OpenFrame Gen1 is Here

Your client's marketing team signed up for three AI writing tools last quarter. Their sales lead keeps proposals in a personal Dropbox. Someone in finance built a billing workflow in a no-code app nobody has heard of. None of it came through you, and all of it lands in your incident report when something breaks. Shadow IT is any software, hardware, or cloud service running inside an environment without approval from the people responsible for securing it, and when you're the MSP, that's a visibility gap with your name on the contract.

TL;DR: Shadow IT for MSPs

  • Definition. Shadow IT is any app, device, or cloud service running in a client environment without IT approval or oversight.
  • Scale. BetterCloud research puts roughly 65% of SaaS apps in use outside IT's approval path.
  • Cost. IBM's 2025 Cost of a Data Breach report tied shadow AI to 20% of breaches and an extra $670,000 per incident.
  • Fix. Detect across four signals (identity, network, endpoint, spend), score by data sensitivity, then govern with an approved catalog instead of a blanket ban.

What Shadow IT Looks Like in a Client Environment

The textbook examples are personal cloud storage, unapproved messaging apps, and BYOD laptops. Those still show up, but they're no longer where the risk concentrates. In 2026 the common finds are free-tier SaaS bought on a personal card, browser extensions with read access to every page a user opens, no-code automation platforms wired into a CRM, and AI assistants pointed at customer data.

The pattern behind all of them is the same. Someone had a job to do, the sanctioned path was slower than a credit card and a signup form, so they took the faster route. Shadow IT is a symptom of a gap between what the sanctioned stack does and what the work requires. That framing matters, because it's the difference between a governance program that works and one that gets routed around within a quarter.

There's a second pattern worth naming: shadow IT rarely stays personal. A single free-tier project management tool spreads to a team, picks up client data, and becomes load-bearing. By the time you find it, removing it breaks a workflow the business depends on. Detection speed is the whole game.

It also helps to separate the three shapes it takes, because each needs a different response. Unsanctioned SaaS is the largest category by count and usually the easiest to bring under control, since it authenticates against an identity you administer. Unmanaged hardware, meaning personal laptops, home routers used for work, and the odd device somebody plugged into a client network, is rarer but carries the worst blast radius when it goes wrong. Unapproved AI is the newest and moves fastest, partly because the tools are free and partly because using one feels like a productivity choice rather than a technology decision. A single governance policy that treats all three identically will fit none of them well.

Why the Numbers Got Worse in 2026

BetterCloud's SaaS research puts roughly 65% of applications in use outside IT's approval path, with shadow IT accounting for around 34% of the average SaaS portfolio while consuming only 4% of tracked SaaS spend. That gap between usage share and spend share is the reason procurement reviews miss it. Free tiers and personal cards leave no trail in the systems finance watches.

AI made the curve steeper. Microsoft's WorkLab research found 78% of employees bringing their own AI tools to work. Industry surveys put the share who admit exposing sensitive company data to those tools around 33%. Vendors like Nudge Security and JumpCloud have documented the same trend from different angles: unsanctioned AI is now the fastest-growing category of unmanaged software in business environments.

Then there's the money. IBM's 2025 Cost of a Data Breach report found shadow AI involved in 20% of breaches, adding roughly $670,000 to the average incident and displacing the security skills shortage from the top three cost amplifiers. Of the organizations hit by AI-related incidents, 97% had no access controls on the AI tools in question. Shadow data spread across multiple storage locations pushed breach lifecycles from 234 days to 291 and added about $730,000 in cost.

For a US-based client, the baseline matters too. IBM put the average US breach at $10.22 million in 2025. You don't need to sell that number hard. You just need to put it next to a list of forty unsanctioned apps you found in their tenant.

The Authority Gap Nobody Writes About

Every major guide on this topic (IBM, CrowdStrike, Cisco, Proofpoint) is written for an internal IT team that owns the environment. They can mandate policy, block domains, and fire off a company-wide email on Monday morning. You can't, and that changes the entire playbook.

An MSP sits in a position with responsibility but only borrowed authority. You get blamed for the breach. You don't get to write the HR policy. You can see the traffic but you may not have contractual permission to block it. You can find the rogue app but the person who bought it reports to a director who outranks your day-to-day contact.

This is where a lot of shadow IT programs stall. The technical discovery is the easy part. Turning a spreadsheet of unsanctioned apps into a real decision requires a client sponsor who can say yes, a documented scope that says you're allowed to look, and language in the agreement that assigns risk when the answer is no. If your MSA is silent on unapproved applications and you knew about them, silence works against you. Get the scope of monitoring, the reporting cadence, and the client's acceptance of residual risk into the agreement before the first scan, not after the first incident.

The upside of the borrowed-authority position is real, though. You see across every client. An unvetted AI note-taker that shows up in three tenants in the same month is a pattern an internal team would never spot. That cross-client view is the thing you can sell.

Five Ways to Detect Shadow IT and What Each One Misses

No single signal finds everything. Identity logs miss anything without SSO. Network monitoring misses the laptop on home Wi-Fi. Endpoint agents miss unmanaged BYOD. Expense review misses free tiers, which is where the AI tools live. Run at least three of these in parallel and treat the overlap as your confidence score.

Detection methodWhat it catchesWhat it missesEffort to run
Identity provider logs (Entra ID, Okta, Google Workspace)Any app users authenticate to with a work account, including OAuth grantsApps with local accounts, personal-email signups, anything outside SSOLow. Native reports, no new agent
DNS and network filteringCloud services reached from managed networks and VPNOff-network devices, mobile data, home Wi-FiLow to medium. Often already in the stack
Endpoint agent or browser extensionInstalled software and web apps used on managed devices, regardless of networkPersonal and unmanaged devices, contractor laptopsMedium. Deployment and privacy conversation required
Expense and card reviewPaid subscriptions on company cards, including departmental purchasesFree tiers, personal cards later expensed, annual prepaidMedium. Requires finance cooperation
SaaS management or CASB platformBroad app inventory with risk ratings, often thousands of known appsCosts money, needs tuning, still blind to unmanaged endpointsHigher. Real licensing and setup

OAuth grant review deserves a specific call-out. In most tenants, the single fastest win is pulling the list of third-party applications users have granted access to their work identity. A browser extension with mailbox read scope does not appear in expense reports, does not need an install, and does not care what network the user is on. That report takes about ten minutes and reliably surprises people.

If you're building this into a broader defensive layer, discovery pairs naturally with the rest of the controls in a modern MSP security stack. And the asset inventory side of the problem overlaps almost entirely with IT asset management tooling you may already be running.

Scoring What You Find Before You Touch It

A raw list of ninety applications is not useful to a client. It reads as noise, and it invites the worst possible response: block them all, break six workflows, and watch users route around you with personal devices. Score first.

Three questions sort almost everything. Does the app touch regulated or customer data? Does it hold a persistent credential or OAuth grant into a core system like email, CRM, or file storage? Is it load-bearing for a business process right now? An app that answers yes to the first two is an incident waiting for a date. An app that answers yes only to the third is a procurement conversation, not a security one.

That sorting produces four practical buckets. Sanction and secure the tools the business genuinely needs, and bring them under SSO and MFA. Replace the ones that duplicate something already licensed, which is where the cost story lives. Remove the ones with real exposure and no business case. Monitor the low-risk remainder rather than spending political capital on it.

The cost angle is the part clients hear. Duplicate subscriptions are common in the finding, and consolidating them funds the rest of the engagement. The same logic that drives a full stack audit applies inside your clients' environments, not just your own.

The Client Conversation That Decides Everything

How you present the findings determines whether you get a governance mandate or a defensive client. Lead with the business consequence and the fix, not with a list of people who broke rules. Naming individuals turns a security review into an HR problem, and the next round of shadow IT simply gets better at hiding.

Language that works: "We found 41 cloud services in use across your environment. Twelve hold customer data. Four have standing access to your email tenant. Here's what we'd sanction, what we'd replace, and what we'd shut down, with the license savings on the same page." That framing gives the client a decision to make instead of a mistake to defend.

Then close the loop on process. If people went around IT because requests took two weeks, publishing a shorter approval path does more for your risk posture than any block list. An approved catalog with a 48-hour request path removes the incentive that created the problem. Governance that only says no gets ignored quietly.

The approved catalog is worth building properly rather than as a PDF nobody opens. Keep it to the tools a given client is licensed for, note which ones are already covered by SSO and MFA, and name the sanctioned alternative for the categories where people keep going rogue. If three departments independently signed up for the same transcription tool, that category needs a sanctioned answer, not a warning. Reviewing the catalog once a quarter alongside the discovery report keeps it from going stale, and it gives the client's leadership a document they can point staff at without involving you every time.

Put the results in the quarterly business review as a recurring line item. A shadow IT count that trends down over three quarters is the cleanest proof of value an MSP can put in front of a client, and it renews contracts on its own.

Turning Discovery Into a Service Line

Shadow IT discovery works better as a productized service than as a favor. The work is repeatable, the deliverable is concrete, and the finding usually pays for the engagement through recovered license spend.

A workable shape: a fixed-fee initial assessment covering identity, network, endpoint, and spend discovery, delivered as a scored inventory with recommendations. Then a recurring monthly fee for continuous monitoring, new-app alerting, and a quarterly report. Price the assessment against the license savings you expect to surface, and price the monitoring per seat so it scales with the client.

The 2026 version of this includes AI. Shadow AI detection is a distinct offer, and clients understand it faster than generic SaaS governance because the headlines did the selling. Discovery of AI tools, review of what data those tools receive, and a sanctioned AI policy is a package a director-level buyer can approve without a security committee.

Vendors including Augmentt, Nudge Security, and JumpCloud sell tooling into exactly this motion, which tells you the demand is validated. Your advantage over a pure software play is that you sit inside the environment already and can act on what you find.

Where Your Own Stack Fits

Detection creates the finding. Something has to act on it, and that's where fragmentation costs you. When identity data sits in one tool, endpoint telemetry in another, ticketing in a third, and the asset inventory in a spreadsheet, correlating a rogue app to a device, a user, and a ticket becomes manual work nobody has time for at scale.

OpenFrame, the AI-native all-in-one MSP/IT platform Flamingo builds, is designed for that correlation problem. Native PSA and RMM in one platform means the discovery signal, the affected assets, and the client conversation live in the same system, and the AI layer handles the triage that would otherwise eat a technician's afternoon. It's the no-lock-in option here, priced so that adding governance work to your service catalog doesn't get eaten by another per-seat vendor increase. Whether OpenFrame fits depends on how much of your current stack you're willing to consolidate, and that's a real trade-off worth weighing.

Your First 90 Days

Start narrow. Pick two clients, run identity and OAuth discovery, and score what comes back. That takes days, not months, and it gives you a real deliverable to build the offer around.

  1. Days 1 to 30. Pull OAuth grants and sign-in logs from every client tenant you already administer. Sort by data sensitivity. Get monitoring scope and residual-risk language into your MSA template.
  2. Days 31 to 60. Layer DNS and endpoint discovery onto the two pilot clients. Build the scored-inventory deliverable and run the findings conversation with a client sponsor who can approve changes.
  3. Days 61 to 90. Publish an approved-app catalog with a 48-hour request path, add the shadow IT count to the QBR deck, and price the assessment and monitoring tiers for the rest of your base.

Shadow IT isn't a discipline problem inside your clients' companies. It's a demand signal telling you exactly which gaps in the sanctioned stack are big enough that people paid to route around them. Find them first, and you're the one who gets to close them.

Kristina Shkriabina

Marketing Manager

Ohayo! I'm Kristina, and I'm doing good things with content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Shadow IT Governance

Shadow IT means any software, hardware, or cloud service running inside an organization without approval or oversight from the team responsible for securing it. It covers unsanctioned SaaS, personal devices used for work, and AI tools nobody vetted.
Common examples include free-tier SaaS bought on a personal card, proposals stored in a personal Dropbox, browser extensions with mailbox read access, no-code automation wired into a CRM, and AI assistants pointed at customer data. Unmanaged personal laptops count too.
Shadow IT creates exposure nobody is monitoring. IBM's 2025 Cost of a Data Breach report tied shadow AI to 20% of breaches and roughly $670,000 in added cost, and found 97% of affected organizations had no access controls in place.
Employees use shadow IT because the sanctioned path is slower than a signup form. It signals a gap between what the approved stack does and what the work requires, which is why shortening the approval path reduces it faster than blocking does.
Combine at least three signals: identity provider logs and OAuth grants, DNS or network filtering, endpoint or browser telemetry, and expense review. Each has blind spots, so overlap between them becomes your confidence score. OAuth grant review is usually the fastest win.
Shadow AI is a subset of shadow IT, but it moves faster and carries different risk. The tools are free, feel like productivity choices rather than technology decisions, and often receive customer data directly. It needs its own policy, not a generic ban.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.