What counts as shadow IT
Shadow IT covers technology in use without IT governance: departmental SaaS subscriptions on a company card, spreadsheets that have become de facto systems of record, personal messaging tools carrying client data, automations built by whoever knew how. Cloud pricing made it trivial to acquire; expense thresholds keep it invisible.
Why it matters at decision time
Any decision scoped against the official estate inherits the gap. Migrations discover mid-flight that a "simple" legacy system feeds forty unofficial spreadsheets, each now a stakeholder. Security assessments certify a perimeter the actual data left long ago. Software selections evaluate requirements drawn from the official process while the real workflow, the one users built for themselves, goes unexamined, which is one reason new platforms meet such puzzling resistance. Sizing the shadow estate belongs in the preparation for all three.
The misreading that makes it worse
Treating shadow IT purely as a discipline problem misses what it is: evidence, gathered at the users' own expense, about where the sanctioned tools fail them. Crackdowns push the same behaviour onto personal devices and private accounts, where the risk is worse and the visibility is zero. Organisations that periodically inventory it without punishment learn where demand is unmet. The alternative is learning at audit, breach or migration.