Shadow IT
Also known as: Unsanctioned Software, Rogue IT
Definition
Shadow IT is technology that enters the company outside procurement: a team expenses a tool, a pilot becomes production, a corporate card becomes a renewal. Each instance is individually rational and collectively expensive - duplicate categories, unmanaged data exposure, and renewals nobody negotiates. Discovery (via expense and SSO audits) is the first step of any credible software spend triage.
The point of surfacing shadow IT is not punishment - teams bought the tools because official channels were slower than their problems. The point is consolidation leverage: you cannot negotiate, consolidate, or secure spend you have not found.
Related terms
- SaaS Sprawl — The unmanaged accumulation of software subscriptions across a company - overlapping tools, unowned renewals, and spend nobody can defend.
- Shadow AI — Employee use of AI tools without company visibility, approval, data rules, or review standards.
- Shelfware — Software a company pays for but does not use - unused seats, abandoned tools, and subscriptions renewing on habit.
Where this gets applied
- Financial Infrastructure — ARR waterfalls, deferred-revenue rules, board-pack standardization, FP&A architecture.
- Compliance & Security — SOC 2, CMMC, FedRAMP, security baselines for post-acquisition standardization.