The IT manager’s guide to unmanaged SaaS applications
August 24, 2026
9 minute read
For anyone in IT, the SaaS apps you know about are only part of the job.
The harder problem is everything you don’t know about like the AI tool an employee tried with their corporate email, the project management app a department bought on a credit card, the free file-sharing service someone connected to company data, or the subscription quietly renewing in an expense report.
These unmanaged SaaS applications can create security risks, unnecessary costs, and extra work during onboarding and offboarding. And because employees can adopt SaaS in minutes, a spreadsheet or annual software audit isn’t enough to keep up.
The goal shouldn’t be to stop employees from trying useful technology, but to give IT enough visibility to understand what’s being used, decide what belongs in the environment, and take action when an app creates unnecessary risk or cost.
This guide explains how to find unmanaged SaaS applications, investigate them, and build a practical process for keeping your SaaS stack under control.
What are unmanaged SaaS applications?
Unmanaged SaaS applications are cloud applications being used within your organization without being fully visible to or governed by IT.
You may also hear these applications described as shadow IT. BetterCloud defines shadow IT as hardware, software, or services employees use without the explicit approval or knowledge of IT.
An unmanaged app could be:
- A free SaaS app an employee signs up for using their work email
- A paid subscription purchased directly by a department
- An application that bypasses your normal procurement process
- A tool that isn’t connected to your identity provider or SSO
- An app IT knows exists but doesn’t have an established owner or lifecycle process for
- A duplicate tool that performs the same job as an approved application
- An AI application employees begin using before IT has reviewed how it handles company data
That last category is becoming particularly important. The barrier to experimenting with a new SaaS or AI application is extremely low. An employee can find a tool, create an account, and begin putting corporate information into it before IT even knows the application exists.
That creates a basic SaaS management problem: You can’t govern what you can’t see.
A SaaS management platform helps solve that problem by giving IT a central place to discover applications and manage the users, access, spend, and data associated with them.
Why unmanaged SaaS is an IT problem
Employees generally don’t adopt new SaaS applications because they’re trying to circumvent IT.
They’re trying to get something done.
Marketing needs a design tool. Sales wants an AI meeting assistant. Finance finds software that makes reporting easier. An employee needs to send a large file and discovers a free service through a Google search.
That’s why unmanaged SaaS is difficult for IT generalists in particular. Saying “no” to every new tool isn’t realistic. But allowing applications to spread without oversight isn’t sustainable either.
The consequences tend to show up in four places.
1. Security risk
An employee may grant a SaaS application access to their company account, files, calendar, contacts, or other sensitive information.
If IT hasn’t reviewed the application, you may not know:
- What permissions it has
- What corporate data employees are uploading
- How the vendor stores or uses that data
- Whether MFA or SSO is supported
- Whether access will be removed when an employee leaves
The security problem doesn’t necessarily end when the employee stops using the app. Accounts and permissions can remain behind long after the original business need disappears.
That’s one reason shadow IT management needs to be part of ongoing SaaS operations rather than a one-time cleanup project.
2. Hidden SaaS spend
Unmanaged SaaS isn’t always free.
Employees and departments can purchase subscriptions themselves and submit the charge through an expense management system or put it on a corporate card. Individually, a $20 or $50 monthly subscription may not attract much attention.
Across an organization, those charges add up.
You can also end up paying twice for essentially the same capability. One department buys one project management platform while another uses a competing product—even though IT already has an enterprise agreement for a third.
Without centralized visibility, nobody sees the overlap.
Effective SaaS spend management therefore starts with discovery: understanding both sanctioned and unsanctioned applications and what they cost.
3. Offboarding gaps
Unmanaged applications can turn a routine offboarding into an investigation.
Your standard offboarding workflow might remove an employee from Google Workspace, Microsoft 365, Slack, Zoom, and the other applications IT manages.
But what happens to the account they independently created six months ago?
If IT doesn’t know the account exists, it can’t reliably remove access.
That can leave orphaned SaaS accounts—and potentially company data—outside the normal employee lifecycle process.
4. Operational overhead
Eventually, unmanaged SaaS tends to become managed SaaS.
Employees submit support tickets. Finance asks who owns a renewal. Security needs information for an audit. A department wants IT to configure SSO. Someone leaves and their manager asks IT to transfer application data.
The application may have entered the organization without IT involvement, but IT often inherits the operational work later.
Finding unmanaged SaaS earlier gives you a chance to make deliberate decisions before those requests become urgent.
How to find SaaS apps employees are using without IT approval
There isn’t one perfect discovery source.
An employee can access SaaS through SSO, create a standalone account, purchase an application personally, or simply use a free product in a browser. Each path leaves different evidence.
That’s why the strongest discovery strategy combines several signals.
BetterCloud’s guide to SaaS discovery tools covers the different discovery methods available to IT teams. For a lean IT organization, the important principle is simple: Don’t depend on a single data source to tell you what’s in your SaaS stack.
Here are several places to look.
1. Start with your identity provider and SSO
Your identity provider is one of the cleanest sources for SaaS discovery.
Review applications connected through systems such as Google Workspace, Microsoft Entra ID, or your SSO provider. Look at authentication activity and OAuth grants as well as the applications you’ve intentionally configured.
This gives you a baseline of applications interacting with corporate identities.
But don’t stop there.
SSO data can tell you a lot about your environment, but unmanaged SaaS frequently exists precisely because it isn’t going through your standard SSO process.
Treat identity data as one discovery layer rather than the entire inventory.
2. Find SaaS apps signed up with work email addresses
One of the easiest ways for shadow IT to enter an organization is also one of the simplest:
Employee enters work email → employee creates account → SaaS app is now part of the company’s technology footprint.
There may be no procurement ticket, SSO integration, or IT request involved.
Finding SaaS apps signed up with work email accounts can therefore uncover tools that traditional inventory methods miss.
Look for signals showing employees registering corporate identities with external applications. Depending on your discovery approach, that could include browser activity, authentication data, SaaS discovery tooling, or other application signals.
Then ask:
- How many employees are using the app?
- Which departments are using it?
- Is the application already approved?
- Does the company pay for another product with the same functionality?
- What data can the application access?
- Is the use case legitimate?
- Should IT approve, consolidate, restrict, or remove it?
The objective isn’t merely to produce a longer application list. It’s to turn discovery into a decision.
3. Look beyond SSO with browser-based discovery
Think about how an employee actually adopts a new SaaS tool.
They open a browser, find an application, and start using it.
That makes browser-level visibility valuable for how to find SaaS apps employees are using without IT approval, particularly when those applications never appear in your SSO environment.
For example, BetterCloud’s shadow IT capabilities can discover sanctioned and unsanctioned applications using multiple signals, including SSO, browser extension, and ERP data.
Combining these signals gives IT a broader view than relying on identity data alone.
More importantly, discovery should give you context. A raw list of URLs isn’t particularly useful to an IT manager with 30 other things to do.
You want to understand who uses an app, which department owns it, whether licenses overlap with another application, and the application’s risk category. That information helps you prioritize what actually needs attention.
4. Partner with finance to find SaaS spend hidden in expense reports
Your accounting and expense systems can be an unexpectedly useful SaaS inventory.
Why?
Because employees may skip IT procurement but they generally can’t skip payment forever.
Finding SaaS spend hidden in expense reports can reveal subscriptions purchased directly by employees or departments that IT never approved.
Work with finance or procurement to review:
- Corporate card transactions
- Employee expense reimbursements
- Recurring software charges
- Vendor and merchant names
- Accounts payable records
- Department-level technology expenses
You’re looking for vendors that don’t appear in IT’s approved application inventory.
A recurring $30 charge may represent a single-user application. A few thousand dollars going to an unfamiliar vendor could indicate an entire department has adopted software outside the normal procurement process.
Financial discovery also helps answer a question identity data can’t:
What are we actually paying for?
BetterCloud’s SaaS cost control capabilities combine software discovery with spend information so IT can see applications, licenses, and spending across employees and departments.
That can turn a shadow IT conversation from “We think people might be using this app” into “Twenty employees are using this application, we’re paying for it, and we already own another tool that does the same thing.”
That’s a much easier problem to act on.
5. Compare discovered applications against your approved inventory
Discovery only becomes useful when you have something to compare it against.
Maintain a centralized SaaS inventory that identifies, at minimum:
- Application name
- Business owner
- IT owner
- Approval status
- Number of users
- Departments using the application
- Cost
- Renewal date
- Authentication method
- Risk classification
- Approved alternative, when applicable
Then compare newly discovered applications against that inventory.
For a small IT team, you don’t necessarily need to investigate every application immediately. Triage them.
A free productivity tool used by one employee probably doesn’t deserve the same urgency as an unapproved file-sharing platform used by 80 employees.
How to prioritize unmanaged SaaS applications
Once you discover shadow IT, avoid treating every unknown app as an emergency.
A simple risk-based model works better.
High priority
Investigate quickly when an unmanaged application:
- Handles sensitive company or customer data
- Requests broad OAuth permissions
- Provides file storage or sharing
- Uses generative AI with corporate data
- Has a large number of employees using it
- Represents meaningful unapproved spend
- Duplicates an expensive enterprise application
- Is used by former employees
- Has no clear business owner
Medium priority
Review applications with legitimate business use but incomplete governance.
Maybe a department has adopted a useful application, but IT hasn’t configured SSO, documented ownership, reviewed the vendor, or incorporated the tool into offboarding.
These are good candidates for formal approval and management.
Low priority
Some applications may have limited use, minimal permissions, no company data, and no meaningful spend.
Document them and monitor them rather than spending hours investigating every free utility an employee opens once.
The point is to give IT a manageable queue—not another endless dashboard.
What to do when you find an unmanaged SaaS app
Finding the application is only the beginning.
For each meaningful discovery, IT should decide whether to approve, consolidate, restrict, or remove it.
Approve it
Sometimes shadow IT exposes a legitimate gap in your technology stack.
Employees found a useful application because the approved tools weren’t meeting their needs.
If the vendor passes your security and procurement requirements, formalizing the application may be the right decision.
Assign ownership, negotiate the appropriate contract, connect it to your identity infrastructure where possible, and add it to your employee lifecycle processes.
Consolidate it
Suppose you discover three project management applications across three departments.
Rather than supporting all three indefinitely, compare usage and requirements and determine whether employees can consolidate onto an existing standard.
Consolidation can reduce SaaS spend while making administration, security, and offboarding much easier.
Restrict it
An application may have a valid use case but introduce unacceptable permissions or data handling.
In that situation, IT can work with security and the business owner to establish appropriate restrictions or provide an approved alternative.
Remove it
Some applications simply don’t belong in the environment.
If an app introduces unnecessary security risk, duplicates an approved product, has no legitimate business purpose, or violates company policy, remove access and communicate why.
The communication matters.
Employees are much more likely to follow SaaS policies when IT provides a useful alternative rather than simply blocking the tool they wanted.
Turn SaaS discovery into an ongoing process
A common mistake is treating SaaS discovery like spring cleaning.
IT performs an audit, builds a spreadsheet, cleans up the obvious problems, and moves on.
Six months later, the inventory is outdated.
SaaS adoption doesn’t stop after your audit. Neither should discovery.
A more sustainable approach looks like this:
Discover → investigate → decide → govern → monitor
As new applications appear, classify them. Assign ownership to approved tools. Remove or consolidate unnecessary ones. Incorporate sanctioned applications into onboarding, offboarding, and access management. Review usage and spend before renewals.
For spend specifically, ongoing management lets IT identify unused or underutilized licenses and work with finance and procurement to rightsize contracts. BetterCloud’s guidance on SaaS spend management for IT covers how application discovery, usage monitoring, cost analysis, and license optimization work together.
This turns SaaS discovery from an occasional audit into part of normal IT operations.
A practical unmanaged SaaS checklist for IT generalists
If you’re responsible for a broad IT workload, start small.
- Build or update your approved SaaS inventory.
- Review applications connected through SSO and your identity provider.
- Look for SaaS accounts created with corporate email addresses.
- Add browser-based discovery to surface applications outside SSO.
- Work with finance to identify software purchases in corporate cards and expense reports.
- Compare discovered applications with your approved inventory.
- Prioritize apps based on users, permissions, data access, spend, and risk.
- Identify duplicate or overlapping applications.
- Assign business and IT owners to approved applications.
- Add sanctioned apps to onboarding and offboarding processes.
- Remove unnecessary accounts and licenses.
- Establish a simple process employees can use to request new SaaS applications.
- Review new applications continuously rather than waiting for an annual audit.
SaaS visibility should lead to action
Finding unmanaged SaaS applications isn’t about creating the world’s most complete software spreadsheet.
It’s about answering practical questions:
What applications are our employees using? Who is using them? What do they cost? What company data can they access? And what should IT do about them?
The answers may be scattered across SSO logs, corporate email registrations, browsers, expense reports, accounting systems, and individual departments.
Bringing those signals together gives IT a much more accurate picture of the SaaS environment—and gives an IT manager or generalist a realistic way to prioritize what needs attention.
That’s where a SaaS management platform can help. BetterCloud brings application discovery, SaaS spend visibility, automation, and governance into a centralized platform, helping IT teams move from discovering unmanaged applications to actually managing them.
With BetterCloud, IT can uncover shadow IT and hidden SaaS expenses, understand application usage and ownership, identify overlapping tools and unused licenses, and establish more consistent governance across the SaaS stack.
Because ultimately, the goal isn’t to prevent employees from finding better ways to work.
It’s to make sure IT can see those tools early enough to keep the business productive, secure, and in control.