Sastrify's Shadow IT Radar helps IT and compliance teams detect, assess, and manage shadow IT. With automated risk scoring, it provides actionable insights to reduce compliance risks, enhance security, and improve operations. Using browser extensions, it identifies shadow IT assets, assigns risk scores, and enables actions like approval, sanctioning, or contacting users.


IN THIS ARTICLE


Basic Functionality Requirements


For Shadow IT Radar to function at its best, all of the following steps must be completed:

  1. Connect to one of the HRIS integration
  2. Enable an admin setup of Sastrify browser extension from your Sastrify platform.
  3. Have your employees add and activate their Sastrify browser extension

Accessing Shadow IT Radar and its Building Blocks


Sastrify Radar can be accessed from Risk Monitoring > Shadow IT Radar.



Within the interface of this feature, you'll find four building blocks as represented by the four tabs, each designed with a specific purpose in mind. 

  1. Overview: Track all discovered tools with filtering by risk score and usage, take actions such as approval or sanction, and summarize shadow IT findings and user monitoring by risk and monitoring status.
  2. Sanctioned: View sanctioned tools and notify users with reminders to ensure compliance.
  3. Users: View a breakdown of users or employees, along with information about the tools they are using and their risk scores, as well as a summary of monitored and unmonitored employees and how many of them are using shadow IT and unsanctioned tools.


The following sections provide a detailed overview of each tab and the available actions within them.


1. Overview Tab



  1. Display all tools discovered through browser extensions and SSO discovery integrations. These tools are not yet part of your existing tool stack.
  2. Receive a risk assessment score for each of the detected tools. The detailed scoring breakdown can be viewed by clicking the expand buttons.
  3. Allow filtering and sorting by risk level, date, usage frequency, and category.
  4. Take actions such as approving or sanctioning tools. 
    • Approving will move the tools from this page to the Tool Stack page.
    • Sanctioning will move the tools from this page to the Sanctioned page.
  5. Provide a summary of total tools categorized by risk level and sanction status.
  6. Provide a breakdown of monitored and unmonitored users, showing which users have the Sastrify browser extension enabled and which have not.


Pro Tip: Approval and sanctioning can be performed on an individual basis or in bulk.


Each line item can be expanded by clicking the expand button to view a detailed score breakdown. Scores are generated automatically by a built-in AI agent that analyzes publicly available information on vendors and products.


We categorize scores into three risk levels:

  • Low Risk (0-35): Minimal risk with no significant threats to security or operations.
  • Medium Risk (36-64): Moderate risk with potential issues that should be addressed.
  • High Risk (65-100): Significant risk requiring immediate action to mitigate security and operational threats.


For more detailed risk score evaluation criteria, click here.



2. Sanctioned Tab


This tab contains tools that have previously been marked as sanctioned. Within this tab, you can perform the following actions:

  1. View sanctioned tools.
  2. Allow filtering and sorting by name, category, and status.


3. Users Tab


  1. Provide a breakdown of monitored and unmonitored users, showing which users have the Sastrify browser extension enabled and which have not.

  2. Provide a summary of shadow IT users in your organization and those using sanctioned tools.

  3. Get a detailed breakdown at the employee level, including tools used and tools sanctioned per employee.

  4. Allow filtering and sorting by name, used tools, sanctioned tools, and status.