Skip to content

Shadow IT will make organisations more agile and user centric

Shadow IT is a signal before it is a threat — people route around IT when provisioning is too slow. Self-service removes the reason it happens. Discovery tells you where it already has.

Shadow IT — devices, software and services outside the ownership or control of the IT department — keeps growing. There are obvious disadvantages to that, and we will come to them. But the more useful reading is that shadow IT is a wake-up call from employees who find IT provisioning too slow and too cumbersome for the realities of their working lives.

From personal devices to unsanctioned software, IT needs to look hard at why this is happening before deciding what to do about it. An answer that only restricts will fail, because it treats the symptom.

Before looking at how shadow IT should be embraced, it is worth being honest about the problems it brings.

It increases non-compliance

The main issue is licensing. Even with strong SAM procedures in place, shadow IT introduces software onto corporate devices that nobody has entitlement for. That leaves the organisation exposed at audit, and exposed to the settlement that follows a finding.

There is a second problem, less discussed. New devices and software are normally tested and piloted before they go anywhere near the wider organisation. Shadow IT skips that step entirely, so the first time anyone assesses the impact on existing infrastructure is after something breaks.

Why it happens now, and did not before

IT departments used to be able to lock down the introduction of new hardware and software simply because users had neither the know-how nor the means to do it themselves.

That has gone. App stores let employees browse, buy, download and install in a few clicks. A tablet or phone joins the corporate network over wireless in seconds. And the modern version is not really software installation at all — it is a signup page, a corporate card, and a working tool inside two minutes.

The scale of that shift is worth stating plainly. The average enterprise portfolio now runs to 305 SaaS applications, and 46% of SaaS licences go unused. Not all of that is shadow IT. But no organisation buys 305 applications through a single, well-governed procurement route.

Self-service removes the reason

This is where the answer lies, and it is a flexibility answer rather than a control answer.

Give employees the ability to choose and deploy the software they need to do their jobs — with the necessary checks and sign-offs attached — and you remove the root cause of shadow IT while regaining control of what actually gets deployed. You also improve the service IT provides, which raises the standing of the IT function across the business. That is the win-win, and it is still true ten years after this post was first written.

A corporate self-service portal delivers the ease of use employees want, alongside the controls IT needs for licence compliance and infrastructure integration. In CerteroX ITAM this is App-Centre: a self-service catalogue with manager approval chains, sitting on the same platform as software distribution, patching and the licence position, so an approved request draws from entitlement you already hold rather than creating a new liability.

But you also have to be able to see it

The original version of this argument stopped there, and in 2016 that was reasonable. Prevention was the only lever anyone had. Discovery of unsanctioned cloud services was, for most organisations, guesswork.

That is no longer the case, and it is the part of this post that most needed updating.

CerteroX SaaS Management finds what is already in use through three converging signals rather than one:

  • A browser extension that detects SaaS domains in real use, with time-on-app and per-user attribution. This is what surfaces the application nobody expensed and nobody integrated.
  • Identity provider sync from Entra ID and Okta, including MFA enrolment, which gives you the authoritative user list to measure everything else against.
  • Vendor API connectors — 47 of them shipping today — that pull the real user and licence lists from the vendor’s own system, so you are comparing your assumption against their record.

On top of that sits OAuth grant discovery, which finds the third-party applications employees have consented to and scores each grant from 0 to 100 on data sensitivity, scope breadth, how the consent was given and how long it has been dormant. This matters more than the seat cost. A forgotten seat wastes money; a forgotten grant with read access to the company drive is a security exposure that survives the person who created it.

There is also a Shadow AI dashboard, because the newest version of this problem is not a project management tool. AI applications are classified from feature tags in a catalogue of more than 35,000 applications rather than a hardcoded list, so the detection set keeps up on its own, and adoption is ranked by the share of the organisation using each tool. Ten people using an AI assistant is a governance conversation. A thousand is a different one.

Embrace it, but on your terms

Shadow IT will not be legislated away. The organisations that handle it well do two things at once.

They make the sanctioned route faster than the unsanctioned one, so most people never need to go around IT. And they keep looking, because some people always will — and because the thing you did not know about is the thing you cannot bring under a contract, renew sensibly, revoke at offboarding, or defend at audit.

Do those together and shadow IT stops being a threat to manage and starts doing what the title says: making the organisation more agile and more user centric, with IT in the room rather than finding out afterwards.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.