Shadow IT
Shadow IT is software adopted inside an organisation without IT or security's knowledge, typically SaaS signed up for with a work email or OAuth grant, creating access and data flows nobody governs.
Shadow IT is every tool in use that the people responsible for security do not know about. It rarely arrives through malice: a team trials a SaaS product with a company email, connects it to the identity provider's "Sign in with…" button or an OAuth grant, starts putting real data in it, and never mentions it, because from their side there was nothing to mention.
Why it is an identity problem
Each shadow app is a set of accounts and grants outside every control you run: no lifecycle automation, so leavers keep their logins; no reviews, so access only grows; and OAuth grants that keep working long after anyone remembers approving them. The risk is not the app existing. It is the ungoverned access and data flow it carries.
Discovery before governance
You cannot govern what you have not found, so the practical response starts with discovery: reading identity-provider sign-ins and OAuth grants to surface what the organisation actually uses, then deciding per app whether to sanction and connect it or shut it off. Ploy's discovery feeds the access graph, where an unknown app shows up as reachable from real identities, which is exactly what makes it hard to ignore.