IT operating model

Shadow IT: what to shut down, and what to adopt

Most shadow IT is a business team solving a real problem faster than the official route would have. Some of it is worth keeping.

Updated September 2026

The short version
  • Shadow IT is a symptom. If the official route were fast enough, most of it would not exist.
  • Assess on risk and dependency, not on who bought it. Some of it is better than the sanctioned alternative.
  • The dangerous ones hold personal or financial data, or have become a system of record without a backup.
  • Amnesty first, then a fast intake. Enforcement without a better route just pushes it further underground.

Shadow IT gets discussed as a compliance failure. It is more useful to read it as feedback: every instance is a team that had a problem, looked at the official route, and decided going around it was worth the trouble.

Find it before judging it

Four places account for most of what is running:

  • Expense claims and credit card statements. Subscriptions below the procurement threshold.
  • Identity logs. Sign-ins to services nobody procured, visible in your identity provider.
  • The tenant itself. Flows, apps and automations built in platforms you already own, often running under a personal account.
  • Spreadsheets with a process wrapped around them. The largest category by far, and the least likely to be recognized as a system.

Assess on risk, not on ownership

The question is not who bought it. It is what happens if it stops, leaks, or the person who built it leaves. Four things to check on each:

What data is in it? Personal information, financial data, or anything with a contractual confidentiality obligation moves this to the top of the list.

Is it a system of record? If it holds the only copy of something, backup and continuity become immediate questions regardless of anything else.

What depends on it? A tool one person uses is different from one feeding a report the executive team reads.

Who can maintain it? One author, no documentation, and no second person who understands it is the most common failure mode.

Four outcomes, not one

Adopt. It works, the risk is manageable, and replacing it would be worse. Bring it into support, sort out the licensing and the ownership, and leave it alone. This happens more often than IT departments expect.

Replace. Something the organization already owns does this job. Migrate, and mean it — announcing a replacement without doing the migration is how you end up with both.

Contain. It stays, with limits: no new users, no more data, a plan to exit. Appropriate where the risk is tolerable but the direction is wrong.

Stop. The risk is not acceptable. This should be rare, and it needs a genuine alternative offered at the same time.

Amnesty before enforcement

Nobody surfaces a tool if doing so gets a team into trouble. A one-time amnesty — tell us what you are running, nothing happens to you — gets a far more complete picture than any discovery scan.

Then make the official route faster

If the intake process takes weeks and building it themselves takes days, shadow IT returns immediately and more carefully hidden. The durable fix is a route that gives a yes, a no, or a date quickly — plus a sanctioned way for business teams to build small things safely, inside an environment strategy and a data policy, rather than a blanket prohibition nobody can enforce.

Want to know what is actually running?

We will find it, rank it on risk, and tell you what to adopt, replace or stop.