8 ms·
Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes
Hey HN,
TL;DR: We’ve launched a free version of our Shadow IT scanner to identify which SaaS apps are used in your company, who uses them, and if they have high-risk OAuth scopes.
Philip and I went through YC with AccessOwl in 2022. We started the company because, in our previous roles, we struggled to track all the SaaS apps, users, and granted OAuth scopes.
The Shadow IT scanner started as a small feature within AccessOwl, which manages SaaS vendors and user accounts centrally. But a standalone scanner would have made our lives so much easier in our previous roles. So, we thought, why not release it?
And here it is: a free, standalone Shadow IT scanner!
Hope you find it useful :) The Shadow IT scan helps with:
1. Offboarding: Employees often don’t report all the apps they sign up for, making it tough to track and secure these accounts when they leave, especially with the common SSO tax.
2. Security: OAuth scopes are quickly granted but rarely reviewed or removed, leading to organizations unknowingly spreading their data.
3. Compliance: Auditors need a list of SaaS vendors, which is hard to compile when employees sign up for tools independently.
Any surprises in your scan? What features would you like to see in the next version?
Looking forward to your feedback!
FAQ
What’s Shadow IT?
Unauthorized SaaS apps within an organization not centrally managed, posing security and compliance risks.
How does it work?
Our tool connects to your Google Workspace or M365 instance, identifies OAuth tokens granted, and maps them to known SaaS tools. Note: In this v1 version, it only detects apps using the “Sign in with Google/Microsoft” button.
Who is this for?
Typically IT and InfoSec teams, but in smaller companies, it may fall under the CTO.
Is it safe to use?
Yes, reading OAuth tokens is standard for SaaS management tools. Data extraction only occurs when you initiate a scan. AccessOwl is SOC 2 Type II audited and GDPR compliant.
- antonmi 2y agoVery interesting, gonna check it!
- PhLR 2y agoThanks! Any interesting findings?
- 650REDHAIR 2y agoThis is very, very cool! Great work guys!
- PhLR 2y agoThanks!
- ctippett 2y agoSeeing the logo made me wonder if this was a project spun out of Tripadvisor, they're very similar.
- PhLR 2y agoGood eye, but no, not related at all
- 3np 2y agoEven more confusable with especially the previous logo (but also current branding) of sendowl.com. https://www.courseplatformsreview.com/wp-content/uploads/2020/10/sendowl-logo-small.png https://www.courseplatformsreview.com/wp-content/uploads/202...
- bdno86 2y agoThis is really cool!! Always excited about increased accessibility of security tools. This used to require jumping through a bunch of hoops in the past to find out, so most companies don’t even know this is possible and therefore and even fewer made the effort to do it.
- PhLR 2y agoIndeed, when I learned about it I felt stupid for not having somebody run a regular report. Everybody talks about Shadow IT but most companies have a decent option to uncover a large chunk of it quite easily
- neilv 2y agoWhat do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who needed it, and often eventually losing the information entirely. I've also seen (to pick one anecdote) newer software developers pasting the data of a very sensitive proprietary engineering model into some random developer's Web site that provided a visualization. This random Web site then spread around engineering as the standard way you visualize that model. And I've seen third-party service dependencies that made no sense at all, but people were just following tutorials and StackOverflow answers they found.
- PhLR 2y agoWe talked to lots of CISOs, InfoSec managers and IT admins about that issue. There's basically two camps: Actively block any new tool vs. not block but educate so people don't do anything stupid. I feel not blocking makes most sense. Employee's want to be treated like adults, especially in tech savvy companies. If they feel like they are unnecessarily blocked they will just find a workaround (i.e. non-work email or device). However, you definitely want to keep track of people are signing up for - that's where the Shadow IT scanner comes in handy. In case you see something that's against policy it's often enough to just explain why it's a risk for the company. No employee means harm and just wants to be treated like an adult.
- KingMachiavelli 2y agoAgree it isn't practical to block everything while still allowing software engineers to do their job. An online regex tester is super useful or could be a big risk is an employee uses it incorrectly. But it is helpful to block certain things that are just too common outside of work so people just don't think twice. Things like ChatGPT, Grammerly, Pastebin, etc. should be manually blocked.
- 2y ago
- NoPicklez 2y agoIn a previous role many years ago I used a tool called Netskope which monitored Firewall traffic and it was excellent at identifying almost every web related service being used. This was helpful because it would detect SaaS platforms being used that were not integrated into SSO, like PDF converters etc But I really like how simple this looks to use and it looks powerful
- PhLR 2y agoIndeed, there are some great alternatives for discovering Shadow IT, some with more or less overhead (i.e. browser extensions that nobody wants to install).
- throwaway290232 2y ago[dead]
- moxli 2y ago> AccessOwl calculates billing based on the number of active Slack users, excluding Single-Channel Guests and service accounts, as this is usually the closest measure to your number of active employees. The billing amount is updated prorata each month and before each payment, based on the number of users in your Slack workspace. https://www.accessowl.io/pricing https://www.accessowl.io/pricing How does pricing work if Slack is not used?
- jorams 2y agoI don't think that's possible, the "Start Trial" button immediately redirects to Slack. This does seem like a weird restriction. Nothing about the product otherwise seems Slack-specific.
- mathiasn 2y agoSlack is required for AccessOwl. It's used for things like approval workflows, task management and notifications in general. What do you use instead?
- haswell 2y agoThis severely limits the usefulness of a product like this. Core aspects of the product like workflows and task management should not be tied to a chat vendor in my opinion, and would make me extremely nervous as a potential buyer due to your complete dependence on what SF does with Slack. I’ve also worked places that strongly dislike Slack and won’t touch it since it was acquired by Salesforce. Ironically, your product would cause Shadow IT deployments (of Slack) in such environments. Sharing these concerns because I think the product is a really useful concept, but your roadmap for these core functions would mean the difference between considering and completely passing over AccessOwl, i.e. for some subset of potential customers, the hard dependency on Slack is a complete blocker.
- mathiasn 2y agoDepending on the point of view it can also be a strength. Actually many of our customers like that we're in Slack because their people are already there: - no login required to request an access - they don't need to "learn a new application" So for end users that's great. There is still a web app for admins with more details. But I can see where you're coming from. We plan to offer an alternative to Slack to be independent if the customers want that.