Sastrify Radar empowers IT and compliance teams to uncover, assess, and manage shadow IT within their organization. Through automated risk scoring for identified tools, this feature offers actionable insights that facilitate well-informed decision-making to reduce compliance risks, strengthen security, and boost operational effectiveness.


Using browser extensions and/or SSO discovery integrations, it finds shadow IT assets, automatically assign risk scores, and enables actions like approving, sanctioning, and getting in touch with users of those assets.


IN THIS ARTICLE


Key Features of Sastrify Radar


  • Shadow IT risk scoring: Get a comprehensive view of risk, see sanctioned tools, and track users interacting with risky tools.
  • Rapid actions: Approve safe tools, sanction risky ones, and contact users of risky tools directly from your platform.
  • User & tool monitoring: Get detailed views of users working with shadow IT tools, notify them of non-compliance, and track both monitored and unmonitored users for complete SaaS coverage.

Basic Setup Requirements


For Sastrify Radar to work, all of the following steps must be completed:

  1. Connect to either an SSO (Single Sign-On) discovery integration or an HRIS integration
  2. Enable an admin setup of Sastrify browser extension from your Sastrify platform.
  3. Have your employees add and activate their Sastrify browser extension

Accessing Sastrify Radar and its Building Blocks


Sastrify Radar can be accessed from Risk Management > Radar.



Within the interface of this feature, you'll find four building blocks as represented by the four tabs, each designed with a specific purpose in mind. 

  1. Overview: Track all discovered tools with filtering by risk score and usage, take actions such as approval or sanction, and summarize shadow IT findings and user monitoring by risk and monitoring status.
  2. Sanctioned: View sanctioned tools and notify users with reminders to ensure compliance.
  3. Users: View a breakdown of users or employees, along with information about the tools they are using and their risk scores, as well as a summary of monitored and unmonitored employees and how many of them are using shadow IT and unsanctioned tools.
  4. Audit Trail: Review a log of all actions taken to ensure transparency and accountability.


In the following sections, we will take a closer look at each tab and the actions that can be taken or performed within it.




1. Overview Tab



  1. Display all tools discovered through browser extensions and SSO discovery integrations. These tools are not yet part of your existing tool stack.
  2. Receive a risk assessment score for each of the detected tools. The detailed scoring breakdown can be viewed by clicking the expand buttons.
  3. Allow filtering and sorting by risk level, date, usage frequency, and category.
  4. Take actions such as approving or sanctioning tools. 
    • Approving will move the tools from this page to the Tool Stack page.
    • Sanctioning will move the tools from this page to the Sanctioned page.
  5. Provide a summary of total tools categorized by risk level and sanction status.
  6. Provide a breakdown of monitored and unmonitored users, showing which users have the Sastrify browser extension enabled and which have not.


Pro Tip: Approval and sanctioning can be performed on an individual basis or in bulk.


Each line item can be expanded by clicking the expand button to view a detailed score breakdown. Scores are generated automatically by a built-in AI agent that analyzes publicly available information on vendors and products.


We categorize scores into three risk levels:

  • Low Risk (0-35): Minimal risk with no significant threats to security or operations.
  • Medium Risk (36-64): Moderate risk with potential issues that should be addressed.
  • High Risk (65-100): Significant risk requiring immediate action to mitigate security and operational threats.


For more detailed risk score evaluation criteria, click here.




2. Sanctioned Tab



  1. View sanctioned tools.
  2. Allow filtering and sorting by name, category, and status.
  3. Perform later approvals when specific sanctioned tools are approved for organizational use 
  4. Notify users who are using or are associated to certain tools and send reminders to ensure compliance.


When the "Notify Users" button is clicked, the Sastrify admin can send an email notification to users or employees using the sanctioned tool.



3. Users Tab



  1. Provide a breakdown of monitored and unmonitored users, showing which users have the Sastrify browser extension enabled and which have not.

  2. Provide a summary of shadow IT users in your organization and those using sanctioned tools.

  3. Use the notification option to:

    • Contact shadow IT users to address unauthorized tool usage.
    • Remind sanctioned tool users to discontinue use.
    • Notify unmonitored users to add and activate the browser extension.

4. Audit Trail Tab


  1. Review a log of all actions taken to track changes and decisions to ensure transparency and accountability for all performed actions.
  2. View the details of each action as well as the associated tools that are impacted.