Shadow IT
Updated August 22, 2026
Software a team buys and uses without going through IT or finance. Nobody is hiding anything as a rule: someone needed a tool, expensed it, and the purchase never reached a system that tracks purchases.
How do you find shadow IT without installing anything?
Through the money. The standard approaches watch identity or the network: single sign-on logs, a browser extension, an agent on the laptop. Each of those sees the tools that touch the thing it monitors, which means a tool bought with a card and used in a browser tab outside SSO stays invisible. Payment is the one signal every purchase produces, because a tool nobody pays for is not a spend problem.
That is why a general ledger is a better discovery surface for this than an IT tool, and why it needs no software installed on anybody's machine.
What can a ledger not tell you about shadow IT?
Who is using it, or whether anyone is. A ledger records what was paid, not who logged in. Seat-level usage is a different data source and a different question; anything promising both from accounting data alone is overstating what accounting data contains.
Every term in this glossary is defined from the general ledger, because that is the one place a company's whole software estate is already written down. See how a software spend audit reads a ledger for what that involves.