“ABIT: Anyone But IT.” In a world already saturated with acronyms, this is one you may not have met as a SAM or ITAM stakeholder. Your technology vendors know it well. They created it. It is now their core sales methodology.
Anyone But IT is the target buyer for most B2B technology, and especially for software as a service, where an application can be bought, onboarded and used with little or no involvement from IT. The benefit to the vendor is obvious: sell directly to the person who feels the pain, and there is no technical review to get past.
That is why Salesforce targets chief revenue officers and sales VPs, why Eloqua — now part of Oracle — targets marketing professionals, and why Slack targets anyone who wants people to collaborate. For every line of business in your organisation there is a growing number of vendors selling to it directly.
How did we get here?
Once software no longer had to sit on hardware you owned, vendors finally found a way around IT — often seen as the department of “no” — by serving their product from the cloud. No footprint on the customer’s network, no need for IT to be involved.
It was never quite that simple, but you get the gist. Combine it with far more people outside IT holding technology budget — as technology becomes central to everything, almost every decision about transformation, new ways of working or new processes becomes a technology decision — and you have the ideal conditions for Shadow IT.
Except it is not Shadow IT any more. It is business as usual.
The scale is the part people underestimate. The average enterprise portfolio runs to 305 SaaS applications. Very few IT functions could name 305 applications unprompted, and nobody bought them in one place.
When this article was first written, the honest position was that IT could not see what it had not provisioned. That is no longer the case, and the practical advice changes as a result.
CerteroX SaaS Management discovers applications through three converging signals rather than one. A browser extension detects SaaS domains, time on app and per-user attribution, so an application bought on a card and never mentioned to anyone still appears. Identity provider sync from Entra ID and Okta brings across users, groups and MFA enrolment. Connectors pull the authoritative user and licence list from the vendor itself — 47 of them ship today, covering Microsoft 365, Google Workspace, Slack, Salesforce, Atlassian, Zoom, Box, ServiceNow, OpenAI, Anthropic and the rest of the list.
Applications are resolved against a catalogue of more than 35,000, which is what makes classification possible rather than guesswork. Because AI tools are identified from catalogue feature tags rather than a hardcoded list, the Shadow AI dashboard keeps finding new ones without anyone maintaining a blocklist, and it ranks adoption risk by the share of the organisation using each tool — ten people on a model service is a different problem from a thousand.
OAuth grant discovery covers the part most people forget. When someone consents to a third-party application against the company Google or Microsoft tenant, that grant is scored from 0 to 100 on data sensitivity, scope, consent and dormancy, and it can be revoked in one click or by workflow rule.
So the premise has inverted. The question is no longer can we see it. It is what are we going to do about what we can now see.
Balance the loss of control with an increase in influence
The sooner IT accepts some loss of control — not total loss, as I will come to — and recognises that it now has an opportunity to guide the people making these decisions, the faster the SAM and ITAM functions mature to match how the organisation actually selects and consumes technology.
That does not mean the established responsibilities go away. Sorry to be the bearer of bad news, but one symptom of having more people authorised to make technology decisions is that you are more likely to face compliance issues, not less. Business leaders race ahead and use technology in ways it was not sold for, or create usage beyond what the existing agreement covers. In some ways staying on top of compliance and licence management matters more as IT loses control of consumption, not less.
But this shift is an opportunity as well as a burden. It puts SAM and ITAM teams close to business stakeholders, in a position to understand why consumption is changing and to offer a partnership rather than a policy.
With SaaS, the much-repeated line is that compliance no longer matters because it is the vendor’s problem. Well — yes and no. Even if you set compliance aside, overspend and bill shock remain. Wasted cloud spend runs at 29%, and it rose for the first time in five years. The waste is not an accident of procurement; it is what happens when nobody is managing consumption.
In the rush to transform, that overspend was often overlooked deliberately, because CFOs and business leaders chose speed over cost. As those programmes bed in and organisations start to assess whether they worked, cost becomes a much more important factor. CFOs, business leaders and budget holders are now considerably more willing to take counsel from a SAM or ITAM team offering ways to optimise spend than they used to be.
In fact, technology decision makers outside IT increasingly demand that insight — they want to know whether their people are getting full value from the subscriptions at their disposal, whether behaviour matches the goal, and whether the departmental budget is being used well.
For a SAM or ITAM team with the right tooling, that information is already assembled. An executive dashboard rolls up applications, users, spend and trend. A usage summary gives the active usage rate and identifies power users. Unused licences surface automatically at 30 days of zero usage, and upcoming renewals show days to renewal alongside utilisation, which is the pair of numbers a renewal conversation actually turns on. Applications carry four owner types — application, business, technical and data owner — so the report goes to the person accountable, and per-application budgets carry warning and critical thresholds so the finance conversation starts before the invoice does. Reports can be delivered on a schedule to Slack or Microsoft Teams, which is where the budget holder already is.
Suddenly SAM and ITAM look valuable again, rather than like the licensing police.
Everything stays the same, but everything is different
From the inside it may not feel like a revolution. But the external perception of SAM and ITAM is changing, and we should encourage that shift and respond to it. Yes, SAM will still be cleaning up compliance problems on a regular basis — as I say, everything stays the same. But the primary external role of the team now has to be helping the organisation optimise how it selects, onboards, consumes and pays for technology.
PS — you do not have to surrender control completely
With more technology decision makers than ever and a workforce that expects self-service, you would be forgiven for feeling that control has gone. It has not.
Mature SAM and ITAM practice includes giving people a controlled way to get what they want. The App-Centre self-service portal in CerteroX ITAM lets users request software themselves, with manager approval chains behind it and software distribution doing the delivery. On the SaaS side the same principle runs through provisioning and deprovisioning across Entra, Okta, Google Workspace and Microsoft 365, driven by a workflow engine with eight triggers, eleven conditions and thirteen actions.
The user feels in control — and that is a good thing — but behind the scenes everything is as it should be, within the rules the organisation set, and visible to the teams accountable for it.