What Is Shadow IT? (Definition + Evolution)
Shadow IT is any technology, software, or cloud service used within an organisation without the explicit approval or knowledge of the IT department. It is not a new concept. IT teams have battled unauthorised technology for decades. But the nature of shadow IT has changed dramatically, and the tools your employees are adopting without permission in 2026 look nothing like the rogue servers of 2010.
From rogue servers to rogue SaaS subscriptions
In the early days, shadow IT meant a developer spinning up an unapproved server under a desk or a marketing team buying boxed software with a corporate credit card. Discovery was relatively straightforward: you could physically see the hardware, and software required installation on managed devices.
SaaS changed everything. When any employee with a corporate email and a credit card can sign up for a new tool in under two minutes, the old model of IT gatekeeping collapsed. Today, research shows that 65% of all SaaS applications in a typical organisation are unsanctioned. On the Cledara platform, the average company has 57 known SaaS subscriptions and discovers 20 or more previously unknown ones once they gain proper visibility. That means roughly one in four tools is invisible to IT and Finance before a proper discovery process is in place.
The barrier to entry keeps dropping. Most SaaS products offer free trials or freemium tiers that require nothing more than an email address. By the time a tool generates a charge that Finance might spot, it has already been in use for weeks or months, often with company data inside it. And because SaaS runs entirely in the browser, there is no installation footprint for endpoint management tools to detect.
Shadow AI: the new frontier
The latest evolution is shadow AI. Employees are signing up for ChatGPT, Claude, Midjourney, Cursor, and dozens of other generative AI tools to boost their productivity, often without telling anyone. A Microsoft study found that 75% of knowledge workers already use AI at work, and 78% bring their own tools rather than waiting for IT to provide approved options. Meanwhile, 98% of organisations report some level of unsanctioned AI usage, according to recent industry research.
Shadow AI carries unique risks that traditional shadow SaaS does not. Employees paste proprietary source code, confidential customer data, and internal strategy documents directly into public AI models. Samsung famously discovered engineers uploading trade secrets into ChatGPT. Unlike a rogue project management tool, a single prompt to an unsanctioned AI service can expose your most sensitive intellectual property. And the pace of adoption is staggering: shadow AI usage has increased by as much as 250% year over year in some industries.
For a deeper look at how AI spending is evolving, see our analysis of real AI spending data from the Cledara platform.
Why Shadow IT Is Worse Than You Think
If you suspect your organisation has a shadow IT problem, you are almost certainly underestimating its scale. The average company uses two to three times more SaaS applications than IT knows about. Here is why that matters across three critical dimensions.
Security and data exposure risks
Every unsanctioned application is a potential attack surface that your security team cannot monitor, patch, or protect. Research from OWASP shows that an unsanctioned app increases the probability of sensitive data exposure by 25% compared to a vetted equivalent. Nearly half of all cyberattacks now involve shadow IT in some form, and the average cost to remediate a breach linked to shadow IT is $4.2 million.
The risk multiplies with shadow AI. According to CybSafe and the National Cybersecurity Alliance, 38% of employees share confidential data with AI platforms without any form of approval. Organisations with high levels of shadow AI usage experience breach costs averaging $4.63 million, roughly $670,000 more per breach than those with low or no usage. Each of these interactions creates an uncontrolled data flow outside your security perimeter, with no audit trail, no data loss prevention, and no way to recall the information once it has been submitted.
Shadow IT also undermines your identity and access management strategy. When employees create accounts on unsanctioned tools using corporate email addresses, those accounts persist even after the employee leaves the company. Without visibility into which tools employees have signed up for, your offboarding process has blind spots that leave orphaned accounts (and the company data inside them) exposed indefinitely.
Compliance failures (SOC 2, GDPR, HIPAA)
Compliance frameworks like SOC 2, GDPR, and HIPAA require organisations to maintain an accurate inventory of all systems that process sensitive data. Shadow IT makes this impossible by definition. If you do not know a tool exists, you cannot assess its data handling practices, verify its certifications, or include it in your audit scope.
A single unsanctioned tool processing EU customer data without a proper Data Processing Agreement can trigger GDPR fines of up to 4% of global annual revenue. For companies pursuing or maintaining SOC 2 certification, undiscovered SaaS applications represent a material gap in your control environment that auditors will flag. HIPAA-regulated organisations face even steeper consequences: a shadow IT tool handling protected health information without a Business Associate Agreement can result in fines up to $1.5 million per violation category per year.
The compliance exposure extends to vendor risk as well. Every SaaS tool your employees use is a third-party vendor, and any serious compliance programme requires evaluating each vendor's security posture. Shadow IT creates a parallel universe of unvetted vendors that sit completely outside your vendor risk management process.
Wasted spend on duplicates
Shadow IT is not just a security problem; it is a financial one. When different teams independently purchase tools that solve the same problem (three different project management tools, two video conferencing platforms, four separate file sharing services), the organisation pays multiple times for overlapping functionality. Gartner estimates that 30 to 40% of enterprise IT spending is shadow IT. Even if your company is smaller, the pattern holds: teams buy what they need without checking what already exists, and Finance only discovers the duplication months later when reconciling expenses.
The waste compounds over time. Many SaaS subscriptions auto-renew annually, and without visibility into what employees actually use, you end up paying for tools that were adopted once for a specific project and never cancelled. Application rationalisation, the process of consolidating redundant tools, is impossible until you know the full scope of what exists. This is why shadow IT discovery is a prerequisite for any meaningful SaaS management strategy.
How to Discover Shadow IT in Your Organisation
Discovering shadow IT requires a multi-layered approach. No single method catches everything, but combining these four techniques gives you comprehensive visibility into what your organisation is actually using.
Method 1: Expense report and payment data analysis
This is the most powerful discovery method and the one most organisations overlook. The logic is simple: if a SaaS tool costs money, it leaves a financial trail. Every subscription charged to a corporate card, submitted as an expense claim, or paid via invoice creates a transaction record that you can analyse.
Start by pulling transaction data from your corporate cards, expense management system, and accounts payable records. Search for recurring charges to known SaaS vendors, but also look for unfamiliar merchant names. Many SaaS companies process payments under parent company names or payment processor labels that are not immediately recognisable. A charge from 'Paddle' or 'Stripe' could be any one of hundreds of SaaS products.
Look for patterns: monthly recurring charges between $5 and $500 are the sweet spot for shadow SaaS. Annual charges in the $500 to $5,000 range often indicate team-level purchases that bypassed procurement entirely. Flag anything you cannot immediately identify and investigate the merchant.
Payment-based discovery catches tools that other methods miss entirely. An employee using a personal browser profile will not appear in SSO logs. A tool accessed only on a mobile device will not show up in browser extension data. But if the company is paying for it, the financial record exists. This is why Cledara's approach to shadow IT discovery starts with the payment layer: connect your cards and expense systems, and Cledara automatically flags every SaaS charge against its directory of over 6,000 tools.
Method 2: SSO and browser extension monitoring
Your identity provider (Okta, Azure AD, Google Workspace) already has valuable data about what employees are accessing. Review SSO logs to identify applications that employees authenticate into, then cross-reference that list against your approved software inventory. Any application in the logs that is not on your approved list is shadow IT by definition.
However, SSO data has a significant blind spot: it only captures tools that are configured for single sign-on. Many shadow IT tools, especially freemium apps and personal AI subscriptions, are accessed with standalone credentials that never touch your identity provider. This is where browser extensions fill the gap.
Browser extensions deployed across employee devices track which SaaS domains employees visit during work hours. This catches tools that bypass SSO entirely, including free tools, tools where employees signed up with personal email addresses, and AI services accessed through direct URLs.
Cledara's Engage browser extension works across Chrome, Safari, and Firefox. It tracks only SaaS provider URLs, never browsing history, making it privacy-first by design. When Engage detects an employee using an unapproved tool, it surfaces that information to IT and Finance alongside the usage frequency, giving you data to decide whether to approve, consolidate, or block the tool.
Method 3: Network traffic analysis
For organisations with more mature IT infrastructure, network traffic analysis (via CASB tools or DNS monitoring) can identify connections to cloud services that fall outside your approved list. This method is particularly effective at detecting high-volume data transfers to unknown services, which can indicate sensitive data leaving the organisation through an unsanctioned tool.
The limitation is coverage. With remote and hybrid work now standard, a significant portion of SaaS usage happens on home networks, personal devices, and mobile connections that your network monitoring cannot see. Network traffic analysis is a useful complement to payment and browser-based discovery, but it should not be your primary method unless the majority of your workforce operates on-premises.
Method 4: Employee surveys
Sometimes the simplest approach is the most underrated. Ask your employees what tools they use. A well-designed survey sent quarterly can surface tools that slip through technical detection methods, especially free tools, tools used sporadically, or tools adopted by a single team for a specific workflow.
Frame the survey as collaborative, not punitive. The message should be: 'We want to make sure you have the tools you need and that we are not paying for duplicates.' When employees feel they will be penalised for honesty, surveys produce incomplete data. When they feel heard, you get a surprisingly accurate inventory of what people actually rely on day to day.
The most effective survey includes three questions: What tools do you use daily? What tools did you start using in the last quarter? Are there tools you wish the company provided but does not? The third question is particularly valuable because it reveals unmet needs that are likely to generate future shadow IT.
Managing Shadow IT Without Becoming the Department of No
Discovery is only half the battle. The harder question is what you do with what you find. The worst response to a shadow IT audit is to lock everything down and block every unapproved tool. That approach drives employees to find even more creative workarounds, and it positions IT and Finance as obstacles rather than partners.
A better approach has three elements. First, create a lightweight approval process. Most shadow IT exists because requesting a new tool is harder than just signing up for one. If your approval workflow takes three weeks and four signatures, employees will route around it every time. Build a process that takes hours, not weeks. Cledara's approval flows let you set threshold-based rules: tools under a certain annual cost get fast-tracked with a single approval, while higher-spend tools require dual sign-off from IT and Finance.
Second, evaluate before you eliminate. Some shadow IT is genuinely useful. If three engineering teams independently adopted the same CI/CD tool, that is a signal about an unmet need in your approved stack, not just a compliance violation. Review what you discover with an open mind: consolidate where there is duplication, approve where there is genuine value, and only block tools that pose real security or compliance risks.
Third, make approved alternatives easy to find. Maintain an internal catalogue of approved tools by category. When you decline a shadow IT request, always suggest an approved alternative that solves the same problem. Employees choose unsanctioned tools because they need to get work done; your job is to make the approved path the path of least resistance.
For a detailed framework on building these governance structures, see our guide to SaaS management: why you need it, when to implement it, and the disasters that happen without it.
How Cledara Prevents Shadow IT at the Source
Cledara takes a fundamentally different approach to shadow IT compared to tools that rely solely on network monitoring or SSO integration. Because Cledara controls the payment layer, it catches shadow IT that other platforms cannot see.
Payment-based discovery is Cledara's first line of defence. When you route SaaS purchases through Cledara's virtual cards, every subscription is visible from the moment the first payment is made. Each subscription gets its own virtual card with individual spend limits, so there is granular control from day one. For tools purchased outside this flow (on other corporate cards or as expense claims), Cledara flags the transaction and categorises it automatically against its directory of over 6,000 SaaS applications. If it costs money, Cledara knows about it.
The Engage browser extension adds a second discovery layer. Deployed across Chrome, Safari, and Firefox, Engage tracks which SaaS tools employees actually access, even free tools or tools paid for on personal cards. This is privacy-first: Engage monitors only SaaS provider URLs, never general browsing history. Combined with payment data, this dual approach gives you visibility into both paid and unpaid shadow IT.
For the shadow AI challenge specifically, Cledara's AI Dashboard connects directly to AI provider APIs (OpenAI, Anthropic, Cursor) to track usage-based AI spend with daily visualisation and budgets. Instead of guessing which teams are using generative AI or how much they are spending, you get a real-time view of AI adoption across the organisation. This is the feature that turns shadow AI from an invisible risk into a managed line item.
Once shadow IT is discovered, Cledara's governance features prevent it from recurring. New tool requests go through configurable approval workflows with customisable compliance questionnaires before any payment is issued. These questionnaires can include sections for business case justification, risk assessment, and exit planning, so every new tool is evaluated against your organisation's standards before it enters the stack.
Because Cledara issues a unique virtual card per subscription, cancellation is instant: freeze the card, and the subscription cannot renew. No emails to vendors, no waiting for contract terms, no forgotten renewals. Combined with automated onboarding and offboarding workflows that integrate with your HRIS, Cledara closes the full lifecycle loop: discover what exists, evaluate what stays, govern what comes next, and cancel what is no longer needed.
That is the complete SaaS lifecycle on a single platform: Discover, Buy, Manage, Cancel. Built for finance. Trusted by IT.




