📊 Key Data
  • 52% of employees have downloaded apps without IT approval (1Password 2025 report).
  • Organizations failing to manage SaaS lifecycles are five times more susceptible to cyber incidents and overspend by at least 25% (Gartner).
  • 27% of employees use unsanctioned AI-based applications.
🎯 Expert Consensus

Experts agree that unchecked SaaS sprawl and shadow AI adoption pose significant security, cost, and governance risks, necessitating centralized management solutions to restore visibility and trust.

28 days ago
The New Gatekeepers: Taming the Wild West of Workplace AI and SaaS

The New Gatekeepers: Taming the Wild West of Workplace AI and SaaS

TORONTO, ON – June 23, 2026 – In the ever-expanding digital workplace, a quiet but profound power struggle is underway. It’s not a battle for market share in the traditional sense, but a fight for control, visibility, and trust. This month, the identity security firm 1Password was named a Leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms, a recognition that serves less as a corporate milestone and more as a flare illuminating a critical challenge for every modern organization: the unchecked proliferation of software and artificial intelligence.

For years, IT departments have watched as employees, driven by a desire for efficiency, have adopted hundreds of Software-as-a-Service (SaaS) applications on their own. This phenomenon, known as “SaaS sprawl” or “shadow IT,” has created a vast, unmanaged digital territory within our companies. Now, with the explosive arrival of generative AI tools and agentic workflows, this territory is expanding at an exponential rate, bringing with it a new class of risks and costs that most organizations are only beginning to comprehend.

The Shadow Ecosystem

The modern employee is a digital pioneer, forging new paths to productivity. When a company-approved tool is clunky or inadequate, they find a better one. This spirit of innovation is what drives business forward, but it has also given rise to a sprawling, invisible ecosystem of applications. According to 1Password’s 2025 “Access-Trust Gap” report, a striking 52% of employees have downloaded apps without IT approval. More alarmingly, 27% have used AI-based applications their employer did not sanction.

This isn’t a story of malicious intent. It’s the story of a workforce adapting faster than its corporate structures. But the consequences are undeniable. As David Faugno, CEO of 1Password, noted, “The challenges organizations have faced with SaaS sprawl have been exacerbated by the introduction of AI tools and agentic workflows. Runaway costs with unclear ROI and security risks resulting from ungoverned access by users and their agents are concerns we hear from nearly every customer we speak with.”

This “shadow AI” landscape is particularly perilous. Unlike traditional software, many AI tools operate on consumption-based pricing models, where costs can spiral unpredictably. They also process and learn from the data they are fed, creating profound questions about data privacy, intellectual property, and security when sensitive corporate information is entered into an unvetted public model.

A Crisis of Visibility and Trust

The core of the problem is a fundamental breakdown in visibility. Gartner research starkly illustrates the danger, projecting that organizations failing to centrally manage their SaaS lifecycles will remain five times more susceptible to cyber incidents. They also predict these same organizations will overspend on software by at least 25% due to redundant applications and unused licenses.

“We’re flying blind,” confessed one chief information security officer at a mid-sized tech firm, speaking on the condition of anonymity. “We know our teams are using dozens of AI tools for coding, marketing copy, and analysis. But we don’t know which ones, what data is being shared, or how much it’s costing us on consumption-based plans. It’s a crisis of governance that keeps me up at night.”

This gap between the tools people use and the systems that are meant to govern them creates what 1Password calls the “access-trust gap.” Without a clear audit trail of who—or what—has access to company data, trust erodes. It becomes impossible for leadership to confidently assure regulators, partners, and customers that their information is secure. In an age where data is currency, this lack of internal control poses an existential threat.

The Rise of the SaaS Manager

Enter the SaaS Management Platform (SMP), a category of technology built to bring order to this chaos. 1Password’s recognition as a Leader by Gartner for its 1Password SaaS Manager signals the market's maturity and the urgent need for these solutions. These platforms are the new digital gatekeepers, but their role is more sophisticated than simply blocking access.

An effective SMP acts as a central nervous system for a company’s software ecosystem. By integrating with hundreds of data sources—from identity providers and finance systems to device agents and browser extensions—platforms like 1Password’s can build a comprehensive, real-time inventory of every application in use, including those operating in the shadows outside of Single Sign-On (SSO) systems.

Once visibility is established, governance can begin. These tools map application usage against contract data, automatically flagging unused licenses and optimizing spend. This has become particularly critical with the rise of AI, as SMPs can help manage volatile token consumption costs, a key reason Gartner added “FinOps” as a primary evaluation criterion this year. They also automate the employee lifecycle, granting access upon hiring and, just as importantly, revoking it upon departure to close lingering security gaps.

The goal is not to create a restrictive digital panopticon but to build digital guardrails. By offering self-service access requests and automated approval workflows, these platforms empower employees to get the tools they need quickly while ensuring IT and security maintain oversight. It’s a system designed to rebuild trust by enabling choice within a secure, transparent framework.

Beyond the Password: A Unified Vision for Access

1Password’s position in this landscape is part of a larger strategic evolution from a beloved password manager into a comprehensive Unified Access platform. This journey reflects a deeper truth about the future of security: managing passwords is no longer enough. The real challenge is managing identity and access across a complex web of human, machine, and now, AI agents.

The market is evolving in concert. Competitors in the Gartner Leaders quadrant, such as Zylo, Flexera, and Torii, are also pushing the industry forward, with particular strengths in spend optimization, FinOps intelligence, and deep AI analytics, respectively. What distinguishes 1Password's vision is its effort to bind SaaS and AI governance directly to its core identity security framework. By bringing applications into the same governance model used to secure credentials and secrets, the platform aims to provide a single, coherent view of access across the entire organization.

This holistic approach is what Gartner’s “Completeness of Vision” metric acknowledges. The problem isn’t just discovering an unsanctioned AI app; it’s understanding who is using it, what credentials they are using to access it, and what data that AI agent can now access on the user’s behalf. As AI agents are increasingly granted the authority to act for us, securing their identity becomes as critical as securing our own. Defining and defending the boundaries of access in this new, blended workforce of humans and machines is the central challenge of our time, and the work to build a trustworthy digital world has only just begun.

Topics & Related

Sector:
Cybersecurity
Software & SaaS
Theme:
Generative AI
Identity & Access Management
UAID: 38704