Shadow IT discovery

The apps nobody told you about

What people signed up for with a company card and a work email, and what those apps can reach.

Discovery shows you the scope rather than the logo. An application holding read access to every file in Drive is a different problem from one that reads a calendar, and you see who granted it, when, and what it has touched since.

That framing is the useful one. Shadow IT is usually framed as a spending problem. It is mostly an access problem.

The subscription is the visible part and generally the smaller one. The part that matters is that somebody clicked "Sign in with Google" and granted an application read access to all their mail, and that grant is still live 18 months later.

Die Shadow-IT-Ansicht in Iden mit erkannten Applikationen, die im Einsatz, aber nie freigegeben oder angebunden wurden.

Applikationen im Einsatz, von denen die IT nichts wusste, und worauf jede davon zugreifen kann.

Why it happens

Because it works. Somebody needed a transcription tool on a Tuesday, procurement takes 3 weeks, and the trial took 90 seconds.

Treating that as misconduct is both wrong and unhelpful. It is a signal that the sanctioned path is slower than the need.

What to actually look at

The scope, not the app. A tool with read access to all files is a different problem from one that reads a calendar, even if both are unsanctioned.

Who granted it. One person granting on their own behalf is a smaller blast radius than an admin granting domain-wide.

Whether anybody still uses it. Most of what discovery finds is abandoned, and abandoned-with-a-live-token is the worst combination.

Whether it holds company data. An app nobody uses that still has a copy of last year's customer list is a breach waiting for somebody else's incident.

What happens next

Three outcomes, and only one of them is shutting it off.

Sanction it, which means connecting it so it joins lifecycle and reviews like everything else. Replace it with whatever you already pay for that does the same job. Or revoke it, which for an OAuth grant means killing the token rather than cancelling a subscription.

What still needs a person

Deciding which bucket each app goes in. That is a judgement about how your company works, and it is worth having the conversation with the person who signed up rather than about them.

Frequently asked questions

Mostly through OAuth grants against your Google Workspace or Microsoft tenant, plus expense signals and connector-level data. An app somebody logged into with a work account leaves a trace.

No. Most shadow IT is somebody solving a real problem faster than procurement could. The goal is knowing what exists, what it reaches, and closing the ones that are genuinely wrong.

Usually not the subscription. It is the OAuth scope: a tool granted read access to all mail or all files, by one person, for a trial they forgot about.