Skip to content
Asset Register

Register  ·  Foundations

Shadow IT: Why It Exists

Unapproved tools appear because the approved path was slower than the problem. Treating it as indiscipline just produces better concealment.

Analysis  ·  759 words

Shadow IT is usually framed as a control failure. It is more accurately a symptom: people needed something and the sanctioned route did not deliver it in time.

Why it happens

The approved tool does not do the job, or does it badly.

Procurement takes weeks and the deadline is Friday.

Nobody knows what the approved tool is.

A free tier costs nothing, so no approval is needed and none is sought.

The team is remote or newly acquired and never learned the process.

A vendor made it trivially easy — sign in with your work account, thirty seconds, no card.

None of these is defiance. They are rational responses to friction.

The actual risks

Worth being specific rather than treating all of it as equally alarming.

Company data in an unassessed service. The primary risk, and it varies enormously by what data.

No offboarding. A leaver keeps access indefinitely, because nobody knew the account existed.

No backup or export. A team's system of record with no continuity plan.

Duplicate spend on overlapping tools.

OAuth grants giving a third party read access to your email or files, granted by one user with one click.

Compliance exposure where regulated data is involved.

A free note-taking tool used for personal task lists is not the same risk as an unassessed platform holding customer records, and a programme that treats them identically loses credibility fast.

What does not work

Blocking. Users find alternatives, and the alternatives are less visible.

Punishing discovery. If admitting to a tool produces trouble, admissions stop.

A long approval process as the only route. It is the cause, not the cure.

Blanket bans on categories, which push usage to personal accounts where you can see nothing at all.

What does

A fast path. A lightweight approval that returns an answer in days for low-risk tools, with a fuller review reserved for anything touching sensitive data. Most requests are low risk and should be answered quickly.

Amnesty. A stated period where declaring an existing tool has no consequence. This produces more inventory than any discovery tool, once, and it only works if the promise is kept.

Make the approved options findable. A visible catalogue of what is already licensed. A large share of shadow IT is people buying something the organisation already has.

Automatic discovery, so the register does not depend on declarations.

Risk-tiered response. Low risk: register it and move on. High risk: review it. Unacceptable: migrate the data and close it, with help rather than blame.

The productive framing

Every shadow application is a requirement nobody captured.

A team using an unapproved tool is telling you something about the approved stack. Three teams using the same unapproved tool is telling you what to buy centrally, at a better price, with a security review.

Treated that way, discovery produces a roadmap. Treated as a compliance sweep, it produces a list, a round of removals, and the same situation again in a year with better concealment.

Tiering the response

Treating every unregistered application as equally serious wastes attention and credibility. A three-way split works.

Register and move on. No company data, no integration, no cost. A formatting tool, a converter, a diagramming site. Add it to the register, note the owner, do nothing else.

Review and decide. Business data, or an integration with a platform you control. Run the medium-tier assessment, decide whether to sanction, consolidate or replace.

Act now. Regulated or personal data at scale, credentials, or broad write access to a core system. Contact the team the same week, understand what is in it, and plan a migration with help attached.

Most findings land in the first category, which is worth saying aloud when presenting the discovery results. A list of two hundred applications reads as a crisis until it is tiered, at which point it reads as a workload.

The amnesty, run once and properly

An amnesty works exactly once, and only if the promise holds.

State the window, a few weeks, with a date.

State the purpose: protecting data, and building a list so that support and continuity are possible.

State the promise plainly: nothing declared during the window results in disciplinary consequence, and nothing will be removed without a conversation.

Have leadership say it, not IT, because the promise has to be credible.

Then keep it, including in the awkward cases. One team punished for an honest declaration ends every future amnesty in the organisation.

Follow it with a working request path, or the next round of shadow IT begins the week it closes.