Your IT Team Knows About 40 SaaS Apps. You Have 130.
Shadow IT is not a policy failure. It is the natural result of frictionless SaaS adoption. Here is why it keeps growing, what security and compliance risk it actually creates, and what to do about it beyond writing a policy nobody reads.
What shadow IT actually is today
Shadow IT used to mean a team spinning up an unauthorized server, or someone plugging in a personal USB drive. That framing is out of date. Today, shadow IT is almost entirely SaaS: tools employees adopt independently, without going through IT approval, procurement, or security review.
It does not look like a policy violation from the inside. It looks like a marketer signing up for a free Notion account to organize a campaign. A developer connecting a GitHub repo to a new CI tool to ship faster. An executive using a personal ChatGPT subscription to draft board materials. Each individual decision is reasonable. The aggregate is a large, unmanaged, invisible surface area.
How it spreads
The structural reason shadow IT keeps growing is that signing up for a new SaaS tool is now trivially easy. A Google "Sign in with Google" button, a work email address, and you have an active account in under 60 seconds. No ticket, no approval, no procurement cycle.
Three patterns drive most of it:
- OAuth sign-in. Employees connect new tools using their Google or Microsoft identity. This creates an active session in a tool your IdP never touched and may not know exists.
- Free tiers. Most SaaS products have a free tier that requires no corporate involvement. The tool starts as a personal experiment and becomes a team workflow before IT is ever notified.
- Team sprawl. One person adopts a tool, finds it useful, and shares it with their team. By the time IT discovers it, there are 20 active users and real business data inside.
IT policies requiring approval before adopting new tools exist at most companies. They do not slow SaaS adoption, because the friction of following the process exceeds the friction of just signing up and dealing with it later.
The real risks
Shadow IT risk gets framed as a compliance problem, and it is. But the compliance framing understates what is actually at stake.
What a shadow IT discovery scan actually shows
Most IT teams are surprised by the results of their first comprehensive shadow IT scan. Not because the tools are exotic, but because of the volume and what they contain.
The Grammarly finding surprises people most. 89 users means effectively your entire writing-heavy workforce has a browser extension with access to everything they type, connected to a third-party service under their personal accounts. It is not malicious. It is completely invisible to IT until a scan surfaces it.
Govern, not block
The instinct after a shadow IT scan is to block. Revoke OAuth grants, enforce browser policies, tighten the approval process. That instinct produces two outcomes: employees find workarounds, and legitimate productivity tools get caught in the net.
A more effective approach distinguishes between tools by risk level and treats them accordingly:
The goal is not zero shadow IT. That is not achievable without blocking productivity. The goal is known shadow IT: a continuous, up-to-date picture of what tools exist, who uses them, and what data they touch, so you can make risk decisions rather than discovering problems during an audit.
The offboarding connection
Shadow IT and offboarding are the same problem from different angles. Shadow IT is the discovery problem: you do not know what tools an employee uses. Offboarding is the remediation problem: you cannot remove access to tools you do not know about.
Every shadow IT tool an employee uses is an account that will survive their departure. The Notion workspace, the personal ChatGPT subscription with uploaded documents, the Zapier account routing CRM data to personal email. None of those appear on the standard offboarding ticket. All of them remain active when the Okta account goes dark.
Solving shadow IT is therefore a prerequisite for complete offboarding. Continuous discovery running ahead of every departure is what makes the offboarding checklist accurate, rather than a best-effort approximation of the access that actually exists.