Resource
Shadow IT and SaaS sprawl
Every business has tools nobody in charge knows about. A team signed up for something with a company card because it solved a real problem faster than asking would have. The instinct to ban it is understandable and usually counterproductive.
What the actual risks are
Six risks, in rough order of how often they cause genuine harm.
| Risk | How it happens |
|---|---|
| Orphaned accessFormer employees retain access to company data | Nobody removes accounts when staff leave |
| Data outside your controlNo visibility, no backup, no contractual protection | Company information in an unknown vendor's system |
| Duplicate spendDirect cost, usually recurring | Three teams buy three similar tools |
| Weak authenticationA credential outside your identity system | Free tiers rarely support enforced MFA |
| Compliance exposureFindings, and potentially notification obligations | Regulated data in an unassessed service |
| Single person dependencyAccess lost when they leave | One person holds the login |
Bringing it under control
Five steps that work better than a prohibition.
- Run a discovery exercise, starting with expense claims and card statements rather than network tools
- Ask teams directly and without blame, since people volunteer this readily when it is not framed as a violation
- Consolidate obvious duplication, which usually funds the whole exercise
- Bring surviving tools into single sign on so access follows employment
- Publish a short, genuinely fast approval route so the next tool arrives through it
Treat it as a signal
Shadow IT is almost always evidence that a real need went unmet or that the official route was too slow. Staff are not being reckless, they are solving a problem with the tools available.
The businesses that handle this well use the discovery exercise as feedback. If four teams independently bought project management software, the finding is not that four teams broke a rule. It is that the business needed project management software and nobody provided it.
Banning without fixing the underlying gap moves the activity to personal accounts and personal devices, which is strictly worse because it removes what visibility you had.
Common questions
Answered before you ask.
How do we find out what is being used?
Start with finance rather than technology. Expense claims and card statements reveal most of it faster than any discovery tool, and cost nothing. Follow that with a direct, blameless conversation with team leads, who generally volunteer the full list when it is clearly not a disciplinary exercise.
What if a tool is genuinely useful?
Adopt it properly. Bring it into single sign on, put the billing on a company account rather than someone's card, assign an owner, and check what data it holds against any compliance obligation. Discovering a good tool your staff found is a positive outcome, not a problem to be corrected.
How does this affect offboarding?
It is the largest practical risk. A departing employee's company accounts get disabled, and their logins to six services nobody documented do not. Bringing tools into single sign on solves this structurally, because disabling one identity removes access everywhere rather than relying on somebody remembering a list.
Related
Read next.
IT consulting and vCIO
Budgets, roadmaps, procurement and quarterly reviews.
Microsoft 365 management
Tenant hardening, device management, licensing and the backup gap.
Microsoft Copilot and AI adoption security
The permissions review to do before deploying it.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
What is included in managed IT services
A line by line scope, including the exclusions most contracts hide.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.