Shadow IT

How to find the software your company pays for but nobody owns

7 min read

Most companies have two software estates. There is the one on the spreadsheet - the platforms IT bought, the contracts finance signed off, the tools everyone knows about. And there is the one on the card statement, which is larger, older and has no owner.

The gap between the two is not a governance failure so much as a natural consequence of how software gets bought now. Before you can decide what to keep, you have to find what you have. This is a discovery sweep you can run in an afternoon.

Why unowned software accumulates

Buying moved to the teams

A modern SaaS product is designed to be adopted without a procurement conversation: a free tier, a card field, and a team using it in production by the end of the week. That is genuinely good for getting work done. It also means the purchase leaves no trace in any system that IT or finance watches.

Card charges do not look like contracts

A twelve-month commitment paid monthly on a company card appears in the accounts as twelve small, unremarkable payments. Nothing about the ledger entry says "this renews in March and needs 60 days' notice". The commitment is real; the paper trail that would surface it is not.

People leave, subscriptions stay

When the person who set a tool up moves on, the knowledge goes with them - the login, the reason it was bought, whether anyone still uses it. The payment carries on regardless, because cancelling requires someone to act and nobody knows they are the someone.

Four places to look

No single source shows you everything, and each one catches what the others miss. Work through all four - the overlap between them is the point.

1. Card and bank statements

This is the most reliable source, because it is the one thing every subscription has in common: it gets paid. Export at least twelve months so annual renewals appear, and sort by merchant rather than by date. Look past the obvious platforms - the entries that matter are the small, regular ones you skim over. Include every company card, not just the central account.

2. Your identity provider

If you use single sign-on, the list of connected applications is effectively a list of software people actually log into. It catches tools paid for outside the accounts you checked, and it tells you something the statement cannot: whether anyone is still signing in. Applications with no logins in six months are your strongest cancellation candidates.

3. The email and password trail

Search shared and finance inboxes for the phrases vendors use - receipts, invoices, welcome messages, renewal notices, trial expiry warnings. Shared password managers are worth the same treatment: an entry for a tool tells you it was adopted, even if nobody remembers by whom.

4. The teams themselves

Ask each team what they use, and make it explicitly blameless. If the exercise feels like an audit, people will not mention the tool they expensed last year, and you will miss exactly the thing you are looking for. Frame it as making sure nothing gets cancelled by accident - which is true.

Record findings as you go, not afterwards

Discovery only pays off if the results outlive the afternoon. Put each tool into a single register the moment you find it, with enough detail to make a decision later:

  • What it is and which team relies on it
  • A named owner - the person who would make the call to drop it
  • What it costs per year, and which card or account pays for it
  • The renewal or expiry date, and whether it renews automatically
  • The notice period, if there is a contract - this is the field people skip and later regret

The renewal date and notice period together give you the date that actually matters: the last day you can give notice before the contract rolls over. Our guide on tracking software renewals covers how to work that out and alert on it.

Then make three decisions, not one

A discovery sweep tends to produce a long list and a vague intention to "clean it up". Force each tool into one of three outcomes instead:

  1. Keep - it is used, it is owned, and the renewal date is now in the register.
  2. Consolidate - it duplicates something else you already pay for. Pick the survivor and plan the move for the loser's next renewal, not immediately.
  3. Cancel - nobody uses it or nobody will defend it. Find its cancellation deadline before you celebrate, because that is the date the saving actually depends on.

Two cautions on cancelling. Check who and what depends on the tool first, including any integration quietly running against its API. And export your data before the account closes - access usually ends the day the subscription does.

Stop the estate drifting again

A sweep fixes today's list. Without a change to how software enters the company, you will be running the same exercise next year on a fresh set of tools.

The fix that works is a light one: a single place new tools get logged, an owner recorded at the point of purchase, and a review triggered before each renewal rather than after each invoice. Heavier processes tend to get routed around, which puts you straight back where you started. What you are aiming for is not approval control - it is visibility, so no tool can renew without somebody choosing to let it.

StackTrackr is the register for exactly this: one record per tool, an owner against each, deadlines computed from the notice period, and alerts before the window closes. See the features overview for the full picture, or start free and log what your sweep turns up.

Take control of your software estate.

Start with your ten most expensive tools. In an afternoon you will know every renewal date, every notice period, and who owns what.

No credit card required. Self-hostable. Cancel anytime.

How to find the software your company pays for but nobody owns · StackTrackr