What Discovery Misses
Every automated source has a blind spot, and the applications hiding in the intersection of all of them are systematically the higher-risk ones.
Analysis · 729 words
A complete-looking inventory is a partial inventory with confidence attached. Knowing the gaps is part of having the inventory.
The categories that hide
Free tiers. No spend, frequently no SSO, sometimes no OAuth grant. Invisible to three of four sources and commonly holding real data.
Personal accounts used for work. A designer with a personal subscription, a manager with a personal note-taking account containing meeting notes. Visible only through endpoint telemetry or by asking.
Applications inside applications. A plugin, an extension, a marketplace add-on operating within a platform you do know about.
Trials. Not yet billing, already holding data.
Anything on unmanaged devices.
Applications at acquired companies, which arrive as an entire second estate with its own history.
Legacy applications with local accounts and no federation, which are frequently the oldest and most privileged.
Applications paid through a parent agreement, bundled into a larger platform line and never itemised.
Why the gap matters more than its size
The hidden set is not a random sample of your estate.
Free tiers skew toward the unassessed. Nobody reviewed them because nobody bought them.
Personal accounts have no offboarding. The data leaves with the person.
Legacy local-account applications skew privileged. Finance systems, admin tools, infrastructure.
Acquired estates skew unknown, and the acquisition due diligence rarely covered SaaS in detail.
So the applications you cannot see are disproportionately the ones you would most want to.
Closing the gap
Ask, with amnesty. A survey per team, with a stated promise of no consequence for declaring. This is the only method that finds personal accounts, and it works once.
Restrict OAuth granting, which converts an invisible action into an approval request.
Require registration for a payment method, which converts an invisible purchase into a visible one.
Federate aggressively, which moves applications from the invisible category into the identity provider's list.
Check the acquisition, deliberately, whenever one happens. A short SaaS inventory exercise during integration is far cheaper than discovering it two years later.
Monitor domains, where you can. New vendor domains appearing in email or DNS traffic is a weak but real signal.
Measuring the gap
Not directly measurable, and it can be estimated.
Take one team and inventory it exhaustively — interviews, screen sharing, asking to see their bookmarks. Compare against what your automated sources found for that team.
The ratio is your coverage estimate, and it generalises roughly.
Repeat annually on a different team.
Organisations doing this for the first time typically find their automated coverage is materially below what they assumed, and the finding is what justifies the survey work.
Reporting honestly
State the sources used with every inventory figure.
State the known blind spots.
Give a range rather than a count where it matters: "at least 180 applications, with free tiers and personal accounts not fully covered".
A programme that reports a precise count it cannot support loses credibility the first time someone names an application that is not on the list.
Inventorying an acquisition
An acquired company arrives as a complete second estate, and the window to inventory it cheaply is short.
Ask during due diligence, not after. A list of applications, contracts and renewal dates is a reasonable request and it rarely appears on the checklist.
In the first month: identity provider export, expense export, OAuth grants. The same three sources, run against their systems.
Identify contractual overlap immediately. Two contracts with the same vendor is a consolidation opportunity that expires at the next renewal.
Map their renewal calendar into yours, which is the most time-sensitive item.
Identify their unfederated applications, which will be your offboarding problem within weeks.
Do this before integration begins. Once systems start merging, working out which estate an application belonged to becomes considerably harder.
Estimating coverage honestly
The gap cannot be measured directly and it can be estimated well enough to report.
Pick one team. Interview them exhaustively — what they use, what they pay for, what they signed up for and abandoned.
Compare against what automated discovery found for that team.
The ratio is your coverage estimate for that kind of team.
Repeat on a different team annually, varying the type: technical, commercial, operational.
Report the estimate with the method, so nobody treats it as precise.
Expect the first result to be lower than assumed, and expect that result to be the strongest argument you have for running the survey across the organisation.