Skip to content

SaaS Discovery: Turning Unknown SaaS Into the Known

Shadow SaaS is what happens when buying software stops needing IT. What it costs you in security, compliance and spend — and the three converging discovery signals that now find it, including the AI tools nobody declared.

Shadow IT comes in many forms, and it is a symptom of something structural rather than a discipline problem. Organisations no longer need the technical enablement of an internal IT team to access technology. A department head with a corporate card can be live on a new application in four minutes, and nothing in that transaction touches a process you control.

SaaS discovery is the work of turning unknown applications, unknown security exposure, unknown compliance obligations and unknown spend into known ones. This is what that costs when you do not do it, why it used to be genuinely hard, and what finding it looks like now.

Why shadow SaaS happens

It is worth being precise about the cause, because the wrong diagnosis produces the wrong remedy.

Shadow SaaS is not usually policy violation. It is people solving a problem with the fastest available tool, in an environment where the fastest available tool no longer requires provisioning, procurement or a server. Free tiers remove the purchase order. Single sign-on with a Google or Microsoft account removes the account request. A browser removes the installation.

The consequence is that the traditional control points — procurement, the service desk, software deployment — no longer sit between a person and a new application. Every one of them can be bypassed without anyone intending to bypass anything.

This is why “ban it” fails as a strategy. The applications are not arriving through a channel you can close. They are arriving through a browser you cannot take away.

Scale matters here too. The average enterprise portfolio runs to 305 applications. A large share of that number was never centrally purchased, which is precisely why it is a number most organisations cannot produce for themselves.

What you cannot see costs you three ways

Security

Every undiscovered application is an authentication surface you are not managing. The specific exposures are consistent:

  • Credentials outside single sign-on. An application that authenticates with a username and password reused from somewhere else does not get MFA, does not get conditional access, and does not get disabled when you disable the account.
  • OAuth grants. The quiet one. A user clicks “Sign in with Google” and grants a third-party application read access to the corporate drive. The grant persists after they stop using the app, after the app changes ownership, and after the user leaves. Nothing expires it.
  • Data in places you have not assessed. Customer records pasted into a tool nobody has reviewed, in a jurisdiction nobody has checked, under terms nobody has read.
  • Leavers who never left. Offboarding removes the accounts you know about. The accounts you do not know about keep working.

Compliance

The compliance problem is not that shadow applications breach a specific rule. It is that you cannot make a statement about your data if you cannot enumerate the places it is.

Any regime that asks where personal data is processed, who has access to it, and under what contractual terms — GDPR, ISO 27001, SOC 2, sector regulation — requires a complete list as its starting input. An incomplete list does not produce a partially correct answer. It produces an answer you cannot stand behind, which is the same as not having one.

The awkward version of this conversation is with an auditor, when the evidence you produce is a list you know to be incomplete and cannot say by how much.

Spend

The financial exposure has two halves, and organisations usually only see the first.

The visible half is duplication: four project management tools, three file-sharing services, two video conferencing platforms, each bought by a different team at list price because none of them was large enough to negotiate.

The invisible half is licences nobody uses — 46% of SaaS licences go unused, and the average organisation uses 54% of what it buys. That waste is not concentrated in the applications you never discovered — it is spread across the ones you did, and it accumulates quietly because nobody reviews a subscription that renews automatically.

Neither half is fixable without the list.

Why discovery used to be hard, and what works now

The reason SaaS discovery lagged behind software discovery for years is that the old techniques do not apply. There is no installer, no registry key, no file on disk, no process to meter. Network-level inspection produces domains without users, drowns in CDN traffic, and stops working the moment someone is at home. Expense-report analysis finds only what was expensed, which excludes every free tier — and free tiers are where the data risk concentrates.

What works is not one signal but three, converging:

Identity provider sync. Entra ID and Okta know about every application that authenticates through them, including MFA enrolment status. This is the authoritative view of your sanctioned world, and the gaps in it are informative in their own right: an application in use that is not behind single sign-on is a ranked risk, not an oversight.

Vendor API connectors. For applications you know about, the vendor is the authority on who holds a licence, which tier they are on, and when they last signed in. Forty-seven connectors ship today, pulling authoritative user and licence lists directly rather than inferring them. The distinction matters at renewal, when “our records say” loses to “your records say”.

A browser extension. The signal that finds what the other two cannot. It detects SaaS domains in actual use, records time-on-app, and attributes both to a named user — which means an application that was never purchased, never provisioned and never expensed still shows up, with evidence of who is using it and how much.

Each signal alone has a blind spot. The identity provider misses everything outside single sign-on. Connectors only see applications you have already connected. The browser extension sees usage but not entitlement. Together they close each other’s gaps, and applications are resolved against a catalogue of over 35,000 to classify what they are rather than leaving you with a list of domains.

Alongside that, OAuth grant discovery enumerates the third-party applications your users have consented to, and scores each grant from 0 to 100 on data sensitivity, scope breadth, how the consent was given and how long it has been dormant. Grants can be revoked with one click, or automatically as a workflow action. This is the part of shadow SaaS that traditional discovery never reached at all.

Shadow AI is the same problem, moving faster

The 2023 version of this article would have stopped at shadow SaaS. It is no longer the whole problem.

AI tools are adopted through exactly the mechanism described above — a browser, a free tier, a corporate email address — but with a materially worse data profile, because the natural use of them is to paste in the thing you are working on. Spend on AI-native applications at large enterprises grew 393%. Very little of that arrived through procurement.

Detection has to be structural rather than a list of known tools, because the list changes weekly. CerteroX SaaS Management classifies AI tools from application feature tags in the catalogue, so the detection set grows on its own as the catalogue does. The Shadow AI dashboard then ranks adoption by the share of the organisation using each tool across three risk tiers — because ten people on an AI assistant is a different problem from a thousand, and treating them the same wastes the response.

From there each tool gets a status: managed, blocked or ignored. That is the governance step, and it is the one that turns a dashboard into a decision.

From discovery to resolution

Finding the applications is the beginning. The value is in what happens next, and the honest test of a discovery programme is whether anything changes as a result of it.

Four things should follow automatically:

  • Reclamation. Licences with 30 or more days of zero usage are surfaced for reclaim, reassignment, tier downgrade or archiving. This is the fastest defensible saving available and it funds the rest of the programme.
  • Rationalisation. Overlapping applications are detected and ranked by recoverable saving, so consolidation starts with the duplication that is actually worth the disruption rather than the one someone complained about.
  • Offboarding that completes. A per-user checklist showing every licence held, the connector status behind each, and whether revocation is pending, in progress or complete — with the monthly cost of anything still open. Deprovisioning respects each vendor’s reality: some have no suspend API, some require file ownership transfer before deactivation, some need roles and group memberships stripped individually.
  • Renewal preparation. Upcoming renewals with days remaining and current utilisation attached, far enough ahead that the number is usable in a negotiation.

Underneath all four sits a workflow engine — eight triggers, eleven conditions, thirteen actions — so the response to a discovery is a rule rather than a ticket.

Where to start

Start with the browser extension and the identity provider, in that order of surprise. The identity provider tells you what you think you have. The browser extension tells you what you actually have. The gap between those two lists is the entire subject of this article, and it is almost always larger than the person who commissioned the exercise expected.

Then connect the vendors for your largest subscriptions, because that is where utilisation data turns directly into money at the next renewal.

The objective is not a complete inventory for its own sake. It is being able to answer three questions — what applications are in use, who is using them, and what data they hold — with a list you would be willing to hand to an auditor.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.