The company card remembers what the survey forgets.
The company card remembers what the survey forgets. Ask a five-person startup how many SaaS tools they run and the founder says "like six?" Then you pull 24 months of card lines and find 40 recurring software charges. A
The company card remembers what the survey forgets.
Ask a five-person startup how many SaaS tools they run and the founder says "like six?" Then you pull 24 months of card lines and find 40 recurring software charges. A contract-signing tool somebody needed on a Tuesday. A nicer tracker. A meeting notetaker that joined every call since March. Each one bought in good faith. Each one holding a slice of customer data, most logging in with a shared password saved in exactly one person's browser.
That gap between "what we think we use" and "what we pay for" is shadow IT. It is not a big-company problem. Small teams have more of it because nobody's job is to say no.
The audit is one afternoon, and it starts with money, not people.
Don't send a survey — surveys collect what people remember. Pull the card statement and every recurring charge is a tool, labeled known, forgotten, or mystery. Then do the part most teams skip: open the admin console of your Google Workspace or Microsoft 365 tenant and read the OAuth grants list. Every third-party app employees connected is sitting right there, already inventoried. Apps with mailbox or file access that nobody can explain are either shadow IT or the first hour of an incident — both get removed the same day.
Score every tool on two questions only.
First: what data does it hold? Customer names, contracts, code, credentials rank first; nice-to-haves rank last. Second: who can get in and how? A tool holding customer contracts that logs in with a shared password is your top finding every single time — not the AI meeting bot.
And yes, there's an AI line item now.
Meeting notetakers, writing helpers, code assistants — each is a third party receiving your conversations on somebody's free plan. People don't stop using AI, and they only stop using it secretly when a sanctioned option exists. Two or three approved tools, paid on the company card, data handling you actually read. That's a tooling decision, not a memo.
Then decide, out loud, three ways:
- Adopt — fold it into SSO, name an owner, add MFA. A tool stops being shadow IT the day it has an owner.
- Kill — export the data, cancel the charge, then delete the account and revoke the OAuth grant. A cancelled card charge is not a deleted account; the data sits there until you ask.
- Sandbox — real value, bad hygiene? Keep it away from customer data, set a review date, write the exit condition.
Close the door behind you with two sentences in the handbook: new tools go through SSO first, and the card that pays for software is the door software enters by. Then run a 30-minute recount each quarter — card statement, OAuth list, delta. The delta stays small when the door is closed. That's the whole point.
The full walkthrough (card-statement inventory sheet, OAuth walk, the adopt/sandbox/kill worksheet, and the quarterly recount) is in the Ops Starter Kit ($14), and the Automation Starter Pack ($19) automates the recurring reviews so sprawl gets caught at charge #1, not #40. Launch week: 30% off any paid kit with code HIVE-LAUNCH30. The free incident quick-start is here.
Full checklist lives on our ops notes: Shadow IT Audit Checklist for Small Teams.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.