Your IT Team Knows About 40 SaaS Apps. You Have 130.

Shadow IT is not a policy failure. It is the natural result of frictionless SaaS adoption. Here is why it keeps growing, what security and compliance risk it actually creates, and what to do about it beyond writing a policy nobody reads.

All posts

What shadow IT actually is today

Shadow IT used to mean a team spinning up an unauthorized server, or someone plugging in a personal USB drive. That framing is out of date. Today, shadow IT is almost entirely SaaS: tools employees adopt independently, without going through IT approval, procurement, or security review.

It does not look like a policy violation from the inside. It looks like a marketer signing up for a free Notion account to organize a campaign. A developer connecting a GitHub repo to a new CI tool to ship faster. An executive using a personal ChatGPT subscription to draft board materials. Each individual decision is reasonable. The aggregate is a large, unmanaged, invisible surface area.

3x more apps than IT knows
2–3 new apps added per employee / month
80% via Google or email sign-up

How it spreads

The structural reason shadow IT keeps growing is that signing up for a new SaaS tool is now trivially easy. A Google "Sign in with Google" button, a work email address, and you have an active account in under 60 seconds. No ticket, no approval, no procurement cycle.

Three patterns drive most of it:

  • OAuth sign-in. Employees connect new tools using their Google or Microsoft identity. This creates an active session in a tool your IdP never touched and may not know exists.
  • Free tiers. Most SaaS products have a free tier that requires no corporate involvement. The tool starts as a personal experiment and becomes a team workflow before IT is ever notified.
  • Team sprawl. One person adopts a tool, finds it useful, and shares it with their team. By the time IT discovers it, there are 20 active users and real business data inside.

IT policies requiring approval before adopting new tools exist at most companies. They do not slow SaaS adoption, because the friction of following the process exceeds the friction of just signing up and dealing with it later.

The real risks

Shadow IT risk gets framed as a compliance problem, and it is. But the compliance framing understates what is actually at stake.

Data you cannot account for
When an employee uploads customer data to a free-tier AI writing tool, that data leaves your environment and lands in a third-party system you have no contract with, no DPA for, and no way to audit. GDPR Article 28 requires a data processing agreement with every processor that handles personal data. Shadow IT creates processors you do not know about.
Access you cannot revoke
Every shadow IT tool is an account your offboarding process will miss. When an employee leaves, their Notion workspace, their Grammarly account with access to all their written content, and their personal ChatGPT subscription with uploaded documents all remain active. The accounts survive the departure because they were never in scope.
Audit evidence you cannot produce
SOC 2 and ISO 27001 ask you to demonstrate that access to systems holding sensitive data is controlled. Shadow IT tools are systems holding sensitive data with zero access controls. An auditor sampling actual employee access will find accounts in tools that were never on any access review.

What a shadow IT discovery scan actually shows

Most IT teams are surprised by the results of their first comprehensive shadow IT scan. Not because the tools are exotic, but because of the volume and what they contain.

Shadow IT Discovery · Sample Results 47 unmanaged apps found
App Users Data category Risk
ChatGPT (personal) 38 Internal docs, customer data High
Notion (personal accounts) 21 Project data, customer notes High
Grammarly 89 All written content Medium
Loom (free tier) 14 Screen recordings, demos Medium
Zapier (personal) 7 CRM and email data High

The Grammarly finding surprises people most. 89 users means effectively your entire writing-heavy workforce has a browser extension with access to everything they type, connected to a third-party service under their personal accounts. It is not malicious. It is completely invisible to IT until a scan surfaces it.

Govern, not block

The instinct after a shadow IT scan is to block. Revoke OAuth grants, enforce browser policies, tighten the approval process. That instinct produces two outcomes: employees find workarounds, and legitimate productivity tools get caught in the net.

A more effective approach distinguishes between tools by risk level and treats them accordingly:

Category
Approach
Why
High-risk, no business case
Block and communicate why
Reduce surface area where no legitimate need exists
High-risk, clear business case
Fast-track to managed status
Employees will use it either way. Better to have a DPA and SSO
Medium-risk, widespread use
Adopt and govern
Blocking 89 Grammarly users creates more friction than value
Low-risk, limited use
Monitor and review quarterly
Not worth enforcement overhead for minimal risk

The goal is not zero shadow IT. That is not achievable without blocking productivity. The goal is known shadow IT: a continuous, up-to-date picture of what tools exist, who uses them, and what data they touch, so you can make risk decisions rather than discovering problems during an audit.

Shadow IT and offboarding are the same problem from different angles. Shadow IT is the discovery problem: you do not know what tools an employee uses. Offboarding is the remediation problem: you cannot remove access to tools you do not know about.

Every shadow IT tool an employee uses is an account that will survive their departure. The Notion workspace, the personal ChatGPT subscription with uploaded documents, the Zapier account routing CRM data to personal email. None of those appear on the standard offboarding ticket. All of them remain active when the Okta account goes dark.

Solving shadow IT is therefore a prerequisite for complete offboarding. Continuous discovery running ahead of every departure is what makes the offboarding checklist accurate, rather than a best-effort approximation of the access that actually exists.

See everything. Govern everything.

Lutril discovers SaaS apps across your organization, including the ones IT never approved, and connects discovery directly to access reviews and offboarding workflows.

Get a demo See the platform