Master consumers (other modules / domains that embed this scope’s masters)

data_objectother module / domainrolenecessitynotes
saas_applicationsAPM-PORTFOLIO-REGISTRY (Portfolio Registry) - APMconsumeroptional-
saas_applicationsIGA-ENTITLEMENT-CATALOG (IGA Entitlement Catalog) - IGAconsumeroptionalNewly discovered or sanctioned SaaS apps trigger entitlement registration in IGA catalog.
saas_applicationsIT-OPS-STARTER (IT Operations Starter) - IT-OPS-STARTERembedded_masteroptional-
saas_applicationsITAM-PORTFOLIO-REPORTING (Portfolio TCO Reporting) - ITAMconsumerrequired-
saas_applicationsSMP-RENEWAL-VENDOR (SMP Renewal and Vendor Management) - SMPembedded_masterrequired-

6.2 Outbound handoffs (events this scope publishes)

source moduletarget domaintarget moduletrigger_eventtransitionpayloadintegrationfrictiondescription
SMP-DISCOVERYIGAIGA-ENTITLEMENT-CATALOGsaas_application.discovered(lifecycle)saas_applicationsevent_streammediumNewly discovered SaaS apps surface to IGA for shadow-IT visibility and access governance.
SMP-DISCOVERYIGAIGA-ENTITLEMENT-CATALOGsaas_application.sanctioned(lifecycle)saas_applicationsapi_calllowSanctioned SaaS apps are wired into IGA provisioning catalog.
SMP-DISCOVERYFINOPS(domain-level)saas_application.sanctioned(lifecycle)saas_applicationsevent_streammediumSanctioned SaaS apps come under FINOPS spend tracking.

6.3 Inbound handoffs (events this scope reacts to)

target modulesource domainsource moduletrigger_eventtransitionpayloadintegrationfrictiondescription
SMP-DISCOVERYDISCOVERY(domain-level)sso_login.unsanctioned_app(state_change)shadow_it_appsevent_streammediumSSO logs reveal a login to a SaaS app that’s not in the sanctioned catalog - flagged as shadow IT. Complements the EXPENSE-side detection: SSO catches apps that use corporate SSO but aren’t tracked; expense catches credit-card paid apps that don’t.
SMP-DISCOVERYEXPENSE(domain-level)card.saas_charge_detected(state_change)shadow_it_appsevent_streamhighCorporate-card SaaS charge detected by the expense system surfaces a candidate shadow-IT app in SMP. High friction: finance sees the charge, IT/SMP sees (or doesn’t see) the app - reconciling vendor-name-on-card with app-name-in-portfolio is messy and is one of the highest-value SMP-to-EXPENSE integrations.
SMP-DISCOVERYSMPSMP-RENEWAL-VENDORsmp_vendor_risk_assessment.remediation_required(state_change)smp_alertslifecycle_progressionlowA vendor risk assessment requiring remediation raises a portfolio alert on the application.
SMP-DISCOVERYSPEND-MGMTSPEND-MGMT-CARDScard_transaction.postedposted (signal)shadow_it_appsapi_callhighSaaS purchases on corporate cards reveal shadow IT to SMP - merchant categorization required to identify SaaS subscriptions vs other spend, then deduplicated against the existing SMP saas_subscription catalog. The card-side discovery path is the primary signal for off-procurement SaaS today. Shadow-data pattern.

6.4 Master providers (modules / domains that own masters this scope embeds)

(none: this scope embeds no masters owned elsewhere; every entity is mastered here)

7. Lifecycle states

saas_applications (SaaS Application)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10discovered---App detected via SSO logs, expense data, or browser plugin. Not yet reviewed by IT.
20triaged----App has been reviewed by IT but no sanction decision recorded yet.
30sanctioned--smp-discovery:sanction_applicationApp is officially supported; IGA provisioning, FINOPS spend tracking, and ITAM registration activated.
40deprecated--smp-discovery:deprecate_applicationSlated for replacement or removal; no new assignments allowed; existing users on read-only or sunset path.
50deprovisioned-smp-discovery:deprovision_applicationApp removed tenant-wide. ITSM closes related tickets; IGA revokes access; FINOPS terminates spend.

shadow_it_apps (Shadow IT App)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10discovered---Unsanctioned app surfaced by discovery (expense card, signup detection, network traffic). Awaiting triage.
20triaged----IT has reviewed the shadow app and is weighing sanction vs block.
30sanctioned_promoted-smp-discovery:promote_shadow_appShadow app promoted to the sanctioned catalog; a corresponding saas_applications record is created.
40blocked-smp-discovery:block_shadow_appShadow app blocked at the network and SSO layer; users notified.

smp_alerts (SaaS Alert)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10raised----
20acknowledged--smp-discovery:acknowledge_alert-
30triaged--smp-discovery:triage_alert-
40resolved-smp-discovery:resolve_alert-
50suppressed-smp-discovery:suppress_alert-

smp_app_catalog_listings (App Catalog Listing)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10draft----
20published--smp-discovery:publish_catalog_listing-
30deprecated--smp-discovery:deprecate_catalog_listing-
40unlisted-smp-discovery:unlist_catalog_listing-

smp_app_integrations (SaaS App Integration)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10configured----
20connected-----
30degraded--smp-discovery:mark_integration_degraded-
40disconnected--smp-discovery:disconnect_integration-
50archived-smp-discovery:archive_integration-

smp_app_lifecycle_stages (App Lifecycle Stage)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10evaluate----
20pilot--smp-discovery:promote_to_pilot-
30sanctioned--smp-discovery:promote_to_sanctioned-
40sunset--smp-discovery:sunset_app-
50retired-smp-discovery:retire_app-

smp_app_owners (SaaS App Owner)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10active----
20revoked-smp-discovery:revoke_app_owner-

8. Permissions and business rules (derived)

8.1 Permissions

permissiontierdescriptionincluded in :admin?
smp-discovery:readbaseline-readRead access to every entity in the module
smp-discovery:managebaseline-manageEdit operational records
smp-discovery:adminbaseline-adminEdit reference data and inherit every workflow gate below-
smp-discovery:sanction_applicationworkflow-gate (lifecycle)Transition saas_applications into state sanctioned
smp-discovery:deprecate_applicationworkflow-gate (lifecycle)Transition saas_applications into state deprecated
smp-discovery:deprovision_applicationworkflow-gate (lifecycle)Transition saas_applications into state deprovisioned
smp-discovery:promote_shadow_appworkflow-gate (lifecycle)Transition shadow_it_apps into state sanctioned_promoted
smp-discovery:block_shadow_appworkflow-gate (lifecycle)Transition shadow_it_apps into state blocked
smp-discovery:revoke_app_ownerworkflow-gate (lifecycle)Transition smp_app_owners into state revoked
smp-discovery:mark_integration_degradedworkflow-gate (lifecycle)Transition smp_app_integrations into state degraded
smp-discovery:disconnect_integrationworkflow-gate (lifecycle)Transition smp_app_integrations into state disconnected
smp-discovery:archive_integrationworkflow-gate (lifecycle)Transition smp_app_integrations into state archived
smp-discovery:publish_catalog_listingworkflow-gate (lifecycle)Transition smp_app_catalog_listings into state published
smp-discovery:deprecate_catalog_listingworkflow-gate (lifecycle)Transition smp_app_catalog_listings into state deprecated
smp-discovery:unlist_catalog_listingworkflow-gate (lifecycle)Transition smp_app_catalog_listings into state unlisted
smp-discovery:acknowledge_alertworkflow-gate (lifecycle)Transition smp_alerts into state acknowledged
smp-discovery:triage_alertworkflow-gate (lifecycle)Transition smp_alerts into state triaged
smp-discovery:resolve_alertworkflow-gate (lifecycle)Transition smp_alerts into state resolved
smp-discovery:suppress_alertworkflow-gate (lifecycle)Transition smp_alerts into state suppressed
smp-discovery:promote_to_pilotworkflow-gate (lifecycle)Transition smp_app_lifecycle_stages into state pilot
smp-discovery:promote_to_sanctionedworkflow-gate (lifecycle)Transition smp_app_lifecycle_stages into state sanctioned
smp-discovery:sunset_appworkflow-gate (lifecycle)Transition smp_app_lifecycle_stages into state sunset
smp-discovery:retire_appworkflow-gate (lifecycle)Transition smp_app_lifecycle_stages into state retired

8.2 Business rules

(none: no flag-derived business rules)

9. Roles, RACI, and responsibilities (derived)

Baseline roles, the permission hierarchy, and RACI realization are DERIVED from this scope’s entity-type write tiers + process_raci; none of it is stored in the catalog (the deployer provisions it from this blueprint).

9.1 SMP-DISCOVERY

Baseline roles:

rolebaseline grant
smp-discovery_viewersmp-discovery:read
smp-discovery_managersmp-discovery:manage
smp-discovery_adminsmp-discovery:admin

Permission hierarchy:

permissionincludes
smp-discovery:adminsmp-discovery:manage
smp-discovery:managesmp-discovery:read
smp-discovery:adminsmp-discovery:sanction_application
smp-discovery:adminsmp-discovery:deprecate_application
smp-discovery:adminsmp-discovery:deprovision_application
smp-discovery:adminsmp-discovery:promote_shadow_app
smp-discovery:adminsmp-discovery:block_shadow_app
smp-discovery:adminsmp-discovery:revoke_app_owner
smp-discovery:adminsmp-discovery:mark_integration_degraded
smp-discovery:adminsmp-discovery:disconnect_integration
smp-discovery:adminsmp-discovery:archive_integration
smp-discovery:adminsmp-discovery:publish_catalog_listing
smp-discovery:adminsmp-discovery:deprecate_catalog_listing
smp-discovery:adminsmp-discovery:unlist_catalog_listing
smp-discovery:adminsmp-discovery:acknowledge_alert
smp-discovery:adminsmp-discovery:triage_alert
smp-discovery:adminsmp-discovery:resolve_alert
smp-discovery:adminsmp-discovery:suppress_alert
smp-discovery:adminsmp-discovery:promote_to_pilot
smp-discovery:adminsmp-discovery:promote_to_sanctioned
smp-discovery:adminsmp-discovery:sunset_app
smp-discovery:adminsmp-discovery:retire_app

Processes wired:

process_keyprocess_namePCF codePCF IDleveldescription
manage_it_portfolio_strategyManage IT portfolio strategy8.2.2206603Strategy for systematic management of IT investments, projects, and activities. Analyze and examine the value of the IT portfolio and allocate resources based on business objectives.
manage_it_user_identityManage IT user identity and authorization8.3.8207563The process of identifying, authenticating, and authorizing IT users to have access to applications, systems, IT components, or networks by associating user rights and restrictions with established identities.
manage_infrastructure_resourceManage infrastructure resource administration8.7.7209143Managing the resources required for administration of IT infrastructure. Manage the IT inventory and assets. Take care of the organization’s IT resource capacity.
manage_corporate_credit_cardsManage corporate credit cards9.6.3209293Handling and authoring credit cards to business entities or for corporate purchases.

RACI realization:

actorkindraciprocess_keyrealization
ITAM-SAAS-PORTFOLIO-MANAGERpersonaresponsiblemanage_it_portfolio_strategygrant gates [smp-discovery:sanction_application, smp-discovery:deprecate_application, smp-discovery:promote_to_pilot, smp-discovery:promote_to_sanctioned, smp-discovery:sunset_app, smp-discovery:retire_app] + the gated entities’ write tier
ITAM-SAAS-PORTFOLIO-MANAGERpersonaaccountablemanage_it_portfolio_strategyapproval gate
IT-SAAS-ADMINpersonaresponsiblemanage_it_user_identitygrant gates [smp-discovery:deprovision_application, smp-discovery:revoke_app_owner] + the gated entities’ write tier
IT-SAAS-ADMINpersonaaccountablemanage_it_user_identityapproval gate
IT-SAAS-ADMINpersonaresponsiblemanage_infrastructure_resourcegrant gates [smp-discovery:promote_shadow_app, smp-discovery:mark_integration_degraded, smp-discovery:disconnect_integration, smp-discovery:archive_integration, smp-discovery:publish_catalog_listing, smp-discovery:deprecate_catalog_listing, smp-discovery:unlist_catalog_listing, smp-discovery:acknowledge_alert, smp-discovery:triage_alert, smp-discovery:resolve_alert, smp-discovery:suppress_alert] + the gated entities’ write tier
IT-SAAS-ADMINpersonaaccountablemanage_infrastructure_resourceapproval gate
IT-SAAS-ADMINpersonaresponsiblemanage_corporate_credit_cardsgrant gates [smp-discovery:block_shadow_app] + the gated entities’ write tier
IT-SAAS-ADMINpersonaaccountablemanage_corporate_credit_cardsapproval gate

9.2 Functional ownership and default grants

responsibilitybusiness functiondefault roledefault tier
ownerIT Asset Managementadmin:admin
contributorFinancemanage:manage
contributorProcurementmanage:manage