Blog
EU AI Act: What Companies Need to Know About the Transparency Obligation Now
4 min read
ReadBlog
Shadow IT grows faster than any governance measure. Without knowing which applications, licenses and owners exist in your company, you can neither consolidate nor secure. A structured approach to IT inventory.
The procurement department uses a project management tool that the IT department never paid for — because the department head subscribed to it on a credit card. Marketing runs its own analytics platform that no one in the IT portfolio knows about. Legal stores contracts in a cloud service that has never been security-reviewed. And in the background, dozens of SaaS subscriptions are auto-renewed — billed to accounts that are no longer active.
Welcome to the reality of the modern corporate IT portfolio.
The problem has a name: shadow IT. And it has not gotten smaller over the last five years — it has grown dramatically, because SaaS tools can be purchased with a credit card, deployed in minutes, and remain invisible for months or years before anyone asks whether they are really needed.
Shadow IT doesn't arise from bad intent. It arises because business units want to act quickly and the official IT procurement process seems too slow. A sales team doesn't wait four months for approval of a sales intelligence tool when it can be available tomorrow. A marketing department buys a social scheduling tool from daily expenses because the request disappears into the IT queue.
The result: in companies with 500 to 2,000 employees, industry studies suggest that on average 40 to 60 percent of all SaaS applications in use run outside official IT control. In larger enterprises, this share can be even higher.
The costs of this invisibility are multiple:
Before an organization can stop sprawl, it needs to know what is growing. That sounds trivial — but it isn't. A complete IT inventory covers three dimensions that in most companies are separated from each other and often incomplete:
1. Applications: Which software runs in the organization — on-premise, in the company's own data center, in the cloud, as a SaaS subscription? For each application, you need at minimum: name, category, vendor, hosting model, user count, and activity status.
2. Licenses: What was procured, what is in operation, what is actually being used? The gap between procured and used licenses — the so-called license utilization gap — is 20 to 40 percent in many companies. Every unused license is money paid with no return.
3. Owners: Who is responsible for which application? Who pays the invoice, who has admin rights, who is the business contact in the department? Without clear ownership, no application can be properly operated, negotiated, or decommissioned.
Typical inventory gap
In our experience from portfolio analyses, classic IT CMDB systems cover only 55 to 70 percent of applications actually in use. The rest — often 30 to 45 percent — only surfaces when you actively search: in credit card statements, SSO logs, browser extension usage data, and employee surveys.
A complete picture does not emerge from a single data source. Shadow IT is invisible because it deliberately or inadvertently bypasses official procurement. Making it visible requires several channels at once:
SSO and identity provider logs: Which applications authenticate via the company's identity provider (Okta, Entra ID, etc.)? Every application using a corporate login is visible there — even if it was never officially requested.
Credit card and expense data: SaaS tools on the company credit card are the most common form of shadow IT. A systematic review of expense data for software vendors gives an initial picture within hours.
Cloud access security broker (CASB) / web proxy logs: What traffic leaves the network toward external SaaS services? Proxy logs show which domains are actively accessed — including all services that have never seen an official request.
Employee surveys and self-reporting: Often the underestimated source. When employees can anonymously report which tools they actually use, applications come to light that appear in no log because they are locally installed or used browser-based.
A complete inventory doesn't solve the problem — it makes it workable. The next step is a clear decision structure: which applications are tolerated, which are brought into the official portfolio, which are decommissioned?
A three-tier model has proved effective:
The key point is that this categorization is not IT's task alone. Applications have business owners in the departments — and only when those owners are involved in the decision does a governance decision actually gain acceptance.
Alongside the security question, license optimization is the most immediate economic argument for a clean IT inventory. The key levers:
Reclaim programs: unused licenses are retrieved and redistributed to active users — rather than procuring new ones. Real-world projects regularly reclaim 15 to 25 percent of licenses.
Consolidation: an organization with three tools with overlapping functionality in the portfolio pays triple license, maintenance, and operating costs. Portfolio consolidation is, by experience, the single largest lever for reducing license costs.
Negotiation with utilization data: a vendor who can be shown that only 60 percent of acquired licenses are actively used is much more willing at renewal to accept lower volumes and better terms.
Quick win
Don't start with a full portfolio audit. First analyze your five largest license contracts using this template: procured licenses vs. actively used licenses. In four out of five cases, the utilization rate is below 80 percent — and with that, the business case for a first negotiation is already written.
Shadow IT governance is not a one-time cleanup project. Organizations that don't address the problem structurally will see it return to the same scale within 18 months. Three structural measures have proved effective in practice:
Fast procurement paths: the most common reason for shadow IT is an official process that is too slow. Organizations that create a fast track for low-risk SaaS tools — approval within 48 hours, predefined security requirements, clear owner — remove the main justification for the informal route.
Automatic detection of new tools: organizations that continuously evaluate SSO logs and expense data spot new shadow IT within weeks — not years. Automated alerts on new software vendors in expense reports or new SSO connections dramatically reduce the blind period.
Portfolio check on new procurement: every new software request from a business unit is automatically matched against the existing portfolio. Anyone asking whether there is a tool for task X first gets an answer from the internal portfolio — before searching externally.
A structured IT inventory is the prerequisite for all further portfolio decisions: consolidation, standardization, TBM cost allocation, and compliance evidence. The knooing portfolio module brings together applications with their licenses, business owners, and utilization data — so that the questions "what do we have?", "who is responsible?", and "what does it really cost?" can be answered at any time, without triggering a six-month inventory project.
We thought we had 280 applications. After a complete inventory using SSO analysis and expense review, we had 470. The difference — 190 applications — was our consolidation potential. From reclaiming unused licenses alone, we saved nearly €900,000 in the first year.
— IT director, German retail company, 3,200 employees
More articles
Blog
4 min read
ReadBlog
8 min read
ReadBlog
7 min read
ReadSchedule a free, no-obligation demo