SSO helps centralise authentication, but it does not solve every risk in shadow apps. If a team uses an unapproved application, security may still lack visibility into data access, over-privileged permissions, exposed secrets, and unmanaged third-party integrations. Effective control requires identity governance, secrets protection, and monitoring around the application itself, not just the login layer.
Why This Matters for Security Teams
SSO creates a single front door, but shadow apps rarely fail at the login layer. They fail in the places SSO does not govern well: application permissions, hidden service accounts, embedded secrets, third-party integrations, and data sharing after sign-in. That means a user can authenticate cleanly while the app still exfiltrates data, connects to unreviewed services, or stores credentials outside approved controls. The Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, which is a useful proxy for how often the real risk sits outside the identity provider.
The practical problem is governance drift. Security teams may assume SSO equals control, while the business treats the app as approved because it appears behind a central login. Current guidance from the NIST Cybersecurity Framework 2.0 points toward broader asset, identity, and data governance rather than authentication alone. In practice, many security teams encounter shadow app exposure only after a data-sharing workflow, token leak, or vendor integration has already expanded access beyond what SSO can see.
How It Works in Practice
When organisations rely on SSO alone, they protect the interactive login but leave the application lifecycle largely ungoverned. A shadow app can still collect data, create API tokens, connect to SaaS plugins, and grant persistent access to service accounts. SSO may confirm who signed in, but it does not answer what the app can do after authentication, what secrets it stores, or which downstream systems it can reach.
That is why identity governance for shadow apps has to include the application itself. The control model should combine:
- Application discovery, so unsanctioned apps are identified before they become business critical.
- Secrets inventory and rotation, because a clean SSO session does not protect long-lived API keys or embedded tokens.
- Permission review, so over-privileged app roles are reduced to the minimum needed for the workflow.
- Logging and anomaly detection, so data movement, new integrations, and unusual permission grants are visible after sign-in.
- Offboarding controls, so access is revoked when the app is retired, replaced, or no longer supported.
NHIMG research is clear that the weakest point is often not authentication but lifecycle control. The Ultimate Guide to NHIs highlights that 97% of NHIs carry excessive privileges and that 79% of organisations have experienced secrets leaks. Those numbers explain why SSO can create a false sense of safety if the underlying app identity, keys, and integrations are unmanaged. A login policy does not revoke a hard-coded token, disable a stale webhook, or prevent an app from sharing data with an unreviewed third party. These controls tend to break down when the shadow app is embedded in a team workflow and no one owns the application lifecycle end to end.
Common Variations and Edge Cases
Tighter app control often increases operational overhead, requiring organisations to balance user convenience against review depth and revocation speed. That tradeoff becomes sharper when shadow apps are small departmental tools, because the business may resist formal onboarding even if the security risk is obvious.
There is no universal standard for how aggressively every shadow app should be blocked. Current guidance suggests tiering the response by sensitivity and blast radius. A low-risk productivity app may warrant monitoring and secrets review, while an app handling regulated data should be pulled under formal governance, even if it already uses SSO. The key distinction is that SSO may be a useful control layer, but it is not a sufficient control boundary.
Edge cases also matter. Some apps use SSO for human access while relying on separate machine identities for background tasks, scheduled jobs, or third-party connectors. Others inherit trust through sanctioned identity providers but still leak data through permissive exports or unmanaged integrations. In those environments, the right question is not whether the user signed in through SSO, but whether the app is governed as a distinct identity-bearing system with monitored permissions, secrets, and offboarding. That is where shadow app risk usually becomes visible.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Shadow apps often hide unmanaged non-human identities and secrets. |
| NIST CSF 2.0 | PR.AC-1 | SSO alone does not control app permissions or downstream access. |
| NIST AI RMF | Shadow apps create governance gaps in AI and automation workflows. | |
| CSA MAESTRO | SG-3 | Covers identity, trust, and runtime control for agentic or app workflows. |
| NIST Zero Trust (SP 800-207) | AC-4 | Zero Trust requires verification of each app action, not just SSO authentication. |
Extend access control beyond login to app permissions, integrations, and session monitoring.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on secure storage alone for cardholder data protection?
- What breaks when organisations rely on manual workflows to manage SaaS identities?
- What breaks when organisations rely on opaque business applications for access control and data protection?
- What do organisations get wrong about governing apps outside SSO?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org