I was talking with a business owner last month who was sure she knew every tool her company used. Then her sales manager left for a new job. During the transition, she found something odd. For eight months, her whole sales team had been tracking every deal, every follow-up call, and every customer note in a free CRM tool she had never heard of. Nobody asked her about it. Nobody asked IT about it. One person got tired of the shared spreadsheet, signed up for a free account on a slow Tuesday afternoon, and within a few weeks the whole team was using it.
She wasn't angry at her team. She was worried about what else she didn't know about.
This happens more than most business owners realize. It even has a name: shadow IT. It just means employees using apps and tools that ownership never approved, and often never even hears about.
It's Not Rebellion. It's Someone Trying to Get Work Done
Almost nobody sets out to hide anything. They're just stuck, and they solve it the fastest way they can.
Picture an office manager who needs to send a contract for signature today. The company's official process takes two weeks of internal approvals to add a new tool. So she finds a free e-signature site, signs up in five minutes, and gets the contract out the door. Nobody at the company decides "let's use unapproved software." Someone just has a job to finish and a tool that gets it done right now.
This is far more common than most owners expect. Recent industry research puts the number of unsanctioned apps running inside the average company at over a hundred, and roughly 8 in 10 employees say they've used some kind of app or software at work without asking IT for permission first. The pattern shows up everywhere: a marketing coordinator using a free design tool because the approved one is clunky, a bookkeeper emailing spreadsheets to a personal account to work from home, a project lead running a group chat in an app the company never set up.
None of this is malicious. It's resourceful. Your team wants to do good work, and they'll route around anything that slows them down. That's actually a compliment to how much they care about getting things done. It's just happening somewhere you can't see it.
The Real Risk Isn't the App. It's Everything Around It
A free tool by itself usually isn't dangerous. The trouble comes from what happens next, once real business information starts living inside it.
Your data gets scattered. Customer details end up in three different places: the CRM everyone knows about, a spreadsheet on someone's laptop, and now a fourth tool nobody mentioned. When you need one clear answer, like "how many active customers do we have," you can't get it. Nobody can, because no single place holds the whole picture anymore.
Nothing gets backed up. Your official systems are almost certainly backed up somewhere. That free scheduling app one employee signed up for on their own probably isn't backed up by anyone, including the company that built it. If that employee forgets their password, leaves the company, or the app itself shuts down one day, that information can simply disappear. You can't back up what you don't know exists.
Security has a blind spot. IT and security tools can only protect what they know about. A tool nobody reported never gets a security check, never gets patched, and never gets reviewed for how it handles sensitive information. Industry breach research from 2025 found that roughly one in three data breaches involved information stored somewhere the company wasn't actively tracking or managing. That's not a small crack in the wall. That's an open door nobody knew was there.
There's a cost angle too. Research from Capterra found companies spend tens of thousands of dollars a year on software subscriptions nobody is even using anymore, often because the person who signed up moved on and the subscription just kept charging quietly in the background.
How to Find Out What Your Team Is Actually Using
Here's the good news: finding this out doesn't require a crackdown, and a crackdown would backfire anyway. People hide things faster when they feel accused.
Start with a simple, honest question in a team meeting: "What tools or apps are you using day to day that help you get your work done?" Frame it as genuine curiosity, not an interrogation. Most people will tell you, especially if you make clear nobody's in trouble.
Then check the paper trail. Look through company credit card and expense statements for small, recurring charges you don't recognize — that's often a subscription someone signed up for months ago. A quick look through the company email inbox for "welcome" or "your subscription" messages turns up more than you'd expect.
Talk to anyone who joined recently, too. New hires notice things veteran employees stopped seeing, like "oh, everyone uses that other scheduling app, not the one in the handbook."
Give People Tools They Actually Want to Use
Once you know what's really being used, the real fix isn't banning things. It's asking why people went looking in the first place, and closing that gap.
If your official tools are slow, missing an obvious feature, or take weeks to get approved for, that's the root problem. Ask your team directly what's missing. Sometimes the fix is small: a faster approval process for new software requests, or one feature added to a tool you already have. Sometimes it means replacing an old system that everyone's quietly been working around for years.
Once you know what tools are actually in use, it's worth checking who has access to each one and how. That's a related problem I've written about separately — shared logins on tools you do know about carry their own risks. And if a tool nobody else understands turns out to be sitting entirely with one employee, that overlaps with another risk worth knowing about.
The goal isn't a perfectly locked-down company. It's knowing what you're actually working with, so nothing catches you off guard the way that CRM caught this business owner off guard.