Join our Newsletter — 33% off our NHI Course

Shadow SaaS governance: what should IAM teams do now?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Shadow IT is not the core problem in 1Password’s analysis of SaaS Manager; the real issue is unmanaged SaaS adoption leaving 34% of applications outside SSO and creating compliance, data governance, and lifecycle blind spots. The practical lesson is that business-led IT only works when discovery, access review, and offboarding are treated as governance controls, not optional cleanup.

Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “How IT teams can get a handle on shadow IT”.

By the numbers:

  • 34% of applications sit outside of the company’s SSO, according to 1Password.

Key questions

Q: What breaks when SaaS is adopted outside approved governance processes?

A: When SaaS is adopted outside approved governance processes, organisations lose the connection between application ownership, user access, and renewal accountability.

Q: Why do unmanaged SaaS applications create risk for sensitive data and compliance programs?

A: Unmanaged SaaS creates risk because security teams lose control over where data lives, who can access it, and whether the application meets internal and regulatory requirements.

Q: How can teams tell whether SaaS governance is actually working?

A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow.

Practitioner guidance

  • Build continuous SaaS discovery into identity governance Continuously inventory applications in use, compare them to approved platforms, and flag anything that has entered the environment without a managed workflow.
  • Standardise app ownership and approval criteria Require each business application to have a named owner, a documented purpose, and a decision path for whether it should be approved, restricted, or retired.
  • Tie access reviews to the managed app inventory Move review cycles from ad hoc spreadsheets into the inventory process so unmanaged applications cannot bypass recertification or renewal checks.

Bottom line: Unmanaged SaaS is best understood as a governance gap, not simply an unsanctioned software problem.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 23 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Shadow SaaS is an identity governance problem before it is an IT preference problem. The article correctly treats business-led adoption as a durable operating reality, not a temporary exception. Once applications are adopted outside central oversight, the identity programme loses the ability to govern authentication, ownership, and offboarding on standard terms. The practitioner conclusion is clear: unmanaged SaaS must be treated as part of the identity estate, not as an exception outside it.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: How do organisations know whether shadow SaaS is actually under control?

A: They should be able to show a current inventory of SaaS apps, the identities using them, the data they hold, and the owner responsible for offboarding and renewal. If any of those four elements is missing, the programme still has blind spots. Control exists only when discovery, ownership, and lifecycle actions are connected.

👉 Read our full editorial: Business-led IT and shadow SaaS: governance gaps to close


This post was modified 23 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.