Last verified April 2026
How to detect shadow IT
Four methods to discover shadow IT in your organization
Each method has a blind spot. Combining them gets you to most of the portfolio. This page compares effort, coverage, and blind spots so you can sequence the work.
Why one method is never enough
Every discovery method covers a subset of the shadow IT footprint. SSO-based approaches see what connects to your IdP. Financial approaches see what leaves a payment trail. Network approaches see what transits your managed egress. Survey approaches see what employees will tell you. The portfolio you want to catalogue sits in the intersection of all of these plus what falls outside each.
Combined, the four methods below typically yield 80 to 95 percent of the visible app portfolio. That 80 to 95 percent figure is a methodological estimate from practitioner experience across discovery sprints, not a measurement from a peer-reviewed study. Apply it as order-of-magnitude guidance.
Comparison table
| Method | What it covers | Effort | Coverage estimate | Primary blind spot |
|---|---|---|---|---|
| SSO gap analysis | Apps connected to your IdP (Okta, Entra ID, Google Workspace) | Low (half-day) | 40 to 70 percent | Apps not using SSO at all, personal browser logins |
| Expense audit | Paid apps that leave a financial trail (corporate card, expense reports, vendor invoices) | Low to medium (one week) | 30 to 60 percent | Free-tier apps, personal-card spend never reimbursed, annual billing in unexpected categories |
| CASB and network analysis | SaaS traffic observed from managed devices or network egress points | Medium to high (weeks to months; tool deployment) | 60 to 85 percent on managed devices | Personal device access, home-network usage, privacy-compliant logging constraints |
| Browser inventory + employee survey | Browser extensions, local app use, and honest disclosure of tools | Medium (two to four weeks, includes survey wave) | 20 to 50 percent incremental over the above | Response bias in surveys, personal-device browsing, tools actively being hidden |
Coverage estimates are practitioner heuristics from discovery sprints, not measured figures. Individual results vary by SSO adoption, device management posture, finance system completeness, and survey response rate.
Method summaries
SSO gap analysis
Apps connected to your IdP (Okta, Entra ID, Google Workspace)
Method detail ->
Expense audit
Paid apps that leave a financial trail (corporate card, expense reports, vendor invoices)
Method detail ->
CASB and network analysis
SaaS traffic observed from managed devices or network egress points
Method detail ->
Browser inventory + employee survey
Browser extensions, local app use, and honest disclosure of tools
Method detail ->
Four-week discovery sprint sequencing
- Week 1: SSO gap analysis. Export IdP app lists, compare against approved catalog, build baseline.
- Week 2: Expense audit. Pull 12 months of expense report and corporate card data, filter for SaaS merchants, merge with SSO gap baseline.
- Week 3: Browser inventory plus amnesty survey. Deploy extension inventory via MDM, launch short amnesty-framed survey.
- Week 4: Consolidation. Merge findings, assign owners and data classifications, write the disposition for each app (approve, consolidate, retire, require controls). CASB or network analysis typically follows as an ongoing capability rather than a sprint deliverable.
The output: a consolidated shadow app registry
The deliverable at the end of the sprint is a single spreadsheet with one row per shadow app and the following columns. Every row should trace back to evidence from at least one of the four methods.
| App name | Category | Detected by | Users | Department | Data class | Annual spend | Action |
|---|---|---|---|---|---|---|---|
| Notion | Productivity | SSO + expense | 42 | Product, Eng | Confidential | $7,560 | Approve, add to catalog |
| Loom | Video | Survey only | ~80 | Multi | Confidential | Unknown | Consolidate |
| ChatGPT team | AI | Expense + browser | 15 | Marketing | Confidential | $5,400 | Require controls |
Tool categories
CASB vs SaaS management platform ->
Cost the findings
Measure your exposure ->