Shadow IT comes in many forms, and it is a symptom of something structural rather
than a discipline problem. Organisations no longer need the technical enablement
of an internal IT team to access technology. A department head with a corporate
card can be live on a new application in four minutes, and nothing in that
transaction touches a process you control.
SaaS discovery is the work of turning unknown applications, unknown security
exposure, unknown compliance obligations and unknown spend into known ones. This
is what that costs when you do not do it, why it used to be genuinely hard, and
what finding it looks like now.
Why shadow SaaS happens
It is worth being precise about the cause, because the wrong diagnosis produces
the wrong remedy.
Shadow SaaS is not usually policy violation. It is people solving a problem with
the fastest available tool, in an environment where the fastest available tool no
longer requires provisioning, procurement or a server. Free tiers remove the
purchase order. Single sign-on with a Google or Microsoft account removes the
account request. A browser removes the installation.
The consequence is that the traditional control points — procurement, the service
desk, software deployment — no longer sit between a person and a new application.
Every one of them can be bypassed without anyone intending to bypass anything.
This is why “ban it” fails as a strategy. The applications are not arriving
through a channel you can close. They are arriving through a browser you cannot
take away.
Scale matters here too. The average enterprise portfolio runs to 305
applications. A large share of that number was never centrally purchased, which
is precisely why it is a number most organisations cannot produce for themselves.
What you cannot see costs you three ways
Security
Every undiscovered application is an authentication surface you are not managing.
The specific exposures are consistent:
- Credentials outside single sign-on. An application that authenticates with a
username and password reused from somewhere else does not get MFA, does not get
conditional access, and does not get disabled when you disable the account.
- OAuth grants. The quiet one. A user clicks “Sign in with Google” and grants a
third-party application read access to the corporate drive. The grant persists
after they stop using the app, after the app changes ownership, and after the
user leaves. Nothing expires it.
- Data in places you have not assessed. Customer records pasted into a tool
nobody has reviewed, in a jurisdiction nobody has checked, under terms nobody
has read.
- Leavers who never left. Offboarding removes the accounts you know about. The
accounts you do not know about keep working.
Compliance
The compliance problem is not that shadow applications breach a specific rule. It
is that you cannot make a statement about your data if you cannot enumerate the
places it is.
Any regime that asks where personal data is processed, who has access to it, and
under what contractual terms — GDPR, ISO 27001, SOC 2, sector regulation —
requires a complete list as its starting input. An incomplete list does not
produce a partially correct answer. It produces an answer you cannot stand behind,
which is the same as not having one.
The awkward version of this conversation is with an auditor, when the evidence you
produce is a list you know to be incomplete and cannot say by how much.
Spend
The financial exposure has two halves, and organisations usually only see the
first.
The visible half is duplication: four project management tools, three file-sharing
services, two video conferencing platforms, each bought by a different team at
list price because none of them was large enough to negotiate.
The invisible half is licences nobody uses — 46% of SaaS licences go unused, and
the average organisation uses 54% of what it buys. That waste is not concentrated
in the applications you never discovered — it is spread across the ones you did,
and it accumulates quietly because nobody reviews a subscription that renews
automatically.
Neither half is fixable without the list.
Why discovery used to be hard, and what works now
The reason SaaS discovery lagged behind software discovery for years is that the
old techniques do not apply. There is no installer, no registry key, no file on
disk, no process to meter. Network-level inspection produces domains without
users, drowns in CDN traffic, and stops working the moment someone is at home.
Expense-report analysis finds only what was expensed, which excludes every free
tier — and free tiers are where the data risk concentrates.
What works is not one signal but three, converging:
Identity provider sync. Entra ID and Okta know about every application that
authenticates through them, including MFA enrolment status. This is the
authoritative view of your sanctioned world, and the gaps in it are informative in
their own right: an application in use that is not behind single sign-on is a
ranked risk, not an oversight.
Vendor API connectors. For applications you know about, the vendor is the
authority on who holds a licence, which tier they are on, and when they last
signed in. Forty-seven connectors ship today, pulling authoritative user and
licence lists directly rather than inferring them. The distinction matters at
renewal, when “our records say” loses to “your records say”.
A browser extension. The signal that finds what the other two cannot. It
detects SaaS domains in actual use, records time-on-app, and attributes both to a
named user — which means an application that was never purchased, never
provisioned and never expensed still shows up, with evidence of who is using it
and how much.
Each signal alone has a blind spot. The identity provider misses everything
outside single sign-on. Connectors only see applications you have already
connected. The browser extension sees usage but not entitlement. Together they
close each other’s gaps, and applications are resolved against a catalogue of over
35,000 to classify what they are rather than leaving you with a list of domains.
Alongside that, OAuth grant discovery enumerates the third-party applications your
users have consented to, and scores each grant from 0 to 100 on data sensitivity,
scope breadth, how the consent was given and how long it has been dormant. Grants
can be revoked with one click, or automatically as a workflow action. This is the
part of shadow SaaS that traditional discovery never reached at all.
Shadow AI is the same problem, moving faster
The 2023 version of this article would have stopped at shadow SaaS. It is no
longer the whole problem.
AI tools are adopted through exactly the mechanism described above — a browser, a
free tier, a corporate email address — but with a materially worse data profile,
because the natural use of them is to paste in the thing you are working on.
Spend on AI-native applications at large enterprises grew 393%. Very little of
that arrived through procurement.
Detection has to be structural rather than a list of known tools, because the list
changes weekly. CerteroX SaaS Management classifies AI tools from application
feature tags in the catalogue, so the detection set grows on its own as the
catalogue does. The Shadow AI dashboard then ranks adoption by the share of the
organisation using each tool across three risk tiers — because ten people on an
AI assistant is a different problem from a thousand, and treating them the same
wastes the response.
From there each tool gets a status: managed, blocked or ignored. That is the
governance step, and it is the one that turns a dashboard into a decision.
From discovery to resolution
Finding the applications is the beginning. The value is in what happens next, and
the honest test of a discovery programme is whether anything changes as a result
of it.
Four things should follow automatically:
- Reclamation. Licences with 30 or more days of zero usage are surfaced for
reclaim, reassignment, tier downgrade or archiving. This is the fastest
defensible saving available and it funds the rest of the programme.
- Rationalisation. Overlapping applications are detected and ranked by
recoverable saving, so consolidation starts with the duplication that is
actually worth the disruption rather than the one someone complained about.
- Offboarding that completes. A per-user checklist showing every licence held,
the connector status behind each, and whether revocation is pending, in progress
or complete — with the monthly cost of anything still open. Deprovisioning
respects each vendor’s reality: some have no suspend API, some require file
ownership transfer before deactivation, some need roles and group memberships
stripped individually.
- Renewal preparation. Upcoming renewals with days remaining and current
utilisation attached, far enough ahead that the number is usable in a
negotiation.
Underneath all four sits a workflow engine — eight triggers, eleven conditions,
thirteen actions — so the response to a discovery is a rule rather than a ticket.
Where to start
Start with the browser extension and the identity provider, in that order of
surprise. The identity provider tells you what you think you have. The browser
extension tells you what you actually have. The gap between those two lists is the
entire subject of this article, and it is almost always larger than the person who
commissioned the exercise expected.
Then connect the vendors for your largest subscriptions, because that is where
utilisation data turns directly into money at the next renewal.
The objective is not a complete inventory for its own sake. It is being able to
answer three questions — what applications are in use, who is using them, and what
data they hold — with a list you would be willing to hand to an auditor.