Shadow IT audit checklist for small teams: the 40 SaaS tools nobody told IT about
Nobody in a five-person company is malicious. Somebody needed to send a contract for signature today, so a $12 subscription appeared on the company card. Somebody else wanted a nicer screenshot tool, a different project tracker, an AI assistant that summarizes meetings. Two years later the company card shows 40 charges for software that shares one admin login, holds customer data, and would survive the departure of exactly one person — the one with the password in their personal password manager. A shadow IT audit is not about punishing anybody. It is about turning an invisible sprawl into a short list you can defend in a customer security questionnaire.
1. Start with the spend, not the surveys
- Pull 24 months of card and bank lines. Every recurring software charge is a tool. Label each: known, forgotten, mystery. A survey asks people what they remember; the card statement remembers everything.
- Check app-store and browser sync bills. Mobile tool subscriptions and browser-synced app purchases never show on the card. Ask for screenshots of active app subscriptions in one standing meeting — five minutes, no accusations.
- Check your identity provider's app list. If you use Google Workspace or Microsoft 365, the admin console lists every third-party app employees granted OAuth access to. That list is the honest inventory, and it is already written for you. (The Google side of this is in the Google Workspace checklist.)
2. Ask the browser and the inbox, not the people
- Review OAuth grants per account. Under each user, list third-party apps with mailbox, file, or calendar access. Anything reading mail that nobody can explain is either shadow IT or the start of an incident — both get removed today. The mailbox side pairs with the email security checklist.
- Search the shared inbox for confirmation emails. "Welcome to —, your account is ready" is the paper trail of unapproved signups. One person can grep a year of a shared mailbox in ten minutes.
- Walk one shared laptop's history and extensions. Not to read anyone's business — to count tools. The browser extension angle deserves its own pass; use the browser extension audit.
3. Score every tool on two questions
- What data does it hold? Customer names, contracts, code, credentials, health or payment data. Rank: money and customer data first, convenience tools last.
- Who can get in, and how? Shared admin password, one person's work email, or proper SSO. A tool holding customer contracts that logs in with a shared password is your top finding, every time.
- Does it touch money or code? Invoicing tools, repos, deploy platforms. Those inherit the rules of the repository checklist and the payment path: MFA, named owners, no exceptions.
4. The AI-tools line item — new, and growing fast
- Count the AI assistants people actually use. Meeting notetakers, writing helpers, code assistants. Each one is a third party receiving your conversations, and sometimes customer data, on somebody's free plan.
- Paste-test one thing you would not publish. If a teammate could paste a customer contract into a tool and nobody would notice until it is gone, the policy is missing, not the person.
- Publish a sanctioned list with a green light. Two or three approved tools, paid on the company card, with data handling you have actually read. People do not stop using AI; they stop using it secretly only when a sanctioned option exists. This is a tooling decision, not a memo.
5. Decide: adopt, sandbox, or kill
- Adopt the tools that earn it: fold them into SSO with named owners, MFA, and a line in the asset list. An adopted tool stops being shadow IT the day it has an owner.
- Kill the rest deliberately: export the data, cancel the subscription, then delete accounts and revoke OAuth grants. A cancelled card charge is not a deleted account — the data sits there until you ask. Offboarding mechanics are in the offboarding checklist.
- Sandbox anything with real value but bad hygiene: keep it off customer data, set a review date, and write the exit condition. "Revisit in 90 days" beats an argument today.
6. Close the door behind the audit
- Make SSO the default and say it in one sentence. "New tools go through [email/SSO] first" — one line in the handbook beats a policy document nobody opens. The lightweight version lives with the acceptable-use template.
- Buy through one door. The card that pays for software should be the door software enters by. A two-line expense rule ("software purchases need an owner and a purpose") catches most of the next decade's sprawl.
- Wire new tools into offboarding. The moment a tool is adopted, add it to the access-revocation list so the next departure does not leave an orphaned admin seat. The access request/offboarding pair is the mechanical home for this.
7. The quarterly 30-minute pass
- Recount from the card and the OAuth list. New charges, new grants, new AI tools. The delta since last quarter is small when the door is closed — that is the point.
- Spot-check one adopted tool's login path. Still SSO? Still MFA? Owner still employed?
- Write the three-line summary. Count before, count after, tools killed. It feeds the annual review and it is the exact evidence customer questionnaires ask for — the same folder the questionnaire template builds.
A shadow IT audit for a small team is one afternoon: pull the card statement, list the OAuth grants, score each tool on data and access, adopt or kill, then make SSO the only door and run a 30-minute quarterly recount. The Ops Starter Kit ($14) includes the vendor inventory sheet and the access log that make the recount mechanical, and the Automation Starter Pack ($19) automates the recurring reviews so sprawl gets caught at one charge, not forty. Launch week: 20% off any paid kit with code HIVE20 at checkout.