Shadow IT
Software and services staff adopt on their own, without IT approval or oversight.
It is usually a symptom rather than defiance. When the sanctioned tools are slow or missing a capability, people find something that works, and company data ends up in an account IT cannot see, secure, back up, or recover.
Discovery comes before enforcement. Seeing what is actually in use tells you which gaps drove people elsewhere, and often the right answer is adopting and securing the tool rather than banning it.
Where this comes up
Shadow IT sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.