Every Small Team Has Shadow Software, and Ours Was Eleven Tools Deep
Nobody signed off on any of it and every single one was a reasonable decision at the time. What we found when we went looking, and the policy that replaced the ban I nearly wrote.
Shadow IT is a phrase from enterprise security that sounds absurd applied to a studio of two, and then I counted. Eleven tools were in active use on our work that appeared nowhere in our records, were paid for on three different cards, and in four cases held client data. Every one of them had been adopted for a real reason on a real deadline.

Here is how I found them, because the method generalises and the method is the useful part. Three sources. First, browser history for one week, filtered to domains visited more than three times — this surfaces what people actually open, not what they say they use. Second, the email inbox searched for the words “welcome to,” “your receipt,” “trial ends,” and “verify your email,” which finds every signup going back years. Third, the OAuth permissions page on our Google and GitHub accounts, which lists every service anyone has ever connected, and which almost nobody has ever looked at.
The email search alone returned 47 distinct services. Twenty-nine of those were genuinely dead — a trial from 2021, a tool evaluated and rejected. Eleven were in current use and unrecorded. Seven were paying, which came to $63 a month I had not accounted for anywhere.
The OAuth list was the one that changed how I think about this. It is not about money. There were two services with read access to our entire Google Drive that I had personally authorised, once, for a single task, more than two years earlier. They were both legitimate companies. That is not the point; the point is that I had granted standing access to everything and then completely forgotten, and there is no reminder, no renewal, no receipt. Money leaves a trail. Permissions do not.
My first instinct was to write a policy that said nothing gets adopted without approval, and I got about two paragraphs in before I realised it would not survive its first deadline. The reason shadow software exists is that the sanctioned path is slower than the problem. If getting a tool approved takes three days and the client call is tomorrow, the tool gets used and not mentioned. A ban does not remove the pressure; it removes the record.
What we do instead is a single shared page, and the rule is: use whatever you need, write one line here within a week. Name, what it is for, whether client data touches it, which card. That is it. No approval, no review, no meeting. The bet was that people will comply with a rule that costs them thirty seconds and does not risk a no, and eleven months in the bet has held — the page has 23 entries and I have found exactly one unlisted tool since, which was mine.
The quarterly audit then reads that page alongside the bank statement, and the gap between the two is the interesting part. Things on the statement but not the page are forgotten subscriptions. Things on the page but not the statement are free tiers, which is fine, and which are also where the permissions risk concentrates, because free tools are the ones you connect to your accounts without thinking about it.
Two things I would do differently if starting over. I would have checked the OAuth pages first, because that took ten minutes and produced the most serious finding. And I would have written the shared page before going looking, because arriving at someone with a list of eleven things they did wrong is a bad way to start a process you need them to participate in for years.



