5 Signs Your Organisation Has a Shadow IT Problem
Governance
All articles
9 June 2026 5 min read0 comments

5 Signs Your Organisation Has a Shadow IT Problem

Shadow IT rarely announces itself. These are the patterns that indicate unsanctioned app adoption is quietly growing.

Shadow IT is by definition invisible to the people responsible for managing it. But it does leave traces. Here are five signals that indicate the problem is larger than your official software list suggests.

1. Your expense reports contain software line items IT doesn't recognise

Employees buying SaaS tools on personal cards and expensing them is the most common shadow IT vector. If your finance team doesn't have a process to flag software expenses for IT review, you're flying blind on a significant portion of your software estate.

2. You discover tools during offboarding that aren't in your inventory

When an employee leaves and their manager asks "what about their [tool name] account?" — and IT has never heard of that tool — that's shadow IT surfacing at the worst possible moment.

3. Multiple teams are paying for different tools that do the same thing

Project management tools are the classic example: one team uses Asana, another uses Monday.com, a third uses Notion. When consolidation discussions reveal these overlaps, it's usually because each team adopted their tool independently without visibility into what others were using.

4. Your SSO logs show OAuth connections to tools not in your sanctioned list

Every time an employee clicks "Sign in with Google" or "Sign in with Microsoft" for an app, it appears in your identity provider's audit logs. If you've never reviewed those logs against your approved software list, you may be surprised by what you find.

5. Your SaaS spend is growing faster than headcount

Average SaaS spend per employee grows year on year. But if your per-employee spend is outpacing industry benchmarks, unsanctioned purchasing is frequently the culprit.

What to Do If You Recognise These Signs

Recognition is the first step; the second step is a structured discovery exercise, not an immediate crackdown. Start by running a 90-day SSO audit log analysis to identify every application where employees have authenticated with their corporate identity. Cross-reference against your approved software list. Everything not on the list is a discovery candidate that needs classification and assessment.

Simultaneously, work with Finance to export the last 12 months of expense claims and corporate card transactions filtered for software-related categories. The combination of SSO data and financial data gives you two complementary views — SSO catches tools adopted through identity federation, financial data catches tools paid for with money. Together they cover the majority of your shadow IT estate.

Creating a Self-Reporting Culture

The most sustainable shadow IT management approach is one where employees feel comfortable reporting the tools they use without fear of immediate access loss. Publish a simple intake process — a link, a form, or a dedicated Slack channel — where employees can flag tools they're using that aren't officially approved. Commit to a fast review SLA (48 hours for low-risk tools) and communicate that the goal is assessment, not punishment.

When employees experience the intake process as fast and fair, they use it. When the answer to "I need this tool" is a three-week approval process with an uncertain outcome, they bypass it. The cultural shift from shadow IT avoidance to collaborative governance is one of the most valuable outcomes of a well-run SaaS management programme.

Preventing Recurrence

Shadow IT is not a problem you solve once and forget. The underlying drivers — employee need, tool availability, and procurement friction — don't go away. Prevention requires an ongoing combination of: a fast enough approval process that employees don't need to bypass it, regular discovery cycles that catch new tools as they emerge, and a software catalogue of pre-approved tools that employees can adopt immediately without any approval process. A well-populated software catalogue, covering the most common tool categories, is often the highest-impact single intervention for reducing shadow IT in the medium term.

Share X / Twitter LinkedIn

See Liceo in action

Track every licence, cut waste, and automate renewals — in one platform.

Discussion

Comments are moderated before appearing publicly.

No comments yet. Be the first to share your thoughts.

Leave a comment

Not published. Used for moderation only.

0/3000 characters

Ronke

Liceo product guide · AI assistant

Hi, I'm Ronke, Liceo's product guide. I can help you understand how we bring licence, vendor, and spend visibility together, or walk through plans and integrations. What are you trying to solve today?

Ronke shares verified product info only. For custom quotes or contracts, book a demo.