By NHI Mgmt Group Editorial TeamBased on Josys: “How MSPs Can Tackle Shadow IT” (August 8, 2025)

TL;DR: Shadow IT remains a governance problem because employees adopt unapproved SaaS tools faster than IT can inventory, review, and retire them, while MSPs can centralise discovery, controls, and lifecycle workflows, according to Josys. The real issue is not just visibility, but whether access, approval, and offboarding processes can keep pace with unsanctioned usage.


At a glance

What this is: This is a Josys analysis of how MSPs can govern shadow IT through discovery, policy controls, and SaaS lifecycle workflows.

Why it matters: It matters because identity and access teams need a repeatable way to discover unsanctioned apps, constrain access, and retire them before they become compliance and data exposure problems.

By the numbers:

  • One MSP managing 50 client environments identified 30% more SaaS tools than initially known.

Context

Shadow IT is a governance problem when app adoption happens outside approved intake, access, and offboarding processes. In MSP-managed environments, the issue is not only visibility into who is using which tools, but whether those tools are ever brought under policy, lifecycle control, and review.

For identity teams, that makes shadow IT a SaaS governance and lifecycle issue, not just a discovery exercise. The article frames MSPs as the operating layer that can connect application discovery, approval workflows, and retirement actions across multiple client environments.


Key questions

Q: How should MSPs discover shadow IT across client environments?

A: MSPs should use multiple discovery sources, including traffic scanning, SSO telemetry, finance records, and application inventories. A single control rarely finds everything. The goal is to build a tenant-level view that shows usage, ownership, and approval status so hidden software can be assessed consistently across clients.

Q: What happens when shadow SaaS is found but not lifecycle-managed?

A: When shadow SaaS is discovered but not lifecycle-managed, the organisation gains visibility without control. The app can continue to hold active accounts, consume licenses, move data, and remain outside review cycles, which leaves compliance gaps and makes later remediation slower and more disruptive.

Q: How do organisations know whether shadow IT controls are actually working?

A: They should look for shrinking gaps between discovered apps and remediated access, not just a larger inventory. Useful signals include fewer unmanaged sign-ins, lower numbers of abandoned licenses, faster removal of unknown admins, and better alignment between expense data and authorised application records.

Q: What is the difference between discovering shadow IT and governing it?

A: Discovery tells you which SaaS tools exist and who is using them. Governance adds policy, access control, lifecycle ownership, and offboarding so the organisation can decide which apps stay, which are restricted, and which are removed entirely.


Technical breakdown

How MSPs discover shadow IT across client environments

Shadow IT discovery depends on combining multiple telemetry sources, because no single control sees every SaaS app. Josys describes traffic scanning, SSO data pulls, and finance system insights as complementary inputs that reveal both sanctioned and unsanctioned applications. That matters because one source shows intent, another shows authentication activity, and a third may reveal subscription spend or shadow procurement. The technical pattern is a reconciled inventory, not a single feed. Once those data sources are normalised, MSPs can classify applications by function, risk, and compliance status rather than treating all unknown apps the same.

Practical implication: Use multiple discovery sources together so unsanctioned SaaS does not stay hidden behind one blind spot.

Why lifecycle automation matters more than one-time app discovery

Discovery only identifies the problem; lifecycle control changes the risk profile. The article shows that onboarding can create accounts, assign licenses, apply security settings, and integrate systems, while offboarding should back up data, revoke access, and recover licenses. In practice, this is where shadow IT becomes governable: an app that is known but unmanaged still creates access and compliance exposure. Lifecycle automation also reduces manual error, which is especially important when MSPs manage many clients at once. The control plane is therefore not just inventory, but repeatable joiner, mover, and leaver actions for SaaS.

Practical implication: Automate onboarding and offboarding steps so discovered apps can be governed instead of merely recorded.

How guardrails turn app usage into policy enforcement

Guardrails are the layer that converts visibility into enforceable standards. Josys describes monitoring user behavior, defining approval paths, and conducting periodic reviews so MSPs can intervene before unauthorized usage becomes entrenched. This is governance by exception handling: approved apps flow through standard controls, while unapproved or high-risk apps trigger review and remediation. The value is not only risk reduction, but also clearer accountability across the MSP-client boundary, because policy decisions become visible and repeatable. Without that layer, discovery reports tend to accumulate while access decisions remain ad hoc.

Practical implication: Tie discovery findings to approval paths and periodic reviews so usage is governed, not just observed.


Threat narrative

Attacker objective: The objective is not a single intrusion but the creation of unmanaged application access that weakens governance and exposes data and compliance posture.

  1. Entry occurs when employees adopt unapproved SaaS tools outside the approved intake process, often to move faster than central IT can respond.
  2. Credential and access risk grows when those apps are connected to corporate identities, licenses, or data flows without formal lifecycle control.
  3. Impact follows when hidden apps create compliance violations, data exposure, and unmanaged access paths that the organisation cannot easily retire or review.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Shadow IT is really a lifecycle governance problem disguised as a visibility problem. Discovery matters, but discovery alone does not remove risk if the organisation cannot approve, constrain, review, and retire applications with the same discipline it applies to identities. The article’s MSP framing is useful because it shows that app sprawl becomes manageable only when governance owns the full lifecycle. The practitioner conclusion is simple: inventory without lifecycle control is an incomplete control.

Managed Service Providers become most valuable when they connect control points that enterprises usually keep separate. The useful pattern is not just monitoring, but linking discovery, policy approval, security configuration, and offboarding into one operating model. That reduces the gap between seeing an unsanctioned app and actually ending its risk. In identity terms, MSPs are acting as the orchestration layer for SaaS governance, and that is where repeatability matters most.

Shadow app sprawl exposes a persistent assumption that users will stay inside approved software paths. That assumption was designed for centralised IT environments with slower adoption and stronger enforcement boundaries. It fails when users can onboard SaaS in minutes, route around procurement, and bind business workflows to unapproved tools before governance sees them. The implication is that approval cadence, not just inventory quality, becomes the decisive control variable.

Controlled SaaS adoption is becoming an identity governance discipline, not a service desk function. Once a tool touches authentication, licensing, data transfer, or revocation, it sits inside the identity perimeter whether IT approved it or not. That means MSPs and IAM leads need shared ownership of app governance rather than separate reporting lines. The practical conclusion is to treat SaaS lifecycle as part of identity operations, not as a shadow problem at the edge.

Discovery metrics should be measured against remediation, not just completeness. A larger inventory is useful only if each newly found app can be assigned an owner, risk tier, and lifecycle outcome. The article’s examples show that the operational win is fewer unknowns and faster onboarding or offboarding, not raw tool count. Practitioners should judge success by how quickly shadow usage becomes governed usage.

From our research library:

What this signals

Shadow IT governance becomes materially stronger when discovery is tied to an offboarding path. The operational failure is not finding an unsanctioned app, but leaving it active after it has been found. For MSPs, that means the programme must measure time-to-owner and time-to-retire, not just inventory completeness.

SaaS visibility without identity lifecycle control creates a false sense of coverage. Once application access is tied to accounts, licenses, and data flows, governance has to follow the app through its full life. The practical signal for teams is whether every new app can be converted from unknown usage into approved or removed status quickly and consistently.


For practitioners

  • Build a multi-source SaaS discovery baseline Combine traffic scanning, SSO data, and finance system records to produce one reconciled view of sanctioned and unsanctioned applications.
  • Attach every discovered app to a lifecycle owner Require an owner, risk tier, and approval path for each application so discovery always leads to a governance decision.
  • Automate SaaS onboarding and offboarding steps Standardise account creation, license assignment, security configuration, data backup, access revocation, and license recovery.
  • Turn shadow IT reviews into recurring governance Use periodic reviews to reassess approved tools, remove unused apps, and confirm that high-risk usage has been retired.

Key takeaways

  • Shadow IT becomes a governance exposure when unapproved SaaS escapes normal approval and retirement controls.
  • The article shows that MSPs can find more hidden applications, but discovery only matters when it feeds ownership and offboarding.
  • Practitioners should measure success by how reliably discovered apps move into approval, restriction, or retirement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIShadow IT often enters through third-party SaaS and unmanaged integrations.
NHI-01 — Improper OffboardingThe article emphasises retiring apps, revoking access, and recovering licenses.
NHI-05 — Overprivileged NHIShadow apps frequently accumulate access that exceeds what business use requires.
Recommendation — Map unsanctioned SaaS and delegated access paths to NHI-03 and review third-party app trust before approval. Apply NHI-01 to ensure every SaaS app has a defined offboarding path for accounts, data, and licenses. Limit app permissions to the minimum needed and periodically revalidate access against actual usage.
CIS Controls v8CIS-5 — Account ManagementAccount provisioning and revocation are central to SaaS lifecycle governance.
Recommendation — Use account management controls to inventory SaaS users, revoke stale access, and standardise offboarding.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on governing permissions and approvals for SaaS usage.
Recommendation — Review SaaS entitlements regularly and align approvals, access, and retirement to PR.AA-05.

Key terms

  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • SaaS Lifecycle Automation: SaaS lifecycle automation is the use of workflows to manage application discovery, onboarding, offboarding, access changes, renewals, and license optimization. It helps IT and procurement teams reduce manual effort and improve control over the application estate. The focus is operational efficiency, not direct data loss prevention.
  • Application Discovery: Application discovery is the process of identifying which software and services are actually in use, including unsanctioned or shadow applications. In lifecycle governance, it helps teams align access decisions with the real application estate instead of relying only on a static catalogue.
  • Off-boarding: Off-boarding is the process of removing a departing user’s access, credentials, and related entitlements from the environment. In mature IAM programmes, it also includes reviewing sessions, shared secrets, delegated roles, and linked non-human identities so that exit events do not leave behind hidden access paths.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org