Guide · SaaS Discovery

SaaS Discovery and the real risk of Shadow IT

Shadow IT is not a procurement failure — it is an attribution failure. This guide explains what SaaS discovery actually is, which signals produce a complete picture, the operational risks unmanaged apps create, and how to move from a discovery list to a defensible, audited decision.

What SaaS discovery actually is

SaaS discovery is the continuous process of identifying every application in use across an organisation — including the ones nobody registered, nobody budgeted for and nobody owns. A discovery programme is only useful when each application found can be tied back to a person, a cost, a data class and a decision.

Most tools stop at the first half. They produce a list of application names and leave the hard part — who owns this, what data does it hold, is it still needed, who can safely turn it off — to a spreadsheet. That gap is why shadow IT survives audits: the finding exists, the evidence of a decision does not.

Lojycal treats discovery as one input into an operational graph that already holds people, devices, contracts, spend and access. An app discovered on Tuesday is a fully attributed row on Tuesday, not a ticket that ages for a quarter.

The four signals a complete picture needs

Any single discovery signal has a systematic blind spot. Combining them is what turns a partial list into an inventory you can act on.

Identity and sign-in activity

Your IdP sees every app behind SSO, plus OAuth grants users approved themselves. It is the strongest ownership signal — and it is blind to anything paid for with a personal login or a corporate card.

Endpoint and browser telemetry

Managed endpoints and the browser layer reveal the tools people actually open, including free tiers that never touch SSO and never appear on an invoice.

Spend and procurement records

Finance data catches the apps identity misses: card purchases, renewals, per-seat upgrades and vendors that quietly moved from free to paid.

HRIS-linked ownership

Joiners, movers and leavers decide whether an app is in use or orphaned. Without the HR feed, a discovered app has no lifecycle — and no leaver ever fully closes.

What unmanaged SaaS actually costs you

The risk is rarely the app itself. It is that the app sits outside every control you rely on when someone asks you to prove something.

Unreviewed data exposure

An unmanaged app can hold customer records, source code or HR data with no security review, no DPA and no idea which sub-processor is behind it.

Orphaned access after leavers

Offboarding only removes what you know about. Apps outside SSO keep working for a former employee until the vendor's billing cycle, not your policy, ends the session.

Duplicate and overlapping tooling

Four teams buying four variants of the same tool is a spend problem and a governance problem — the same data now lives in four places with four different retention settings.

Unbudgeted renewal spend

Card-paid tools auto-renew invisibly. The first time finance sees the commitment is usually after the cancellation window has closed.

Compliance evidence gaps

GDPR records of processing, NIS2 supplier oversight and ISO 27001 asset inventories all assume you can list your applications and show who approved each one. An incomplete inventory turns into a finding.

AI tools entering through the side door

Assistants and model APIs are the fastest-growing category of unmanaged app, and the one most likely to receive data nobody classified first.

Discovery methods compared

Each approach is genuinely useful and each one has a documented blind spot. What matters is knowing which spot you are leaving open.

ApproachWhat it seesWhat it misses
SSO / IdP catalogue onlyEvery federated app and its sign-in activityAnything bought with a personal login or corporate card
Expense and card analysis onlyPaid tools, renewals and per-seat growthFree tiers, trials and personally expensed tools
Browser or endpoint agent onlyReal day-to-day usage, including free tiersServer-to-server integrations and unmanaged devices
CASB / network inspectionTraffic to known SaaS destinationsOwnership, cost, contract terms and lifecycle state
Graph-based discovery (Lojycal)All four signals resolved onto one person-app-cost-contract recordNothing structurally — coverage depends on which instruments you connect

From discovery to a defensible decision

A discovery list is not an outcome. This is the six-step loop Lojycal runs so every finding ends in a decision with evidence attached.

  1. 01

    Discover

    Pull identity, endpoint, spend and HR signals continuously and deduplicate them into one application record per vendor.

  2. 02

    Attribute an owner

    Resolve each app to a named person and a cost centre using the employee graph — an app without an owner is escalated, not ignored.

  3. 03

    Classify the risk

    Tag data class, contract status, DPA coverage and whether the app sits inside or outside SSO.

  4. 04

    Decide

    Keep, consolidate or revoke — routed through the approval workflow so the decision has a named approver, not an anonymous cleanup.

  5. 05

    Execute reversibly

    Run the change with a dry-run preview first, so a wrong revoke can be rolled back rather than argued about.

  6. 06

    Write the evidence

    Every step lands in an append-only audit ledger you can hand to an auditor without reconstructing the story afterwards.

What to measure

These five numbers tell you whether a discovery programme is working, and they move long before the spend line does.

  • Unmanaged application count — apps in use with no owner and no contract record
  • Apps per owner — concentration risk when one person carries an unreasonable share of the estate
  • Orphaned seats — active access belonging to people who have already left
  • Time to attribution — days between an app being discovered and an owner being assigned
  • Spend outside procurement — share of SaaS cost that never passed through an approval

Frequently asked questions

What is SaaS discovery?

SaaS discovery is the continuous identification of every application in use across an organisation, including unmanaged and unbudgeted tools, and the attribution of each one to an owner, a cost and a data class.

How is shadow IT different from SaaS sprawl?

Shadow IT describes applications adopted outside any approval process. SaaS sprawl describes the accumulation of approved but overlapping tools. They produce similar spend and governance problems, and both are found by the same discovery signals.

Can SSO logs alone find shadow IT?

No. An identity provider only sees applications federated through it. Anything purchased with a personal login, a free tier or a corporate card never appears, which is precisely the population shadow IT lives in.

Is discovering shadow IT a GDPR requirement?

GDPR requires a record of processing activities, which assumes you can enumerate the systems processing personal data. An incomplete application inventory makes that record incomplete by definition, and the same gap affects NIS2 supplier oversight and ISO 27001 asset management.

How do you remove an unmanaged app safely?

Attribute an owner first, preview the change as a dry run, obtain a named approval, execute reversibly, and record the result in an audit ledger. Revoking access before attribution is what breaks live workflows.

How long does discovery take to become useful?

The first pass is immediate once the identity, endpoint, spend and HR instruments are connected. The value comes from attribution, which improves each time an owner confirms or corrects a record.

Keep reading

Discovery is only the first row

See how a discovered application becomes an owned, costed, contract-linked record with an audit trail attached — in a walkthrough against your own estate.