Case file Nº01

The Cost of Shadow IT

The most expensive software in your company is the software nobody knows you own. Shadow IT is not a tooling problem — it is a visibility problem. Lojycal turns the invisible estate into a row on the ledger.

The cost
1 in 3

SaaS apps in the average mid-market organisation is unknown to IT. The rest is paid for twice, sometimes three times, often through cards no one is reconciling.

47%
of SaaS spend sits outside the IT-approved catalogue
€312
median monthly bleed per duplicate seat, untouched
more abandoned licences than IT believes, on first scan

Five blind spots

Shadow IT is not one failure. It is five different teams each looking at one corner of the same problem, none of them holding the whole picture.

WHY IT HAPPENS

Speed beats process, every single time

A marketer needs a transcription tool by Tuesday. Procurement takes two weeks. They use a corporate card, tick the consent box, and the tool is live in nine minutes. The org just acquired a vendor, a data processor, and a renewal — without a ticket, a contract, or a DPA.

WHY FINANCE MISSES IT

It looks like a coffee, not a contract

€18 on a corporate card lands in the GL as 'software, miscellaneous'. Nothing flags it. Twelve months later that same €18 has compounded into 240 seats across 40 teams — and finance is still booking it under miscellaneous.

WHY IT MISSES IT

If it never asked for SSO, IT never saw it

Modern SaaS doesn't need IT's help to onboard. No AD join, no MDM enrolment, no firewall ticket. The browser is the install. Without device-side telemetry and IdP OAuth-grant ingestion, IT only sees the apps that asked permission — never the ones that just took it.

WHY SECURITY MISSES IT

Unknown apps have unknown data

An app you don't know about cannot be in your asset register, your DPIA, or your SOC2 scope. It can still be processing customer PII, exporting source code, or storing access tokens. The first time security hears its name is usually in the breach notification.

WHY PROCUREMENT MISSES IT

There is no PO to track

Procurement governs what flows through procurement. Shadow IT skips the front door entirely — card, click, consent. The vendor invoices the cardholder, not AP. There is no PO, no MSA, no renewal calendar. Procurement is asked to negotiate down a tool they have never heard of, three days before auto-renew.

How Lojycal discovers
EVIDENCE

Five detection paths, each tied to a real signal source already in the platform. Nothing here is theoretical — every finding cites the table, connector, or webhook that produced it.

  1. 01Unmanaged SaaS

    Apps in use, nowhere on the books

    Two independent signals: IdP OAuth grants the moment a user clicks 'Sign in with Google', and Cookie Jar device-extension telemetry from the work browser. Any domain that shows authenticated traffic without a matching row in the Integration Ledger is flagged within minutes — not at the next quarterly audit.

    idp_webhook_events · cookie_jar_events · integration_ledger
  2. 02Duplicate tools

    Three transcription tools, one job

    license_subscriptions is normalised by vendor family and capability tag, then cross-checked against global_pricing_benchmarks. When two paid contracts share a capability tag (e.g. 'transcription', 'esign', 'project-mgmt') the platform raises a Duplicate finding with the cheaper of the two pre-selected as the consolidation target.

    license_subscriptions · global_pricing_benchmarks
  3. 03Abandoned licences

    Seats paid for, never opened

    Per-seat last-active is pulled from the live connector, not from a CSV export. Seats tier into 30 / 60 / 90-day buckets. Reclaim is dry-run by default, returns a rollback token, and the action is written to the WORM audit log before the connector is even called.

    connector_seat_activity · license_reclaim_runs · audit_log
  4. 04Inactive users

    Leavers still holding live credentials

    The Personio / BambooHR leaver delta is reconciled against IdP group membership and connector seat presence on every sync. The HRIS push reconciliation flow (read → confirm → write → verify) means a leaver flagged in HRIS becomes an actionable revoke list across every connected tool in the same minute.

    personio_employees · bamboohr_employees · hris_onboarding.functions
  5. 05Unauthorised purchases

    An invoice with no request behind it

    Every legitimate buy starts as a row in procurement_requests, sized by the 3-tier policy (€1k / €5k / €25k). Ingested vendor invoices are joined back to that ledger. Invoices with no matching request are routed to the policy for retroactive approval — and the requester, approver, and signer are all named in the audit trail.

    procurement_requests · procurement_policy · vendor_order_dispatches

Evidence trail

  1. Step 01
    Signal captured (IdP grant · browser telemetry · invoice ingest)
  2. Step 02
    Cross-correlated against the ledger and the HRIS
  3. Step 03
    Finding raised with named owner, suggested action, and rollback path
  4. Step 04
    Action written to the WORM audit log, signed, exportable

Shadow IT is not a tooling problem. It's a visibility problem.

You cannot govern, secure, retire, or negotiate something you cannot see. Lojycal makes the invisible estate visible — then puts every row of it under the same audited lifecycle as the rest of your tools.