• Jump to contents
  • Jump to main navigation
  • Jump to site map
  • News
  • Insight
  • Careers
  • Support
  • Book a Meeting
  • Contact Us Now
  • Book a Meeting
  • Contact Us Now
  • +44 207 837 2444
  • US and International: +1 323 984 8908
  • Change Region
  • +1 323 984 8908
  • Change Region

Cardonet IT Support for Business

Cardonet are a consultative business partner who will work closely with you to provide a transparent, vendor-neutral approach to your IT Services.

+44 203 034 2244
7 Stean Street, London, E8 4ED

+1 323 984 8908
750 N. San Vicente Blvd, Los Angeles, CA 90069

  • Home
  • IT Solutions
    • Industry Sector IT Solutions
      • Hospitality
        • Hotels
        • Hotel Management
        • Restaurants
        • Pub & Bars
      • Finance Associations
      • Manufacturing
      • Media and Creative
        • Marketing Agencies
        • Public Relations and Communications Agencies
        • Design Agencies
        • Advertising Agencies
        • Market Research Agencies
        • Entertainment
      • Charity
      • Education
    • Business IT Challenges
      • Remote and Hybrid Working
      • IT Outsourcing
      • IT Cost Optimisation
      • Office Move and IT Relocation
      • Global Technology Operations
      • Global IT Helpdesk
      • Cyber Security Journey
      • Technology Compliance
      • Multi-site IT Operations
      • GDPR Compliance
      • PCI DSS Compliance
  • IT Services
    • IT Support
      • 24x7 Service Desk
      • 24x7 Network Monitoring
      • IT Service Delivery
      • Proactive IT Support
      • Remote IT Support
      • Onsite IT Support
      • Out of Hours IT Support
      • Dedicated Service Desk
      • Network Support
      • Microsoft Support
      • Apple Mac Support
      • Business IT Support
    • IT Consultancy
      • IT Strategy
      • IT Projects
      • IT Audits
      • Software Licensing
      • IT Infrastructure
      • IT Procurement
      • IT Supplier Management
      • IT Security
      • IT Networks and Cabling
      • Cloud Readiness
      • Virtualisation
      • Backup and Continuity
    • Managed IT
      • Managed Networks
      • Managed Hosting
      • Managed Backups
      • Business Continuity
    • Managed Cloud
      • Private Cloud
      • Hybrid Cloud
      • Public Cloud
    • Communication
      • Onsite Telephone System
      • Hybrid Telephone System
      • Cloud Telephone System
      • Contact Centre
      • Video Conferencing
      • SIP Trunking
      • Lines and Calls
    • Cyber Security
      • Cyber Security Audit
      • Managed Cyber Security
      • Cyber Compliance
  • About
    • About Cardonet
      • Why Cardonet?
      • News
      • Insight
      • Management Team
      • Case Studies
      • Customers
      • Technology Partners
      • Accreditations & Memberships
      • Approach and Culture
      • History
    • Careers with Cardonet
      • Why Cardonet for your Career?
      • Meet our Team
      • Job Entry Options
      • Current Job Vacancies
  • Contact

News

Shadow IT in Creative Agencies: Why Teams Use Unapproved Tools

by Raphael Waller / Thursday, 07 May 2026 / Published in Managed IT
shadow it creative agencies why teams use unapproved tools cardonet

Shadow IT in a creative agency is a workflow stress signal, not a culture problem. When teams build client work across Slack, Dropbox, Canva, and Notion outside the approved stack, it is a sign that your official tools are too slow, too rigid, or too hard to use under deadline pressure.

Imagine a 40‑person creative agency pitching, revising, and shipping across multiple campaigns at once. The approved system says files belong on the central platform, communication belongs in the main collaboration tool, and project tracking belongs in the company PM stack. Yet, in practice, the live work is scattered across personal Dropbox links, side Slack workspaces, Canva files sitting in individual accounts, and Notion pages that nobody outside the immediate team can see.

In our experience, sprawl doesn’t start with people trying to dodge policy. It starts because leaders need a faster way to coordinate pitch teams, designers cannot wait for slow remote access to large files, or account leads need a simpler way of organizing moving parts than the official system gives them.

Workarounds solve immediate problems and survive. But they create the risk that, before long, you will be running a parallel tech stack that can keep work moving but which is too fragmented to manage properly.

This is not only a security risk but an operational one too due to lost time, duplicated work, unclear ownership, version confusion, messy handoffs, and client dissatisfaction.

How Slack‑Dropbox‑Canva sprawl starts

Shadow IT in creative agencies rarely arrives as one dramatic decision. It appears as a series of small, practical choices made under pressure. None of the choices feels serious in isolation and so the problem grows. Each “fix” deals with a local friction point but it simultaneously creates another place where work can live.

The scale can be bigger than most agency leaders realize. The National Cyber Security Centre’s commentary on shadow IT notes that many organizations only discover the true size of their “unknown estate” when they start looking for assets their IT department does not know about. This has prompted guidance on identifying and managing those blind spots. When systems sit outside traditional controls, risks multiply.

In a creative environment, that gap between reality and documentation widens quickly because work is fast, collaborative, distributed, and often shaped by freelancers, partner agencies, or client‑side contributors who do not fit neatly into standard internal IT assumptions.

What shadow IT is really telling you

The mistake is to see shadow IT only as disobedience. In most agencies, it is operational feedback, telling you that the approved tools do not match the way creative work develops in the real world.

In fact, shadow IT is often a map of where the official stack has stopped serving the business. It tells you where systems are adding friction rather than removing it. This is useful information if you are willing to pay attention.

There is also a financial penalty to it. SaaS sprawl often means duplicate tools doing roughly the same job via multiple subscriptions owned by different departments. Even if the unofficial tools are helping your team move faster, the way they are being adopted may still be increasing cost and complexity in the background.

The more useful way to frame the issue is this: if the unofficial workflow is winning, it is because it feels more workable than the official one. That does not mean unofficial tools should be approved. Rather, the official stack needs to be fixed to earn back trust by being faster, clearer, and better aligned to how work actually happens.

Simplifying Agency IT with Shadow IT

Build a governed stack creatives will use

This is where agencies either improve or make things worse. A blanket crackdown may reduce visible tool sprawl for a while, but it usually just pushes the same behavior further underground. If people still need to hit deadlines, they will do what’s needed and simply stop telling you how they are doing it.

Instead, treat shadow IT as a live workflow audit. Map the tools teams actually use to get the work done and compare those to the tools in the procurement records.

From there, work through a practical five‑step sequence:

  • Discover actual usage. Pull together expense records, SSO data, browser extension visibility, and team interviews to identify the true mix of apps supporting delivery. Security leaders consistently stress that if you cannot see the tools people are using, you cannot protect the data flowing through them, which is why automated discovery of shadow SaaS should be a prerequisite for any serious governance effort.
  • Group by job‑to‑be‑done. Sort tools into communication, file sharing, briefing, project tracking, review, approvals, design, and reporting so you can see where duplication and friction cluster.
  • Find the failure point(s). Why did the unofficial tool “win”. Was it speed, flexibility, remote access, freelancer access, better interface design, or less process overhead?
  • Standardize where it matters… Some functions need a single source of truth – especially file storage, permissions, approvals, and offboarding.
  • … but allow controlled flexibility where it helps. Early‑stage ideation or lightweight campaign planning may support a small, approved toolset rather than one rigid system, provided output lands in the right place later.

That last point matters. Build structure where this will protect the business and be flexible where it will genuinely improve the work. Good governance is not automatically about maximum restriction.

For many agencies, this is where specialist support becomes valuable. Our media and creative IT solutions are built around the real workflow of studios – Mac‑heavy environments, large files, mixed on‑site and remote teams – rather than generic enterprise assumptions. That is a more useful foundation than taking a standard corporate stack and hoping that your creatives will adapt to it.

A Shadow IT Review for Creative Agencies

What good creative IT governance looks like

A well‑run agency does not eliminate experimentation. It makes experimentation visible, manageable, and compatible with security and delivery.

In practical terms, that usually means five things are true.

  1. Everyone knows the source of truth: If you ask where live files sit, where approved assets sit, where campaign decisions are logged, and where project status is tracked, you get consistent answers across the business.
  2. Core tools are good enough that people do not need constant workarounds: Remote access performs properly, large files move without drama, shared workspaces are fast, and the chosen systems feel easier to use than the unofficial alternatives.
  3. New tools can be trialed without disappearing into the shadows: Teams know how to propose something new, IT can assess it quickly, and leadership can decide whether to approve, restrict, or replace it. That creates a culture where useful experimentation is surfaced rather than hidden.
  4. Access and ownership are visible: You can see who has access to what, which subscriptions are business‑critical, which are duplicative, and what happens to accounts when staff or freelancers leave. SaaS management analyses repeatedly argue that this combination of discovery, rationalization, and lifecycle management is the only sustainable way to stop a growing application portfolio from turning into unmanaged shadow IT. That is where productivity and control start reinforcing each other rather than fighting each other.
  5. The agency’s stack reflects the project lifecycle, not the org chart: Support, storage, permissions, and communication are designed around the way work goes from brief to concept to delivery, because that is the rhythm your systems need to serve.
Good Creative Agency IT Governance

A simple shadow IT review

If you want a practical starting point, run this six‑question review across one live client account this week:

  • Where are the working files, and is that location officially approved?
  • Where are approvals recorded, and can somebody else find them quickly?
  • Which collaboration tools are in use outside the standard stack?
  • Which freelancers or external partners currently have access to campaign assets?
  • What happens to access when the project ends or someone leaves?
  • Which workaround exists only because the official system is too slow or awkward?

That exercise will tell you far more than a policy document. It will show you whether shadow IT in your agency is a marginal issue or a sign that the operating model underneath your tools needs attention.

If you find that every major account has its own ungoverned mix of tools, you are not alone. Analysts now describe shadow IT and shadow SaaS as an “invisible attack surface”, arguing that you cannot rely on traditional perimeter‑based thinking when so much of your work runs through browser‑based services you do not centrally control.

The creative sector is particularly prone to that pattern because it adopts new tools early and often.

Why this matters

Creative agencies are not judged by how tidy their internal tooling looks. They are judged by delivery, responsiveness, trust, and being able to do excellent work without unnecessary friction. When your stack helps that happen, productivity improves. When it gets in the way, people route around it.

Do not punish teams for being resourceful. It is far better to build an environment where resourcefulness does not require workarounds that fragment delivery and create avoidable chaos. Shadow IT is often the first visible sign that your operations need redesign not tighter policing.

The National Cyber Security Centre’s cloud guidance stresses that mis‑configured or ungoverned cloud services can undermine otherwise sound security controls – and shadow IT is, by definition, hard to configure and monitor properly. That is another reason to bring these tools into the light, even when your main concern is productivity rather than security.

FAQs

What is shadow IT in a creative agency?

Shadow IT in a creative agency is the use of apps, platforms, or workflows outside the approved tech stack to get work done, such as personal Dropbox accounts, side Slack workspaces, or Notion boards used for live client delivery. UK guidance describes these as “unknown assets” from IT’s perspective – still handling business data, but absent from normal asset management and control, which is why law‑firm summaries of NCSC thinking on shadow IT emphasize discovering those assets first.

Why do creative teams use unapproved tools?

Usually because the approved tools feel too slow, too rigid, or poorly matched to deadline‑led creative work. Teams adopt alternatives when they believe those alternatives help them move faster or collaborate more effectively, especially when existing systems were designed around office‑centric assumptions.

Is shadow IT always a security problem?

It is a security and governance issue, but often the first business impact is operational rather than technical – version confusion, fragmented files, duplicate subscriptions, and unclear ownership. SaaS governance commentary also points out that you cannot apply meaningful controls or monitoring to systems you do not know about, which is why shadow SaaS is now a core concern in cloud security discussions.

Should agencies ban tools like Dropbox, Canva, or Notion?

Not automatically. The better question is why those tools appeared, whether they solve a real workflow need, and whether they can be governed properly or replaced with something equally usable. A blanket ban without addressing the underlying friction usually just pushes the same behavior into even less visible corners.

How should a creative agency respond to SaaS sprawl?

Start by discovering what tools are really in use, group them by purpose, identify where the official stack is failing, standardise critical systems, and allow controlled flexibility where it genuinely improves delivery. Modern SaaS management guidance stresses ongoing discovery, rationalization, and lifecycle management – not a one‑off clean‑up – particularly in fast‑moving environments like creative agencies.

Share this on:

  • LinkedIn
  • Twitter
  • Facebook

About Raphael Waller

What you can read next

Microsoft365 Backups
Do I Need to Back Up Microsoft 365?
mobile device management byod vs cope
Mobile Device Management Strategy: The Trust Gap 
reliable-it-support protects creative agency margin
How reliable IT protects creative agency margin 

You must be logged in to post a comment.

Featured Posts

  • hotel network infrastructure blueprint

    What passwordless really means for hotel IT

  • hotel network infrastructure blueprint

    Design your hotel network at the blueprint stage

  • hotel development design it support model before deciding technology stack

    Restaurant Franchising and Technology: How a Brand Standard IT Model Protects Your Brand Across Every Location

  • hotel development design it support model before deciding technology stack

    Designing your hotel IT support model before you lock in the technology stack

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • April 2025
  • June 2024
  • April 2024
  • February 2024
  • January 2024
  • October 2023
  • September 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017

Categories

  • Artificial Intelligence
  • Bam's Blog
  • Customers
  • Cyber Security
  • Events
  • GDPR
  • Guidance
  • IT Consultancy
  • IT Support
  • Managed IT
  • Press Release
  • Recruitment
  • Team
  • Uncategorised
  • USA
  • What is

Tags

ai artificial intelligence Business Business Continuity Christmas Christmas Party Cloud Computing Cloud Hosting Compliance coronavirus Covid 19 Cyber Awareness cyber crime Cyber Risk Cyber Security Cyber Threat Data Backups Disaster Recovery GDPR Halloween HOSPA HOSPACE Hospitality Hotel Hotel IT Services Hotel IT Solutions Hotel IT Support Hotels Hotel Technology IT infrastructure IT Services IT Support Microsoft Microsoft365 Migration Outsourced IT Support Pancake Pancake Day Remote Working Security Software Team Team Event Windows 10 End of Life Windows 11

Cardonet Twitter

Could not authenticate you.
TOP

We will help you overcome your technology challenges

Call us on +1 323 984 8908, email us at or fill out the following form to start the conversation.

",

For further information on how we process your data, please refer to our Privacy Policy.

IT Solutions

  • IT Solutions by Industry
  • Business IT Challenges

IT Services

  • IT Support
  • IT Consultancy
  • Managed IT
  • Managed Cloud
  • Communication
  • Cyber Security

About

  • Why Cardonet
  • Meet our Team
  • News
  • Insight
  • Case Studies
  • Careers

Contact

  • +44 207 837 2444
  • +1 323 984 8908
  • Change Region
Cardonet 26 years proudly supporting our customer
  •  
  •  
  • 750 N. San Vicente Blvd, Los Angeles, CA 90069
Cardonet IT Support and IT Services
Change Region
  • United Kingdom and Europe
  • United States and International

© 1999 - 2023 All rights reserved.

  • Sitemap
  • Terms and Conditions
  • Privacy Policy
  • GDPR
  • Accessibility Statement
  • Corporate Social Responsibility
  • Environmental Policy
Contact TOP
Cardonet
Cardonet Consultancy Limited 7 Stean Street London, Greater London E8 4ED
London Map +442030342244
Cardonet US Inc 750 N. San Vicente Blvd, West Hollywood Los Angeles, California 90069
Los Angeles Map +13239848908
Home Cardonet IT Support Logo