Operations

The shadow IT stack you didn't know existed

The official tooling list had 12 subscriptions. The card statements had 47. The other 35 were a stack the company didn't know it was running.

The shadow IT stack you didn't know existed
Illustration · Deimar Gutiérrez

The official tooling list had 12 subscriptions on it. The credit-card statements had 47. At one company, a two-day audit of SaaS spend, kicked off after a board comment about expenses, turned up 35 vendors nobody in IT knew the company was paying. The tracked tools ran about 65,000 dollars a year. The full bill was closer to 180,000. The gap was shadow stack: software various teams had bought on corporate cards and never told anyone about.

The shadow stack held the usual suspects. Design tools the design team signed up for without a word to IT. Apps engineering adopted in a standup. Marketing tools a manager started testing and never turned off. Analytics tools one PM championed and three others bought on their own. Six of the 47 were duplicates: the company paying twice for the same vendor across teams.

The damage wasn't the raw spend, which was a small slice of revenue. It was the structure underneath. Every shadow subscription is an unaudited vendor, an unmanaged security exposure, company data spread somewhere nobody chose, and a discount the company never asked for.

The pattern is universal at growth-stage companies, and the cause is plumbing, not discipline. Buying software got democratized: anyone with a corporate card can start a subscription in five minutes. The approval step that used to sit in front of IT is gone. Teams grab the tools they need, which is efficient and chaotic at the same time. IT stops being the gatekeeper and becomes the cleanup crew, finding subscriptions months or years after they started.

Security is the part that gets underweighted. Each unmanaged subscription is data handed to a vendor nobody vetted. Most companies meet this fact during their first SOC 2 audit, when getting the stack under control turns urgent and expensive at once. The same surprise runs through an integration nobody owned.

The money leaks too. SaaS vendors price consolidated contracts well below retail, and a company running 47 scattered subscriptions pays retail on all of them. The same tools under negotiated terms usually cost a good deal less. Nobody's chasing that saving, because nobody owns the total.

The cheapest control is a quarterly statement review. Finance pulls the card transactions and AP records for the quarter, filters for SaaS vendor names, and lines them up against the official list. The delta is the shadow stack. The first pass surprises everyone. Later passes surprise less, because teams learn the audit exists and start routing new tools through the front door. It's the same muscle as catching an internal tool nobody used.

Remediation lands in three buckets. Some tools are real and valuable and belong under a central contract with negotiated pricing and a security review. Some duplicate what a central tool already does and get consolidated. Some stopped being used the day the team that bought them moved on and get sunset.

Run the audit. Three buckets. Consolidate, centralize, or sunset. The stack you can't see is the one setting your renewal terms.