Stackpack Blog

Shadow IT & Duplicate SaaS Subscriptions: A Finance-Led Buyer Guide

Detect shadow IT and shadow AI, find duplicate SaaS subscriptions, and run lightweight software asset management without a procurement team.


TL;DR

  • Shadow AI runs inside 70% of companies, according to Vanta's analysis of 16,000+ customers, and unsanctioned tools now make up 55% of the average vendor footprint.
  • Companies carry 7.6 duplicate subscriptions on average and pay for two to three times more software than they actively use, so overlap hides inside spend that already looks legitimate.
  • Lightweight discovery tools now close the visibility gap that once required a full procurement team, using identity logs and financial data instead of manual audits.
  • Stackpack is this guide's top pick for lean finance, ops, and IT teams. Enterprise platforms like Zylo and Flexera fit larger orgs but bring quote-only pricing and IT-heavy rollouts.

What shadow IT, shadow AI, and duplicate SaaS spend actually mean

Shadow IT is any software your company pays for or runs without finance or IT sanctioning it first. A sales rep expenses a scheduling tool, a designer signs up for a paid plan on a personal card, and neither purchase ever hits a procurement queue. Vanta found that 55% of the average organization's vendor footprint is now Shadow IT, meaning over half the tools touching your data were never reviewed by anyone. Only 2% of those vendors ever get a security review, so most of them run unchecked against your budget and your data.

Shadow AI is the newer branch of the same problem. It covers standalone AI tools employees adopt without approval and AI features switched on inside apps you already pay for. Vanta reports that 70% of companies now have Shadow AI operating in their environment, and the tools topping the list are mainstream names like Anthropic, OpenAI, and Cursor rather than obscure startups. Because these vendors touch source code, customer data, and internal documents, Vanta rates them 52% more likely to be high risk than traditional SaaS.

Duplicate SaaS spend is the quieter waste line. It happens when different teams buy separate paid tools for the same job and nobody connects the invoices. Marketing pays for one email platform and sales pays for a second to run sequences, so you fund overlapping products with no shared data. Organizations average 7.6 duplicate SaaS subscriptions, according to Ortto, and most finance teams never see the overlap because each charge looks legitimate on its own.

AI tools make all three of these problems worse. A new AI product usually needs no IT ticket and no purchase order, since it starts free and converts to paid through a self-serve checkout an employee completes in minutes. That low friction is why Vanta measured a 36% year-over-year increase in overall Shadow IT, driven almost entirely by AI adoption. Every frictionless signup adds another line finance has to find, review, and reconcile after the fact.

Why AI adoption is driving SaaS sprawl

AI tools spread through a company faster than any previous software category because signing up takes a credit card and a work email, not an IT ticket. According to Stackpack's Beyond Benchmarks 2026 data, AI spend grew 2.2x in 2025, rising from roughly $16,000 to about $34,000 per company. The median company now pays for six to eight AI vendors, and AI already accounts for around 7% of the enterprise software wallet. That growth stacks a fast new sprawl vector on top of the shadow IT companies already struggled to track.

AI tools enter the building through a path finance cannot see until it is too late. Anthropic, OpenAI, and Cursor top the list of shadow AI tools found in company environments, and none of them require procurement approval to start using. An employee moves from a free tier to a paid seat in a single click, and finance sees the charge only when the card statement lands.

Blocking these tools does not stop the spread. Vanta's analysis of 16,000+ customers found that employees reinstall revoked or blocked tools more than 100 times within 30 days, climbing to roughly 1,000 reinstallations over a year. Prohibition just moves the same tool to a personal account or a different card, where you lose all visibility instead of gaining control.

Embedded AI makes prohibition even less useful. Gartner forecasts that by 2026, 70% of employee AI interactions will happen through features built into SaaS applications you already pay for, not standalone tools you can block. You cannot ban a feature inside Slack or Notion. Because you can only govern spend and risk you can see, detection matches how AI actually enters your stack better than prohibition does.

How to detect shadow IT and unauthorized SaaS/AI signups

Three signal sources give a finance or ops lead enough coverage to find shadow tools without a security team, and none of them require a spreadsheet audit. Your identity provider logs (Okta, Google Workspace, Microsoft Entra) record every app employees sign into with their work credentials, which surfaces tools nobody filed a ticket for. Your corporate card and expense data catches the rest, since even self-serve AI subscriptions leave a charge on someone's statement. Automated discovery tools connect both feeds and match them against a vendor catalog, so you see the full footprint instead of the slice you already knew about.

Manual spreadsheet audits fail because they can only capture what you already know to look for. 55% of the average organization's vendor footprint is now shadow IT, meaning over half the tools touching company data never make it onto anyone's list. When Vanta connected identity providers for its customers, teams discovered roughly 140 shadow tools within 90 days. A finance-led audit built on invoices and memory would have missed nearly all of them, because the tools generating small or free-tier charges leave the faintest paper trail.

AI signups slip past review even more often than traditional SaaS. Only 2% of shadow vendors ever undergo a security review, so the vast majority of tools handling code, customer records, and internal documents are never risk-assessed. AI vendors carry more exposure than that gap suggests, since they run 52% more likely to be flagged high-risk than standard SaaS because they touch sensitive data and intellectual property. The most common tools showing up are mainstream names like Anthropic, OpenAI, and Cursor, not obscure apps you could reasonably dismiss.

One-time audits break down against this pattern because new tools appear faster than a quarterly sweep can catch them. Shadow AI is driving a 36% year-over-year rise in overall shadow IT, so a clean audit in January describes a stale picture by March. Continuous detection reads the same identity and expense signals on an ongoing basis, which means a new signup registers within days rather than surviving unseen until the next review. The cadence matters most for AI tools, where the window between an employee's first login and real data exposure is short.

How to find duplicate subscriptions across departments

Duplicate subscriptions hide inside sanctioned spend, which makes them harder to catch than shadow signups. A marketing team pays for one email platform, sales runs sequences through a second, and customer success sends lifecycle messages through a third, and every one of those purchases clears approval with a legitimate invoice behind it. The overlap only surfaces once someone lines up all three against the same job. Organizations carry an average of 7.6 duplicate SaaS subscriptions, meaning two or more licenses for the same tool bought by different teams who never compared notes.

You can surface most of that overlap with three passes a lean finance team can run in an afternoon. Start with category-based spend grouping. Pull every recurring software charge, then sort tools by the function they serve rather than the department that pays for them. Three "email" tools, two "project management" tools, and four "AI writing" tools jump out fast once the vendor names sit next to their category instead of their cost center.

Next, cluster by renewal date. Group subscriptions coming up for renewal in the same quarter, because overlapping tools rarely renew on the same day and the calendar view shows you where you have negotiating leverage. A duplicate you catch two weeks before its auto-renewal is a canceled contract. The same duplicate caught two weeks after is a sunk cost for another year.

Finally, flag by usage. A duplicate where both tools show active logins signals a real workflow split worth understanding. A duplicate where one tool sits at near-zero usage is a straight cancellation with no downside. Usage data separates the overlaps that need a conversation from the ones you can cut without asking anyone.

This needs no procurement process or application rationalization framework, just your spend data grouped by function, sorted by renewal date, and checked against usage. Automated discovery tools like Stackpack run these groupings continuously instead of once a quarter, which matters because a new duplicate appears every time a team signs up for a tool another team already pays for.

Comparing shadow IT and SaaS management platforms

Most tools in this category were built for organizations with a dedicated IT or procurement function, and their pricing and rollout weight reflect that. Zylo frames itself around identity governance for IT and security teams, with quote-only pricing starting near $35,000 a year on its AWS Marketplace listing. Flexera targets large organizations with complex hybrid IT environments, with a steep learning curve and multi-source setup. BetterCloud skews toward large enterprises, with a two-month implementation and annual costs that reach into six figures. Torii publishes only its entry tier and hides automation and renewal features behind unpriced Professional and Enterprise plans.

That weight fits the IT and procurement teams these products were designed for, but it overshoots what a finance or ops lead needs when the goal is spend visibility and renewal control, not a staffed rollout. The table below sorts each option by who it actually fits and what you give up to use it.

PlatformBest for Tradeoff
Stackpack SMB and mid-market finance, ops, and IT teams that want spend visibility and renewal control without a procurement-heavy rolloutBuilt for lean teams, so it skips the deep IAM and compliance tooling that large security orgs may expect
ZyloLarge enterprises with a dedicated SaaS operations or procurement functionEnterprise pricing and rollout weight that outmatch what a 30-to-500-person team needs
ToriiMid-size and enterprise IT teams comfortable with automation-heavy workflowsAutomation and renewal features sit behind unpriced tiers, and the entry plan omits most of them
ZluriIT and security teams that need identity governance alongside SaaS managementCustom quotes near $35K a year and a feature set reviewers call overwhelming for smaller teams
BetterCloudLarge enterprises automating IT lifecycle tasks across many SaaS appsFive-figure minimum spend and a roughly two-month implementation aimed at IT admins, not finance
FlexeraEnterprises managing complex on-premises, SaaS, and cloud IT estatesQuote-only pricing, a steep learning curve, and setup that demands real IT expertise

Read the tradeoff column across the rows and one pattern stands out: quote-only pricing, multi-week or multi-month rollouts, and an IT-first buyer persona repeat almost everywhere. That depth serves a security team with a procurement office. It becomes an unwanted project for a finance or ops lead who just wants to find duplicate subscriptions and stop surprise renewals. Stackpack was built to sit apart from that pattern, for the reasons below.

Why Stackpack fits finance-led teams without a procurement function

Stackpack finds the spend a lean finance team can't see, and does it in the time it takes to run a payroll cycle. Across our customer base, we surface an average of 35 ghost vendors per company, tools paid for but invisible to finance until discovery pulls them into view. Stackpack customers cut software spend by 15% and reclaim roughly 1,350 hours a year they used to lose chasing renewals and reconciling invoices by hand. You get to that visibility because we read your actual financial data through direct NetSuite and QuickBooks integration, so the vendors it flags are the ones already hitting your books.

You connect your accounting system and identity data, and Stackpack is live in about 30 minutes. That speed exists because Stackpack maps your stack from spend and login signals rather than asking you to build a vendor inventory first. A finance manager or ops lead can run the whole thing without opening a security ticket or standing up a procurement workflow.

Competing platforms require a heavier commitment before you see any value. Torii, Zluri, and Flexera publish quote-only pricing and route buyers through a sales process before anyone sees a number, which means you commit to a scoping call before you know the cost. Their implementations run multi-week to multi-month because they were designed for IT and procurement teams managing large, hybrid estates with formal approval chains. BetterCloud follows the same pattern, with rollouts that assume a dedicated admin owns the tool day to day.

Stackpack's narrower scope is the honest tradeoff, and for a 30-to-5,000-employee company it works in your favor. Stackpack skips the automated deprovisioning workflows and enterprise policy engines of a full IT lifecycle platform, and concentrates instead on the financial control problems a finance-led team actually owns: duplicate subscriptions, ghost vendors, and renewals that slip past the calendar. A procurement department with a security team writing vendor review policy will get real use out of an IT-heavy platform's rollout weight. Without either of those functions, that same machinery is cost and delay nobody asked for.

For SMB and mid-market finance teams that need spend visibility and renewal control this quarter rather than next fiscal year, Stackpack is the top pick in this guide. Zylo fits large enterprises with the staff to run it, and Flexera fits IT-heavy organizations managing complex on-prem and cloud estates.

A lightweight software asset management action plan

You can stand up a working software asset management practice in a few weeks, not a quarter, if you run these five steps in order. Each one closes a specific financial-control risk, so treat the sequence as risk reduction rather than a tidy-up project.

Start by connecting your identity provider and financial data sources. Your SSO logs show who is logging into what, and your NetSuite or QuickBooks feed shows what you actually pay for. Together they turn card statements and directory records into the single view discovery needs.

Run discovery once those sources are connected. Automated stack discovery reads authentication and spend signals to surface tools nobody registered with IT, including the AI signups that never went through a review. It closes the risk of unreviewed AI tools touching your data before anyone knows they exist.

Flag duplicates and ghost vendors next. Group spend by category to catch three teams paying for three tools that do the same job, and isolate vendors that still bill you but show no active users. Stackpack reports finding an average of 35 ghost vendors per company, and every one is a subscription you can cancel or renegotiate.

Build a renewal calendar from what discovery surfaces. Map every contract to its renewal date so no auto-renewal slips through unreviewed. A missed renewal is either wasted spend on a tool you meant to drop or a lost window to negotiate before the price resets.

Set a recurring quarterly review. Shadow AI grows continuously, so a one-time audit goes stale within a quarter. Reviewing discovery, duplicates, and upcoming renewals every three months keeps forecasting accurate and stops sprawl from rebuilding faster than you cut it.

FAQ

How is shadow IT different from shadow AI?

Shadow IT covers any software your teams buy and use without IT or finance approval, from project management tools to expense apps. Shadow AI is the subset made up of unsanctioned AI tools and AI features nobody has reviewed, and Vanta found it now drives a 36% year-over-year increase in overall shadow IT. Shadow AI carries higher stakes because those tools touch code, customer data, and IP that a standard SaaS app never sees.

Does a 100-person company really need SaaS management software?

SaaS management software tracks the tools, subscriptions, and spend a company accumulates as it grows. Even at 100 people, sprawl shows up well before a procurement function does: organizations average 7.6 duplicate SaaS subscriptions and pay for two to three times more software than they actively use, and a lean finance team has no capacity to track that by hand. Stackpack pulls spend from NetSuite and QuickBooks so a 100-person company gets the same visibility a procurement team would build, without hiring one.

How long does detection take to show ROI?

Faster than most buyers expect, because the waste is already sitting in your billing data. Stackpack goes live in about 30 minutes and surfaces an average of 35 ghost vendors per company, which is where the first spend cuts come from. Companies report roughly a 15% reduction in software spend and 1,350 hours saved annually once duplicates and unused licenses are flagged, so the payback lands in the first renewal cycle rather than a year out.