Load BearingWhat actually carries the weight

01 — Technology & Work


Shadow IT: Why It Happens and What It Tells You

Shadow IT — tools adopted without approval, usually paid for on someone's card and often free — is treated as a discipline problem. It is more useful to read it as a diagnostic.

People do not adopt unapproved tools to be difficult. They do it because the approved path did not work, and the work still had to happen.

For an applied reference, see Monitask’s workforce optimization software overview.

The risk is real. The cause is almost always upstream.

What it actually indicates

Procurement takes longer than the problem allows. If approving a tool takes eleven weeks and the project is six weeks long, an unapproved tool is not a lapse in judgment. It is the only way to do the work.

The approved tool does not do the job. Often true, and often unheard, because the person who selected it does not do the work it was selected for.

Nobody knows what is already approved. A team buys a tool the organisation already has a licence for, in another department. This is extremely common and it is a communication failure.

The approved tool is unusable. Technically capable, practically painful. People route around friction reliably.

The request was declined without an alternative. A no with no path produces a workaround every time.

Onboarding never covered it. The person did not know there was a process.

Each of these is fixable. None of them is fixed by a stronger prohibition.

The risks that are real

Reading it as a diagnostic does not mean tolerating it. The exposure is genuine:

Data in systems with no agreement. Customer data, employee data, or confidential material sitting in a service the organisation has no contract with and no ability to compel.

No offboarding. The tool is not on any list, so a departing employee's access persists indefinitely.

Single points of failure. A critical process running on a free tier of something one person set up, in their personal account.

No backup, no export. When the person leaves or the vendor closes, the data goes with it.

Compliance and privacy exposure. Depending on sector and jurisdiction, this is the part with legal consequences rather than merely operational ones.

Duplicate spend. Paying twice for the same capability, in different departments, without either knowing.

The response that does not work

Blanket prohibition with enforcement. It drives the behaviour further underground. Instead of a tool you know about, you get a tool you do not, and the risk is identical plus invisible.

Blocking at the network level and nothing else. People use their phones.

Treating it as misconduct. The predictable outcome is that nobody tells you about the next one, which is precisely the wrong incentive given the risks above.

What works

Amnesty first. Announce a window in which anyone can declare a tool with no consequence, and mean it. The inventory this produces is usually startling and it is the only accurate picture you will get.

Make the approved path fast. A lightweight route for low-risk tools — a short form, a two-day turnaround, a small spend threshold — removes most of the pressure. Reserve the heavy review for tools handling sensitive data.

Publish what is already approved. A visible list of what the organisation has, with what each is for. A significant share of shadow IT is people not knowing.

Ask why, every time. Each declared tool is a report about where the approved stack fails. That information is worth more than the compliance win.

Tier by data sensitivity, not by cost. A free tool holding customer records is a larger risk than an expensive one holding nothing. Most approval processes are calibrated on spend, which is the wrong axis.

Give teams a budget and a boundary. Within these rules, spend up to this amount without asking. It converts hidden adoption into visible adoption, which is the whole objective.

The connection to tool sprawl

There is a tension worth naming. Reducing shadow IT by making adoption easy increases the number of tools; reducing tool sprawl by restricting adoption increases shadow IT.

The resolution is not a middle setting on a dial. It is that the two problems have different causes and different fixes:

Shadow IT is caused by a slow or unresponsive approval path. Fix the path.

Sprawl is caused by nobody owning the question of what capability exists where. Assign the owner, publish the conventions, and audit annually. See tool sprawl.

An organisation that does both has fast approval and a maintained map. One that does neither has both problems and blames its employees for the second.

The question worth asking

When you find an unapproved tool, before anything else:

What did this person need that they could not get, and how long would getting it have taken?

The answer is usually the actual finding. The tool is the symptom.

For broader public guidance and background, consult the National Institute of Standards and Technology.