Shadow IT is software bought or used without the knowledge of IT or procurement. A team signs up for a project tool with a credit card. A department starts a free trial that quietly becomes a paid plan. An employee connects a browser extension to company data. None of it is malicious, and much of it is useful. But it creates three problems: cost nobody manages, contracts nobody reviewed, and data nobody protects.
Why it grows
Most SaaS is now bought outside IT. Zylo's 2025 data shows lines of business control 70% of SaaS spend. When the official route takes weeks and a card payment takes minutes, people choose the card.
Shadow IT is not a discipline problem. It is a measure of how much faster the workaround is than the approved route.
The three risks
Duplicate tools, monthly list prices, subscriptions that outlive the project that needed them.
Click-through terms with auto-renewal, data-processing clauses and liability limits nobody checked.
Company data in accounts outside single sign-on, with no offboarding and no retention control.
How to find it
| Discovery method | What it finds | Limits |
|---|---|---|
| Expense and card data | Paid subscriptions bought by teams | Free tools; vague descriptions |
| Accounts payable | Invoiced tools outside procurement | Reseller invoices hide products |
| Identity provider sign-ins | Apps connected to single sign-on | Apps that use separate passwords |
| OAuth app grants | Apps users connected to company accounts | Needs admin access to review |
| Browser or network data | Websites and apps in use | Privacy considerations; partial coverage |
Start with money. Expense and card data find the paid tools, which carry the cost and the contract risk. Then add OAuth grants, which reveal free tools connected to company email and files.
A fair five-step response
- Discover
Paid and connected tools, from money first and identity second.
- Assess
What data each one holds, its security posture, its terms and its cost.
- Decide
With the team that uses it: keep, replace with an approved tool, or retire.
- Contract
Put the tools you keep under a company agreement with an owner, single sign-on and a renewal date.
- Monitor
Review new expense and sign-in data every month.
Make the approved route faster
Shadow IT is a symptom of friction. Publish a catalog of approved tools, pre-approve low-risk, low-cost categories, and set a service level for reviewing new requests. Our guide to SaaS approval workflows shows how to tier approvals so small purchases move fast.
- Publish a searchable catalog of approved tools by capability.
- Pre-approve low-risk, low-cost categories.
- Promise a review time for new requests, and keep it.
- Treat discovered tools as signals of real needs.
- Blocking everything not on the list.
- Naming and shaming teams that bought their own tools.
- Running discovery once and never again.
- Ignoring free tools that hold company data.
How MI One helps
Frequently asked questions
Is shadow IT always bad?
No. It often shows what people need. The goal is visibility and control, not prohibition.
Should we block unapproved apps?
Block only clear security risks. For everything else, make the approved route easier.
How often should we run discovery?
A full discovery once a year, and a monthly review of new card transactions and app grants.
Sources
- Zylo, "2025 SaaS Management Index," January 16, 2025. https://zylo.com/news/2025-saas-management-index