DEV Community

Serguey Shinder
Serguey Shinder

Posted on

The Next Wave of Shadow IT Will Be Built, Not Bought

For the last decade, unsanctioned technology arrived by credit card. Somebody signed up for a service, it appeared on an expense claim eventually, and the way we found it was to read the card statements. Imperfect, but it worked, because the act of acquiring the thing left a financial trace outside the technology estate.

That trace is disappearing. What people are building now costs nothing to start, happens inside platforms we already own and pay for, and generates no purchase order at all.

The example that changed my thinking was modest. An analyst in finance built a scheduled flow inside our own productivity suite that pulls a report from one system, reshapes it, and writes it into another, replacing about two days of monthly manual work. It is good. It runs under her personal account, it moves customer data between two systems that have never been assessed as connected, four people now depend on its output for a regulatory return, and it exists nowhere in our architecture, our recovery plan or our access reviews. No procurement process was avoided, because none applied. Nobody did anything wrong.

What I expect over the next few years is that the volume of this rises sharply, for a plain reason: the skill required to build a working automation is falling fast, and the skill required to judge whether one is safe to depend on is not falling at all. Assistants inside the tools will write the script, connect the systems and schedule the job for anybody who can describe the outcome in a sentence. That is genuinely good. It also means the gap between what our organisation can build and what it can operate responsibly gets wider every year.

I do not think prohibition is available, and the departments that try it will simply be told less. The work that looks useful is duller. Find out what your existing platforms can already report about who is building what, because most of them know. Define the point at which a personal automation becomes something the organisation depends on, and make a supported route for it to graduate into. Put the guardrails in the platform rather than in a policy document, particularly on which connectors may touch which data.

The scarce skill will not be building things. It will be deciding what is safe to leave running.

– Serguey Shinder

Top comments (0)