Identity and sign-in activity
Your IdP sees every app behind SSO, plus OAuth grants users approved themselves. It is the strongest ownership signal — and it is blind to anything paid for with a personal login or a corporate card.
Shadow IT is not a procurement failure — it is an attribution failure. This guide explains what SaaS discovery actually is, which signals produce a complete picture, the operational risks unmanaged apps create, and how to move from a discovery list to a defensible, audited decision.
SaaS discovery is the continuous process of identifying every application in use across an organisation — including the ones nobody registered, nobody budgeted for and nobody owns. A discovery programme is only useful when each application found can be tied back to a person, a cost, a data class and a decision.
Most tools stop at the first half. They produce a list of application names and leave the hard part — who owns this, what data does it hold, is it still needed, who can safely turn it off — to a spreadsheet. That gap is why shadow IT survives audits: the finding exists, the evidence of a decision does not.
Lojycal treats discovery as one input into an operational graph that already holds people, devices, contracts, spend and access. An app discovered on Tuesday is a fully attributed row on Tuesday, not a ticket that ages for a quarter.
Any single discovery signal has a systematic blind spot. Combining them is what turns a partial list into an inventory you can act on.
Your IdP sees every app behind SSO, plus OAuth grants users approved themselves. It is the strongest ownership signal — and it is blind to anything paid for with a personal login or a corporate card.
Managed endpoints and the browser layer reveal the tools people actually open, including free tiers that never touch SSO and never appear on an invoice.
Finance data catches the apps identity misses: card purchases, renewals, per-seat upgrades and vendors that quietly moved from free to paid.
Joiners, movers and leavers decide whether an app is in use or orphaned. Without the HR feed, a discovered app has no lifecycle — and no leaver ever fully closes.
The risk is rarely the app itself. It is that the app sits outside every control you rely on when someone asks you to prove something.
An unmanaged app can hold customer records, source code or HR data with no security review, no DPA and no idea which sub-processor is behind it.
Offboarding only removes what you know about. Apps outside SSO keep working for a former employee until the vendor's billing cycle, not your policy, ends the session.
Four teams buying four variants of the same tool is a spend problem and a governance problem — the same data now lives in four places with four different retention settings.
Card-paid tools auto-renew invisibly. The first time finance sees the commitment is usually after the cancellation window has closed.
GDPR records of processing, NIS2 supplier oversight and ISO 27001 asset inventories all assume you can list your applications and show who approved each one. An incomplete inventory turns into a finding.
Assistants and model APIs are the fastest-growing category of unmanaged app, and the one most likely to receive data nobody classified first.
Each approach is genuinely useful and each one has a documented blind spot. What matters is knowing which spot you are leaving open.
| Approach | What it sees | What it misses |
|---|---|---|
| SSO / IdP catalogue only | Every federated app and its sign-in activity | Anything bought with a personal login or corporate card |
| Expense and card analysis only | Paid tools, renewals and per-seat growth | Free tiers, trials and personally expensed tools |
| Browser or endpoint agent only | Real day-to-day usage, including free tiers | Server-to-server integrations and unmanaged devices |
| CASB / network inspection | Traffic to known SaaS destinations | Ownership, cost, contract terms and lifecycle state |
| Graph-based discovery (Lojycal) | All four signals resolved onto one person-app-cost-contract record | Nothing structurally — coverage depends on which instruments you connect |
A discovery list is not an outcome. This is the six-step loop Lojycal runs so every finding ends in a decision with evidence attached.
Pull identity, endpoint, spend and HR signals continuously and deduplicate them into one application record per vendor.
Resolve each app to a named person and a cost centre using the employee graph — an app without an owner is escalated, not ignored.
Tag data class, contract status, DPA coverage and whether the app sits inside or outside SSO.
Keep, consolidate or revoke — routed through the approval workflow so the decision has a named approver, not an anonymous cleanup.
Run the change with a dry-run preview first, so a wrong revoke can be rolled back rather than argued about.
Every step lands in an append-only audit ledger you can hand to an auditor without reconstructing the story afterwards.
These five numbers tell you whether a discovery programme is working, and they move long before the spend line does.
SaaS discovery is the continuous identification of every application in use across an organisation, including unmanaged and unbudgeted tools, and the attribution of each one to an owner, a cost and a data class.
Shadow IT describes applications adopted outside any approval process. SaaS sprawl describes the accumulation of approved but overlapping tools. They produce similar spend and governance problems, and both are found by the same discovery signals.
No. An identity provider only sees applications federated through it. Anything purchased with a personal login, a free tier or a corporate card never appears, which is precisely the population shadow IT lives in.
GDPR requires a record of processing activities, which assumes you can enumerate the systems processing personal data. An incomplete application inventory makes that record incomplete by definition, and the same gap affects NIS2 supplier oversight and ISO 27001 asset management.
Attribute an owner first, preview the change as a dry run, obtain a named approval, execute reversibly, and record the result in an audit ledger. Revoking access before attribution is what breaks live workflows.
The first pass is immediate once the identity, endpoint, spend and HR instruments are connected. The value comes from attribution, which improves each time an owner confirms or corrects a record.
See how a discovered application becomes an owned, costed, contract-linked record with an audit trail attached — in a walkthrough against your own estate.