Shadow IT discovery: how to actually find what you can't see

by
Dawid Winiarski
Last update:
July 17, 2026

Most companies do not have a shadow IT problem so much as a shadow IT visibility problem. The tools are not hidden on purpose. They were adopted by resourceful people solving real problems faster than procurement could keep up. The issue is that no central record sees them, so nobody can govern, secure, or even cost them. Around a third of the applications in a typical corporate stack are disconnected from any identity provider, invisible to standard IAM tooling (Stitchflow, 2026).

Discovery is the precondition for everything else. You cannot offboard a leaver from an app you do not know they use, meet an asset-inventory duty for systems you cannot list, or assess the risk of an integration nobody recorded. Every shadow IT policy, every cleanup, every compliance baseline starts here. The catch is that no single method sees everything. Each one has a blind spot. Good discovery layers a few methods so the blind spots do not overlap.

  • Most companies have a shadow IT visibility problem rather than a shadow IT problem: the tools were adopted by resourceful people, but no central record sees them, so nobody can govern, secure, or cost them.
  • Around a third of the applications in a typical corporate stack are disconnected from any identity provider, invisible to standard IAM tooling (Stitchflow, 2026).
  • No single discovery method sees everything; each has a blind spot, so good discovery layers a few methods so the blind spots do not overlap.
  • The identity provider and OAuth grants give the best ratio of signal to effort, because they show the access apps hold, not just their presence.
  • Triage discovered tools by access, not by name: an app with a read-write OAuth grant into email and files matters more than a standalone utility.
  • Shadow IT regrows continuously, so discovery has to be a habit folded into joiner-mover-leaver and a regular re-check of OAuth grants and new sign-ups.

the discovery methods, and what each one sees

Identity provider and OAuth grants. Your identity provider (Google Workspace, Microsoft Entra, Okta) records every app someone signed into with their company account, and every OAuth grant they approved. This is the highest-signal, lowest-effort source available, because it captures the apps connected to the directory along with the scopes they hold. It sees apps and AI tools authenticated through the directory and the access they were granted. It misses apps people signed up for with email and password rather than "Sign in with Google," and anything on a personal account.

Financial and expense data. Card statements, expense reports, and invoices show what is being paid for. Finance is one of the most reliable shadow SaaS sources precisely because someone has to pay for the tool. It sees paid subscriptions, including ones outside the directory. It misses free tiers and trials, which are often the riskiest because no one is tracking them at all.

Email signals. Sign-up confirmations, "welcome to" emails, password resets, and invoice notifications in company mailboxes reveal tools people adopted. Several discovery tools work primarily from a read-only mailbox connection for this reason. It sees a broad swath of SaaS and AI sign-ups, including free ones. It misses tools adopted entirely on personal email.

Browser and endpoint. What people actually do happens in the browser. Browser-based discovery and endpoint tooling can see the SaaS and AI tools in active use, including ones that never touch single sign-on, and the risky extensions installed alongside them. It sees real usage, personal-account AI, shadow SaaS, and browser extensions. It misses activity on unmanaged devices outside the tool's reach.

Network and egress. Logging or inspecting outbound traffic, historically the CASB approach, shows which cloud services devices connect to. It sees services reached from managed networks and devices. It misses a growing share of activity, as remote work and personal devices move traffic off the corporate network, and the method has weakened as the perimeter has dissolved.

Ask people. A short, blame-free survey asking teams what tools they use is underrated. People will tell you, if the goal is clearly "get it supported" rather than "get it banned." It sees the context and the why, which no automated method captures. It misses what people forget, and what they would rather not mention.

layering the methods

No single source is complete, so combine the cheap, high-signal ones first and add depth where the risk is. Start with the identity provider and OAuth grants, the best ratio of signal to effort, because it directly shows access, not just presence. Add finance data to catch paid tools outside the directory. Add email or browser discovery to reach the free tiers and personal-account AI that the first two miss. Use a survey to add context and surface the rest. The aim is a layered picture good enough to govern and keep current, rather than a perfect census on day one.

from discovery to governance

A list of discovered tools is the start, not the finish. What turns it into action is a small set of moves. Triage by access, not by name: a tool's risk is mostly about what it can reach, so an app with a read-write OAuth grant into email and files matters more than a standalone utility, regardless of brand. Decide on each one: sanction the useful and safe by bringing them into the inventory and into single sign-on, replace the risky duplicates, and remove the abandoned and the dangerous. Close the access, not just the account: when a tool is removed, revoke its OAuth grants and tokens, because a revoked password leaves an active token in place. And open a sanctioned path, because discovery without a legitimate route for new tools just pushes the next wave further underground; a lightweight intake with a fast yes or no is what keeps shadow IT from rebuilding.

keeping it current

Shadow IT regrows continuously, so a one-time discovery goes stale fast. The thing that works is making it a habit: re-check OAuth grants and new sign-ups on a cadence, fold tool checks into joiner-mover-leaver, and keep the inventory close to live rather than reconstructing it annually. Continuous discovery tooling helps here.

Subscribe to unshadowed.

Subscribe to receive the latest blog posts to your inbox and stay up to date with

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

let's start with a conversation

Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.

Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.

We'll take it from there

Julian Machowski
Head of Technical Sales
+48 783 762 997
julian@unshadowit.com
Let's connect on LinkedIn
Message received. We'll be in touch soon.
Something failed. Try again or call us directly.