[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-shadow-it::en":3,"gloss-cluster-shadow-it::en":26,"gloss-next-shadow-it::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"shadow-it","security","Shadow IT","Shadow IT is software and infrastructure in use inside an organisation without the knowledge or approval of the people responsible for it: a team's own project tracker paid on a personal card, a spreadsheet exported nightly to a personal cloud drive, a database spun up for a prototype and never decommissioned. It exists because self-serve SaaS made it faster to buy a tool than to request one, and it grows in proportion to how slow the official path is. The risk is not that the tools are bad. It is that nothing is inventoried: company data sits in systems nobody has assessed, access does not end when an employee leaves because the account was never in the identity provider, no data processing agreement exists, and an incident at the vendor reaches a customer's data through a route the security team cannot see. Discovery through SSO logs, expense reports and network telemetry usually finds far more than expected. The durable fix is procedural rather than punitive: make the approved path fast, offer a short review for low-risk tools, and give teams a way to register something they already use without a reprimand — bans push usage further out of view. For SaaS vendors, the mirror image matters commercially. Products adopted bottom-up eventually meet a security review, and features like single sign-on, directory provisioning, audit logs and an admin view of who is using the product are what convert an unsanctioned team account into a sanctioned company one instead of a mandated removal.","Shadow IT is unapproved software holding company data outside any inventory — why bans backfire, and which features turn a rogue team account into a sanctioned one.",null,[11,14,17,20,23],{"slug":12,"name":13},"scim","SCIM (System for Cross-domain Identity Management)",{"slug":15,"name":16},"security-questionnaire","Security Questionnaire",{"slug":18,"name":19},"shadow-ai","Shadow AI",{"slug":21,"name":22},"sso","Single Sign-On (SSO)",{"slug":24,"name":25},"trust-center","Trust Center",[27,31,35,39,42,45,48,51,54,57,60,63],{"slug":28,"category":5,"name":29,"updated_at":30},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":32,"category":5,"name":33,"updated_at":34},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":36,"category":5,"name":37,"updated_at":38},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":40,"category":5,"name":41,"updated_at":38},"bridge-letter","Bridge Letter",{"slug":43,"category":5,"name":44,"updated_at":38},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":46,"category":5,"name":47,"updated_at":30},"byok","Bring Your Own Key (BYOK)",{"slug":49,"category":5,"name":50,"updated_at":38},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":52,"category":5,"name":53,"updated_at":34},"data-classification","Data Classification",{"slug":55,"category":5,"name":56,"updated_at":38},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":58,"category":5,"name":59,"updated_at":38},"data-minimization","Data Minimization",{"slug":61,"category":5,"name":62,"updated_at":38},"data-poisoning","Data Poisoning",{"slug":64,"category":5,"name":65,"updated_at":38},"data-processing-agreement","Data Processing Agreement (DPA)"]