On this page
› Why Employees Bypass IT in the First Place
| What’s Driving It | What It Looks Like | What It Should Infer |
| Slow approval cycles | The team waits for weeks to get a simple scheduling, reporting, or file tool | Your approval timeline doesn’t match the urgency of the team |
| Poor tool fit | Employees have an enterprise license but use the niche alternative | The approved tool stack doesn’t fit their workflow or team needs |
| Unclear ownership | Nobody knows who approves a new software or what evidence they need | You have a hard-to-find and harder-to-navigate request process |
| Consumer-style buying | A free trial or even a browser extension takes a few minutes to activate | Procurement is competing with self-service checkout experiences. These two cannot match on speed |
| Tool fragmentation | Different teams inherited different systems after growth or acquisition | Your software inventory didn’t keep pace with the organisation |
| AI feature urgency | Teams adopt AI tools to write, analyse, summarise, and automate their work | You don’t have a clear AI adoption or data-use policy |

› The Real Risk Is Unmanaged Access
| Risk Layer | What Can Happen | CIO Question | Example |
| Data exposure | Staff uploads contracts, product plans, customer lists, and even internal reports | What business data is entering the tool? | A team uploads the customer spreadsheet to an unapproved AI tool |
| Identity and OAuth permissions | The app is granted access to files, calendars, emails, contacts, and collaboration platforms | What did A actually authorise the app to do? | A browser-based tool is provided with read access to a shared drive |
| Account ownership | The account is tied to your employee’s work and personal email as well as their personal payment method | Could the company recover this account tomorrow if it had to? | A departing employee is the sole administrator of the project workspace |
| Offboarding and retention | Access, data, API tokens, and integrations outlive the person/project | How can access be revoked and who is responsible? | An inactive account will hold live company files |
| Compliance and vendor risks | Provider hasn’t been checked against data, privacy, retention, security, or contractor requirements | Does the vendor meet the benchmark for this kind of data? | Regulated records are stored in a tool with no formal agreement |
| Financial duplication | Separate teams are paying for overlapping products that in turn perform the same job | Are we already paying for this capability elsewhere? | Three teams are subscribing to different survey platforms. |
| Operational dependency | A business-critical workflow quietly depends on an employee’s unowned and undocumented account | What breaks if this account disappears? | A recurring client-report automation that’s owned by one employee and has no documentation |

› The Four-Outcome Triage Model
| Outcome | When It Applies | IT Action | Employee Experience |
| Approve and govern | The tool meets your legitimate business need and even passes security, privacy, and ownership | Assign a business owner. Configure SSO wherever possible, and document permitted data use. Also establish renewal and offboarding controls | The team gets to keep the tool with clear guardrails |
| Fast-track with Conditions | Your team has an urgent need and full review hasn’t been completed yet | Limit permissions to access data, restrict the number of users or integrations, and set a review deadline. Define temporary safeguards | A controlled interim option instead of an incentive to go further underground |
| Replace | The use case is valid, but the specific tool doesn’t meet the organization’s needs. | Recommend an approved or comparable alternative that will solve underlying workflow issues | Their problem is solved |
| Contain or Remove | Exposure is unacceptable, required controls unavailable, and no accountable owner is identified | Revoke access, migrate or delete data where appropriate, communicate the reasons, and provide next steps | Clear explanation and replacement path is available |
| Decision Dimension | Questions to Ask |
| Business value | What problem does this solve, how urgent is it, and how many people depend on it? |
| Data sensitivity | What information does it process? Is it public, internal, confidential, customer, financial, or regulated data? |
| Identity access | Does it use corporate login, OAuth permissions, API tokens, service accounts, or administrator consent? |
| Vendor confidence | Does the vendor meet the organisation’s requirements for privacy, security, support and contractual protections? |
| Ownership | Is there a named business and technical owner along with a workable plan for renewals, access removal or offboarding? |

› Shadow IT Risks and Solutions: A Governance System People Can Actually Use
| Governance Layer | What to Build | Why It Works |
| Continuous discovery | Combine SSO logs, OAuth consent records, expense data, procurement data, and other available signals. Don’t restrict to an annual audit. | No single source reveals every app. But together, these signals create a more accurate picture of the SaaS management software your teams are using |
| A visible catalogue | Publish all approved tools by their business use case along with product name and IT category | Employees will find a safe option without having to understand the internal approval process |
| A fast request path | Create a short intake form, published Review timelines, and clear risk tiers | Predictable route reduces the incentive to self-provision software |
| Risk-based review | It prioritises assessment according to data sensitivity, identity access, business value, and integrations ownership | IT spends review time where operational dependency and exposure are the highest. |
| Lifecycle ownership | Assign responsibility for renewals, access reviews, data retention, and administration access | Tools don’t outlive your employees, projects, and business needs |
- The number of newly discovered unapproved apps trends down over time
- The time from software request to low-risk approval decision is shorter
- Fewer teams request the same unmet capabilities repeatedly. This indicates the approved catalogue is widely useful.
