---
name: shadow-it-rationalization
description: Finds unapproved or overlapping software from spend, usage, security, and approved-tool records, then produces a rationalization plan with risk, savings, and decision backlog. Use for shadow IT reviews, SaaS portfolio cleanup, tool consolidation, software governance, and renewal planning.
license: Apache-2.0
metadata:
  adlass.categories: "it-security/vendor-risk, operations/supplier-management"
  adlass.industries: ""
  adlass.tags: "shadow-it, saas, rationalization, software, governance, savings"
  adlass.adaptation: "mapping"
  adlass.source: "original"
  adlass.version: "1"
---

# Shadow IT rationalization

## Purpose

Create a reliable inventory of software purchased or used outside the approved portfolio and identify security exposure, duplication, owner gaps, and consolidation opportunities.

## Scope

Spend records, software inventory, usage, approved catalogue, security requirements, contracts, and user or business-owner data. **Excluded:** disabling tools, migrating users, cancelling contracts, or making security approvals.

## Data basis

- Spend and vendor records, usage data, and software catalogue.
- Approved-tool list, security baseline, and data-classification rules.
- Contracts, renewal dates, owners, and business capability descriptions.

## Result

A normalized tool inventory, rationalization plan, and decision backlog with evidence, cost basis, and unresolved ownership.

## Quality criteria

- Every tool has vendor, product, owner, usage, approval, and renewal status or a gap.
- Similarity groups cite the capabilities compared.
- Risk and savings are kept separate.
- Recommendations do not imply a completed migration or cancellation.

## Instructions

Normalize vendor and product names without losing source values. Treat spend without usage as an ownership lead, not proof of adoption. Group tools only by evidenced capability overlap. Use company risk and renewal rules; otherwise label assumptions and avoid invented savings.

The review should make the population, calculation basis, and exception treatment understandable to a second operator. Preserve source identifiers in every working table, and state the effect of missing evidence on the decision. A reviewer must be able to reproduce each material result from the cited rows, clauses, dates, or policy rules. Where two sources disagree, show both values and explain which source was treated as authoritative.

Use the outputs as review workpapers: retain the source locator beside every material value, and keep planned action separate from completed evidence. The final document must identify the consequence of each gap for the relevant operational or control decision.

## Adapt before use

- Map spend, usage, catalogue, contract, and owner identifiers.
- Add approved-tool, security, data-classification, and renewal rules.
- Define savings calculation, risk labels, and decision owners.
