Join our Newsletter — 33% off our NHI Course
Home› FAQ› Cyber Security› Why do ITAM and SAM miss shadow IT…
Cyber Security

Why do ITAM and SAM miss shadow IT in SaaS environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Cyber Security

They miss it because they were built around hardware and on-premise software, not browser-delivered subscriptions created outside traditional procurement flows. SaaS adoption often happens through self-service sign-up or business-led purchasing, so endpoint-focused inventory leaves a gap where access exists but the governance team cannot see it.

Why traditional inventory misses browser-led SaaS adoption

ITAM and SAM are strongest when an asset has a clear procurement trail, installed software footprint, or endpoint presence. SaaS breaks that model because the “asset” may exist only as a tenant, subscription, or login created directly by a user or business team. That means the organisation can have active software use without a matching record in procurement, endpoint management, or the software catalogue.

The practical gap is not just visibility, it is ownership. When business-led purchasing bypasses central processes, the tool may never be tagged to the right cost centre, control owner, or security reviewer. A browser-first app can be fully operational long before any governance system sees it, which is why discovery methods built around devices and installed binaries routinely undercount SaaS.

What counts as shadow IT in SaaS environments

In SaaS, shadow IT is often less about rogue infrastructure and more about unapproved access paths to externally hosted services. That includes free trials converted into paid subscriptions, department-owned tools bought on cards, or embedded SaaS used through a browser without IT involvement. The risk is that the organisation treats the application as absent simply because it never touched a managed endpoint.

For practitioners, the useful distinction is between installation visibility and operational use. If the control set only monitors endpoints, software images, or standard procurement records, it may miss legitimate but unsanctioned SaaS usage that has its own identities, data flows, and sharing settings. SalesBleed Salesforce Agentforce 2026 illustrates how SaaS exposure can sit outside the normal software inventory model while still creating direct data-risk and access-risk consequences.

Why governance gaps, not just tooling gaps, drive the miss

Shadow IT persists when the organisation has no enforced intake path for SaaS requests, no consistent approval gate for business-led purchases, and no reliable way to reconcile usage against an authoritative app register. In that state, ITAM and SAM may be doing their intended job, but they are solving for owned software, not unsanctioned service consumption.

Current guidance in security operations favours correlating procurement, identity, network, and browser signals rather than relying on a single inventory source. That matters because SaaS can be discovered through authentication logs, OAuth grants, SSO events, browser telemetry, expense data, and vendor sharing alerts long before it appears in a traditional software estate report. Stronger governance turns “unknown app” into a measurable intake and ownership problem instead of a pure discovery problem.

Risk and Threat Considerations

Unseen SaaS creates exposure because access, data sharing, and third-party retention can continue even when the application is outside approved inventory. The main failure mode is false confidence: teams believe software is controlled because endpoints are clean, while users are still creating accounts, syncing data, or granting integrations to services the organisation has not reviewed.

Failure mechanism: Browser-delivered SaaS bypasses endpoint-centric discovery, so the organisation never links the service to a sanctioned owner, risk review, or offboarding process.

Impact: Data can be shared into unapproved tenants, access can persist after role changes, and the service can become a blind spot for incident response, compliance, and contract management.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-01 — Physical devices and systems inventoriedBrowser-first SaaS is often missed when inventory depends on managed endpoints.
ID.AM-02 — Software platforms and applications inventoriedShadow SaaS persists when application inventory excludes user-created subscriptions.
GV.OC-03 — Cybersecurity roles, responsibilities, and authorities are established and communicatedMissed SaaS often reflects unclear ownership between IT, procurement, and business teams.
Recommendation — Correlate endpoint data with identity and procurement signals to complete software discovery. Maintain an authoritative SaaS application register that includes business-led purchases. Assign clear ownership for SaaS intake, approval, and review across business and security teams.
CIS Controls v8CIS-1 — Inventory and Control of Enterprise AssetsSaaS blind spots arise when inventory practices stop at devices and installed software.
Recommendation — Extend asset inventory to include externally delivered SaaS used by employees and teams.

Practitioner Guidance

What to verify: Check whether your discovery model includes SSO logs, OAuth consent, expense claims, browser telemetry, and cloud app access events, not just endpoint software lists. If those signals are absent, your SAM program is probably undercounting SaaS rather than accurately reflecting low adoption.

Decision rule: If the application is reachable through a browser and can be self-provisioned, treat identity and access evidence as part of software discovery. If the only evidence source is endpoint inventory, assume the record is incomplete until proved otherwise.

Practitioner takeaway: The control problem is not simply finding more software, it is building a discovery model that sees service consumption wherever users can create it, own it, and share data through it.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org