# Shadow Provisioning Discovery

*/Problems/Shadow_Provisioning_Discovery*

## Problem Overview

IT and security teams lack visibility into the decentralized adoption of software and cloud infrastructure across the enterprise. Employees bypass formal procurement to spin up SaaS workspaces, deploy cloud instances, and connect third-party APIs using corporate email addresses or departmental credit cards. This creates an unmapped surface of unmanaged data stores, redundant software spend, and compliance violations that official asset registers fail to track.

The friction of corporate approval processes forces teams to self-provision tools to hit project deadlines. Modern software delivery models enable this behavior by offering freemium tiers and low-friction signups that require no technical approval. As a result, critical company data flows into unauthorized environments long before the expense ever appears on a departmental budget report.

Traditional discovery methods rely on network perimeter monitoring or endpoint agents, which miss out-of-band provisioning from personal devices or remote networks. Expense management software identifies shadow software only after the transaction clears, leaving an unacceptable window of vulnerability. Identifying these unmanaged assets requires parsing fragmented signals across single sign-on logs, OAuth token grants, and email receipts rather than relying on centralized hardware management.

## Problem Severity Frequency

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Severity**: 4
**Frequency**: continuous
**Budget Reality**:
- **Price Ceiling**: ~$25k-40k/yr - capped by established budgets for CASB or SaaS management platforms
- **Who Controls Spend**: CISO or CIO approves; Director of IT Security recommends
- **Existing Budget Line**: true
- **Switching Cost From Status Quo**: moderate: requires API integrations to identity providers and expense systems but avoids heavy endpoint agent deployment
**Regulatory Risk**: high
**Time Cost Per Event**: ~2-5 hours per shadow asset discovered
**Money Cost Per Event**: ~$500-2,500 per unmanaged app in redundant licenses and IT labor
**Annual Cost Per Affected Entity**: ~$50k-150k in wasted spend and compliance audit overhead

## Problem Why Now

The explosion of generative AI tools and low-friction SaaS models eliminates the procurement barrier entirely. Employees grant third-party applications access to corporate repositories via OAuth in a single click, transferring proprietary data before any financial transaction occurs. According to broad industry tracking circa 2023–2024, shadow IT shifted from a redundant billing issue to an acute data governance crisis as unvetted AI assistants proliferated.

Traditional Cloud Access Security Brokers (CASBs) and network perimeter tools fail because modern provisioning happens off-network and out-of-band. Relying on expense management systems only catches shadow software after the corporate credit card clears, leaving a 30-day window of vulnerability. Endpoint agents remain completely blind to server-to-server API integrations or workspaces spun up from personal laptops.

Recent advancements in large language models make it computationally viable to parse unstructured corporate exhaust to identify this adoption natively. Systems continuously ingest millions of email receipts, OAuth token grants, and single sign-on logs to extract deterministic proof of unmanaged SaaS adoption. This structural shift allows security teams to map shadow provisioning in real-time without relying on legacy network choke points.

## Problem Current Solutions

**Status Quo**: IT and security teams piece together decentralized software usage by manually reviewing expense reports, scanning single sign-on logs, and checking cloud access security broker dashboards. They rely on post-transaction financial data or rigid network filters to identify unauthorized applications long after the initial deployment.
**Workarounds**:
- exporting expense data to spreadsheets
- manual OAuth permissions review
- cross-referencing corporate card statements
- sending employee self-attestation surveys
**Named Tools In Use**:
- [Netskope CASB](/Products/Netskope_CASB)
- [Microsoft Entra ID](/Products/Microsoft_Entra_ID)
- [Expensify](/Products/Expensify)
- [Zscaler Internet Access](/Products/Zscaler_Internet_Access)
**Why Insufficient**: Current tools rely on network traffic intercepts or delayed financial transactions, missing out-of-band freemium signups occurring on remote networks or personal devices. An AI-native system can continuously parse and correlate unstructured signals like email receipts and OAuth grants to identify shadow assets the moment they are provisioned.

## Problem Market Profile

**Incumbents**:
- [Netskope CASB](/Problems/Shadow_Provisioning_Discovery/Competitors/Netskope_CASB)
- [Microsoft Entra ID](/Problems/Shadow_Provisioning_Discovery/Competitors/Microsoft_Entra_ID)
- [Expensify](/Problems/Shadow_Provisioning_Discovery/Competitors/Expensify)
- [Zscaler Internet Access](/Problems/Shadow_Provisioning_Discovery/Competitors/Zscaler_Internet_Access)
- [Torii](/Problems/Shadow_Provisioning_Discovery/Competitors/Torii)
- [Productiv](/Problems/Shadow_Provisioning_Discovery/Competitors/Productiv)
**Substitutes**:
- exporting expense data to spreadsheets
- manual OAuth permissions review
- cross-referencing corporate card statements
- employee self-attestation surveys
**Position Axes**:
- Detection Vector (Network Intercept vs. Identity and API Signals)
- Discovery Timing (Post-Transaction vs. Point-of-Provisioning)
**Market Dynamics**: The market is moving from perimeter-bound network interceptors toward API-integrated SaaS management platforms. Vendors are increasingly correlating fragmented identity, financial, and workspace telemetry to bypass the limitations of traditional endpoint agents.
**Competition Concentration**: Incumbent security tools cluster heavily in the network intercept and point-of-provisioning quadrant, relying on perimeter controls that miss off-network activity. Expense management systems and manual reconciliation workarounds dominate the identity signals and post-transaction quadrant, detecting shadow IT only after a financial footprint exists. The quadrant representing identity and system signals at the exact point-of-provisioning remains comparatively sparse, as few tools capture out-of-band freemium signups instantly without requiring endpoint agents.

## Mint Vocabulary Bag

**Action Verbs**:
- detect
- monitor
- index
- profile
- isolate
**Gerund Stems**:
- audit
- scan
- map
- track
- survey
**Abstract Nouns**:
- exposure
- drift
- visibility
- entropy
- compliance
**Concrete Nouns**:
- endpoint
- gateway
- manifest
- ledger
- beacon
- agent
**Metaphor Nouns**:
- sonar
- prism
- sextant
- scout
- lattice
**Structure Nouns**:
- sandbox
- conduit
- nexus
- vault
- pipeline

## Problem Candidate Solutions

- [Holeprint](/Problems/Shadow_Provisioning_Discovery/Startups/Holeprint) — Agent
- [Exposurespan](/Problems/Shadow_Provisioning_Discovery/Startups/Exposurespan) — Service-as-Software
- [Prismipeline](/Problems/Shadow_Provisioning_Discovery/Startups/Prismipeline) — Software
- [Informalcode](/Problems/Shadow_Provisioning_Discovery/Startups/Informalcode) — Software
- [Accateway](/Problems/Shadow_Provisioning_Discovery/Startups/Accateway) — Software

## Problem Solution Space2x2

```mermaid
quadrantChart
title Shadow Provisioning Discovery
x-axis Network Packet Analysis --> Native Cloud APIs
y-axis Alerting Only --> Automated Teardown
quadrant-1 Automated Cloud Sec
quadrant-2 Automated Net Sec
quadrant-3 Passive Net Sec
quadrant-4 Passive Cloud Sec
Holeprint: [0.15, 0.25]
Exposurespan: [0.85, 0.30]
Prismipeline: [0.75, 0.85]
Informalcode: [0.25, 0.75]
Accateway: [0.60, 0.55]
```

## Problem Affected Roles

- IT Asset Manager — IT Operations
- Cloud Security Engineer — InfoSec
- Software Procurement Manager — Finance
- Information Security Analyst — InfoSec
- Enterprise Architect — IT Strategy
- FinOps Analyst — Cloud Cost
- Compliance Officer — Risk Management

## Problem Affected Companies

- High-Growth Tech Firms — Fast Paced
- Multinational Enterprises — Complex Procurement
- Financial Services Firms — Highly Regulated
- Remote-First Organizations — Distributed Workforce
- Healthcare Providers — Strict Compliance
- Creative Advertising Agencies — Tool Heavy
- Higher Education Institutions — Decentralized Faculties

## Problem Affected Processes

- IT Asset Management — Asset Inventory
- Vendor Procurement — Purchasing
- Expense Management — Spend Analysis
- Access Management — IAM
- Cloud Security Operations — Threat Detection
- Application Portfolio Management — Software Rationalization
- Compliance Auditing — Risk Assessment
- Data Governance — Data Security

## Problem Matching Opportunities

- Shadow SaaS Discovery for IT — Autonomous Scanner
- Rogue Asset Detection for DevOps — Continuous Monitoring
- Shadow Identity Mapping for Compliance — Access Graph
- Expense SaaS Discovery for Procurement — Financial Analytics

## Problem Token Hero

**Genre**: problem-hero
**Rendered**: IT and security teams lack visibility into the decentralized adoption of software and cloud infrastructure across the enterprise.
**Mechanism**: overview-derived-v1
**Template Id**: problem-overview-derived
**Vocab Fingerprint**: 981d0a13a16a9924

## Neighborhood

### Related (entails child problem)

- [Lapsed Vendor Credential Exposure](/Problems/Lapsed_Vendor_Credential_Exposure) — entails child problem · Problems

### Competitors

- [Microsoft Entra ID](/Competitors/Microsoft_Entra_ID) — competes with · Competitors
- [Zscaler Internet Access](/Competitors/Zscaler_Internet_Access) — competes with · Competitors
- [Torii](/Competitors/Torii) — competes with · Competitors
- [Productiv](/Competitors/Productiv) — competes with · Competitors
- [Netskope CASB](/Competitors/Netskope_CASB) — competes with · Competitors
- [Expensify](/Competitors/Expensify) — competes with · Competitors

### What it's used for

- [Microsoft Entra ID](/Software/Microsoft_Entra_ID) — used for · Software
- [Netskope CASB](/Products/Netskope_CASB) — used for · Products
- [Zscaler Internet Access](/Products/Zscaler_Internet_Access) — used for · Products
- [Expensify](/Software/Expensify) — used for · Software

### Solves problem

- [Exposurespan](/Startups/Exposurespan) — candidate solution for · Startups
- [Accateway](/Startups/Accateway) — candidate solution for · Startups
- [Prismipeline](/Startups/Prismipeline) — candidate solution for · Startups
- [Informalcode](/Startups/Informalcode) — candidate solution for · Startups
- [Holeprint](/Startups/Holeprint) — candidate solution for · Startups

### Entails child problem

- [Early Transaction Detection](/Problems/Early_Transaction_Detection) — entails child problem · Problems
- [Freemium Access Management](/Problems/Freemium_Access_Management) — entails child problem · Problems
- [OAuth Scope Auditing](/Problems/OAuth_Scope_Auditing) — entails child problem · Problems
- [Welcome Email Parsing](/Problems/Welcome_Email_Parsing) — entails child problem · Problems
- [Workspace Decommissioning](/Problems/Workspace_Decommissioning) — entails child problem · Problems

### Similar Problems

- [Revoke Unmanaged Application Access](/Problems/Revoke_Unmanaged_Application_Access) — similar · Problems
- [Software Seat License Sprawl](/Startups/Rivocess/Problems/Software_Seat_License_Sprawl) — similar · Problems
- [Control Maverick Spend](/Problems/Control_Maverick_Spend) — similar · Problems
- [Reconcile Software Spend](/Problems/Reconcile_Software_Spend) — similar · Problems
- [Eliminate Rogue Maverick Spend](/Problems/Eliminate_Rogue_Maverick_Spend) — similar · Problems
- [Audit Shadow API Subscriptions](/Problems/Audit_Shadow_API_Subscriptions) — similar · Problems
- [Vendor Entitlement Mapping](/Problems/Vendor_Entitlement_Mapping) — similar · Problems
- [Orphaned Account Cleanup](/Problems/Orphaned_Account_Cleanup) — similar · Problems
- [API Key Secret Sprawl](/Problems/API_Key_Secret_Sprawl) — similar · Problems
- [Spend Aggregation](/Problems/Spend_Aggregation) — similar · Problems
- [Security Contract Renewals](/Problems/Security_Contract_Renewals) — similar · Problems
- [Contractor Procurement Standardization](/Problems/Contractor_Procurement_Standardization) — similar · Problems
- [Audit Shadow API Subscriptions](/api/.env/Problems/Audit_Shadow_API_Subscriptions) — similar · Problems
- [Third-Party Vendor Vulnerability](/Problems/Third-Party_Vendor_Vulnerability) — similar · Problems
- [Permanent Guest Provisioning](/Problems/Permanent_Guest_Provisioning) — similar · Problems
- [Resource Ownership Discovery](/Problems/Resource_Ownership_Discovery) — similar · Problems
- [Control Cloud Infrastructure Sprawl](/Problems/Control_Cloud_Infrastructure_Sprawl) — similar · Problems
- [Prevent Auto-Renewal Creep](/Problems/Prevent_Auto-Renewal_Creep) — similar · Problems

### Similar Opportunities

- [Shadow IT Discovery for Security](/Opportunities/Shadow_IT_Discovery_for_Security) — similar · Opportunities

### Similar Metrics

- [Shadow IT Incident Rate](/Metrics/Shadow_IT_Incident_Rate) — similar · Metrics
