TL;DR: Shadow IT grows when employees buy SaaS outside IT, leaving no reliable visibility into app use, access, or offboarding, according to Zluri’s analysis of discovery and SaaS management tools. The governance problem is not just software sprawl, but unmanaged identity sprawl across apps, licenses, and entitlements.
At a glance
What this is: This is a vendor analysis arguing that shadow IT is really a SaaS identity governance problem, because discovery, access visibility, and offboarding break down together.
Why it matters: It matters because IAM, IGA, and SaaS governance teams need to treat app discovery as an identity lifecycle issue, not just a software inventory exercise.
Context
Shadow IT becomes a governance problem when software can be bought and used outside approved identity and procurement workflows. In that condition, organisations lose the ability to see who has access, which entitlements were granted, and whether access ends when it should.
For SaaS-heavy environments, the issue is not only unknown applications. It is unmanaged access across applications, licenses, and user lifecycles, which makes offboarding, auditability, and entitlement control materially harder.
The article argues that discovery tooling only solves part of the problem unless it connects app inventory to identity state, usage, and termination. That is a typical failure mode in modern SaaS sprawl.
Key questions
Q: What breaks when shadow IT sits outside identity governance controls?
A: Access reviews, offboarding, and privileged approval workflows lose reliability when shadow IT is outside the system of record. The main failure is not the existence of extra tools, but the inability to inventory, classify, and revoke the identities and entitlements tied to them. That leaves unmanaged access in place even when governance activity appears to be working.
Q: Why do shadow IT apps create identity and spend risk at the same time?
A: Shadow IT creates two problems at once. First, it hides recurring cost and duplicate licensing. Second, it creates accounts, tokens, and delegated access that may never be reviewed or revoked. When the application is invisible to governance, the identities attached to it are usually invisible as well, which turns a finance issue into an access-control problem.
Q: How do teams know when SaaS discovery is producing actionable results?
A: They should look for a catalog that is both broad and clean, with accepted applications carrying enough metadata to support policy and licensing actions. If enrichment is missing or false positives remain high, discovery has produced volume but not governance value.
Q: What should organisations do when shadow IT is already widespread across departments?
A: When shadow IT is widespread, organisations should establish a governance framework that defines approved software, procurement rules, usage expectations, and decommissioning steps. They should pair that policy with continuous discovery, employee education, and centralised SaaS management so shadow usage can be reduced without blocking legitimate productivity needs.
Technical breakdown
Why SaaS discovery depends on identity signals
SaaS discovery is not just asset inventory. Effective discovery joins SSO, identity providers, finance records, direct app integrations, and sometimes browser or endpoint signals to infer what is actually in use. The technical problem is that no single source sees the full picture: SSO shows sanctioned access, expense data reveals shadow purchases, and app-level integrations expose usage and entitlement state. Discovery becomes governance only when those signals are normalised into a single identity-linked view of apps, users, and permissions.
Practical implication: Treat discovery projects as identity correlation problems, not standalone inventory tasks.
Why access visibility and license visibility are linked
A SaaS application can be known to the organisation without being governed. The article highlights a distinction between app presence, active usage, license tier, and access level. Those are different data planes, and governance breaks when teams can see one but not the others. In practice, that means an application may be budgeted, licensed, and even audited, while the real question of who can log in and with what privilege remains unresolved.
Practical implication: Map application ownership to access and entitlement data, not just purchase and renewal records.
How offboarding fails when SaaS access is not lifecycle-managed
Offboarding is the point where shadow IT becomes identity risk. If a user leaves and their SaaS accounts are not discovered, deprovisioned, or reviewed, access outlives employment or business need. That creates dormant entitlements, audit gaps, and unmanaged exposure across third-party services. The article's point is that discovery is useful only when it feeds lifecycle actions such as onboarding and offboarding across the SaaS estate.
Practical implication: Bind offboarding workflows to discovered SaaS accounts and revoke access outside authoritative HR and IAM signals.
NHI Mgmt Group analysis
Shadow IT is fundamentally a SaaS identity governance failure, not a discovery failure. Discovery matters, but only because it is the entry point to governing access, entitlements, and lifecycle state across SaaS applications. If the organisation can inventory apps but cannot connect them to identities and offboarding, the core control problem remains unresolved. Practitioners should treat discovery as the first step in SaaS governance, not the endpoint.
App visibility without entitlement visibility creates false confidence. Knowing that an application exists is not the same as knowing who can use it, what they can do, or whether that access is still justified. That gap is where audit risk and excess privilege accumulate. Identity teams should require app-level access and license data to sit inside the governance model, not beside it.
Lifecycle controls are the difference between tolerated sprawl and unmanaged exposure. The article shows that onboarding and offboarding are not administrative add-ons. They are the mechanism that turns discovery into enforceable identity control across the SaaS estate. Without lifecycle coupling, every discovered app becomes a potential blind spot the next time a user moves or leaves.
Shadow IT discovery is really identity surface mapping. The useful question is not how many applications exist, but which identities can reach them and whether those identities are still legitimate. That framing aligns discovery with IGA, PAM-adjacent access review, and SaaS lifecycle governance. Teams should measure the identity surface, not just the application count.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Read next: NHI Lifecycle Management Guide
What this signals
Identity surface mapping: Shadow IT programmes should be measured by how well they connect discovered applications to identity state, not by raw application counts. When discovery is linked to onboarding and offboarding, it becomes a control for reducing SaaS exposure rather than a reporting exercise.
The governance question for practitioners is whether app discovery changes entitlements, licence decisions, and termination workflows. If it does not, the organisation still has an inventory problem disguised as a control programme.
For practitioners
- Link SaaS discovery to authoritative identity sources Correlate SSO, identity provider, finance, and direct app integration signals so discovered applications are tied to named users and access state.
- Build offboarding around discovered SaaS accounts Make deprovisioning a required output of discovery so a departing user cannot keep access to unsanctioned or forgotten SaaS services.
- Reconcile licenses against real usage and access Compare allocated licenses, active logins, and permission tiers to find abandoned subscriptions, unused seats, and overbroad access.
- Use discovery data to prove audit readiness Keep records of application ownership, access level, and termination actions so compliance teams can answer who had access and when it ended.
Key takeaways
- Shadow IT becomes dangerous when SaaS usage escapes identity governance, because access and offboarding cannot be reliably enforced across the estate.
- The article frames discovery as a correlation problem that joins app presence, identity data, licence state, and usage evidence.
- Practitioners should connect discovery outputs to deprovisioning, licence reconciliation, and audit evidence if they want governance rather than visibility alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Shadow IT becomes a governance gap when discovered SaaS accounts are not removed at leaver time. |
| NHI-05 — Overprivileged NHI | Shadow IT often hides excessive SaaS access that is never reviewed or right-sized. | |
| Recommendation — Tie discovery outputs to offboarding so undiscovered SaaS access is revoked when users leave. Review discovered SaaS entitlements and remove privileges that are not justified by current business need. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | This article centres on who can access SaaS apps and whether those permissions are governed. |
| Recommendation — Align SaaS discovery with PR.AA-05 so access permissions and entitlements are continuously governed. | ||
| CIS Controls v8 | CIS-5 — Account Management | Shadow IT governance depends on managing accounts across SaaS applications and leaver workflows. |
| Recommendation — Use CIS-5 to inventory SaaS accounts and remove stale or unauthorised access paths. | ||
Key terms
- Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
- SaaS Identity Risk: SaaS identity risk is the chance that identities used to access software delivered over the internet are misused, overprivileged, or poorly governed. It includes human users, service accounts, API tokens, and connected apps. Technical risk arises when authentication, authorization, lifecycle control, or monitoring fails across tenant, application, and integration boundaries.
- Off-boarding: Off-boarding is the process of removing a departing user’s access, credentials, and related entitlements from the environment. In mature IAM programmes, it also includes reviewing sessions, shared secrets, delegated roles, and linked non-human identities so that exit events do not leave behind hidden access paths.
- Entitlement review: A governance process that checks whether users, service accounts or systems still need their access. For modern identity programmes, the limitation is timing: if reviews happen too late or too rarely, access may already have been misused before the review occurs.
Deepen your knowledge
NHI governance, identity lifecycle management, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org