Shadow IT is usually diagnosed as a discipline problem and policed accordingly, which is why the policing never works. It is a user experience problem: buying software takes a credit card and ten minutes, while asking procurement takes a form and three weeks. The fix is a front door that is faster than the workaround, with AI triage behind it that catches the duplicate before the second contract exists.
Nobody sets out to build shadow IT. A team needs a whiteboard tool before Thursday's workshop, the manager has a corporate card and a $5K threshold, and the path of least resistance does what paths of least resistance do. Multiply by every team with a deadline and a card, and three years later the company owns four whiteboard tools, three project trackers, two e-signature platforms, and a subscription graveyard nobody can name, each renewing on its own silent auto-renewal, none of it benchmarked, none of it on the renewal calendar, and some of it holding customer data that security has never reviewed.
The waste has three layers, and the money is the smallest. Duplicated spend is real but bounded. The unmanaged renewals are worse, because every off-book contract is a notice window nobody watches and an uplift nobody negotiates. And the data exposure is worst, because the tool procurement never saw is also the tool that never went through a security review. All three trace to the same root: the sanctioned path lost a usability contest with a credit card.
Purchase intake on the platform takes a short form or a plain email, deliberately lighter than a vendor's own signup flow, and the AI triage runs the moment the request lands. Every request gets classified four ways.
Duplicate? The request is checked against the estate you already own, by capability rather than by name, because the requester asking for "Miro" does not know the company owns Mural. This is the check that pays for the whole system: the answer "we already have a tool that does this, here is your license by Thursday" kills the shadow purchase by being faster than it.
Renewal in disguise? A surprising share of "new" requests are expansions or re-buys of something under an existing agreement, where the negotiated rate already applies and buying outside it pays list for no reason.
Over threshold? Requests above your approval lines route into the proper process automatically, with the benchmark attached from the first touch, so the negotiable purchases get negotiated from day one.
Genuinely net-new? Then it flows into sourcing with the groundwork already done: category, alternatives from the estate and the market, and the security review queued. The requester gets a tracked request instead of a black hole, which is the entire difference between a front door people use and one they route around.
Intake protects the future. The past is already in your systems, and two of the background jobs surface it without anyone running a project. The weekly anomaly watchdog flags tool overlap, multiple products in the estate doing the same job, and shadow spend, recurring software charges in the invoice and expense stream that match no known contract. Each finding arrives priced, because a duplicate that costs $8K a year and one that costs $300K a year deserve different meetings.
What you do with the findings matters more than finding them. The wrong move is the amnesty-free crackdown, which teaches teams to hide purchases better. The right sequence is gentler and pays more: fold the discovered tools into the estate first, onto the renewal calendar, into the security review, under negotiated terms, and consolidate second, at natural renewal boundaries, when the switching conversation has a date and the usage data to stand on. Shadow IT that has been adopted is just IT. The problem was never that teams chose tools. It was that the company was paying retail for chaos.
The honest limit: no intake process reaches the purchase that never becomes a request, the free tier quietly holding company data, the personal subscription expensed as "software, misc." That tail is a security tooling problem as much as a procurement one. What the front door and the watchdog reliably end is the expensive middle: the duplicate contracts, the retail-priced repeat purchases, and the renewals nobody owned. Which, for most companies, was most of the bill all along.
Fredrik has spent more than twenty years in enterprise software, with time at Oracle, IBM, SAP, and Salesforce before moving to the buy side. He structured and priced the kind of large agreements most buyers only see once or twice in a career, which taught him where the leverage sits and how far a vendor will actually move. He started VendorBenchmark to hand that knowledge to every sourcing team.
What shipped on the platform, and the pricing and licensing moves worth knowing before your next renewal. One email a week, to your work address. Unsubscribe any time.