
This is the operational workflow for detecting shadow IT — the unapproved tools your company is using or paying for without finance, IT, or leadership knowing. For the why and the strategy, see the shadow IT guide. This is the runbook: the exact steps, in order, to surface what's hidden.
Run it end to end the first time, then re-run the detection steps quarterly.
You can't find the unknown without a list of the known.
Everything you discover in the next stages that isn't on this list is a shadow IT candidate.
welcome to, your account is ready, you've been invited, confirm your email, your trial has started. Welcome emails mark the birth of a shadow tool.receipt, invoice, subscription confirmed, payment, renews.For each shadow IT candidate, capture:
| Field | Why |
|---|---|
| Vendor | The tool |
| Likely user/buyer | Who to talk to |
| Monthly cost | Spend impact |
| Data access | Security risk — the column most audits skip |
| Still needed? | Keep/cut decision |
Prioritize by risk, not just cost. A free tool holding customer data outranks a $50/month tool that touches nothing sensitive.
Stages 2 and 3 — the billing-trail and payment detection — are exactly what InvoiceAgent automates. It scans your connected billing inbox for signup confirmations, receipts, and trial notices, surfacing the tools your company pays for (including the welcome emails that mark a shadow tool's creation) so you're not running manual searches every quarter. It turns recurring detection from a manual sweep into a continuous signal. The triage, resolution, and prevention stages stay human — but they start from a complete list instead of guesswork.
Run the full playbook once. After that, the detection should be running quietly in the background, so shadow IT surfaces as it appears instead of accumulating until the next audit.
Scan Gmail for software receipts, invoices, signup emails, and renewal notices.
Scan Gmail Free