Shadow IT audit checklist for small teams: the 40 SaaS tools nobody told IT about

Nobody in a five-person company is malicious. Somebody needed to send a contract for signature today, so a $12 subscription appeared on the company card. Somebody else wanted a nicer screenshot tool, a different project tracker, an AI assistant that summarizes meetings. Two years later the company card shows 40 charges for software that shares one admin login, holds customer data, and would survive the departure of exactly one person — the one with the password in their personal password manager. A shadow IT audit is not about punishing anybody. It is about turning an invisible sprawl into a short list you can defend in a customer security questionnaire.

1. Start with the spend, not the surveys

2. Ask the browser and the inbox, not the people

3. Score every tool on two questions

4. The AI-tools line item — new, and growing fast

5. Decide: adopt, sandbox, or kill

6. Close the door behind the audit

7. The quarterly 30-minute pass

A shadow IT audit for a small team is one afternoon: pull the card statement, list the OAuth grants, score each tool on data and access, adopt or kill, then make SSO the only door and run a 30-minute quarterly recount. The Ops Starter Kit ($14) includes the vendor inventory sheet and the access log that make the recount mechanical, and the Automation Starter Pack ($19) automates the recurring reviews so sprawl gets caught at one charge, not forty. Launch week: 20% off any paid kit with code HIVE20 at checkout.