Live data from Hacker News

Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

accessowl.io

21–30 of 38 posts

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#22
post #17

Earlier quoted context omitted.

The biggest challenge is that there's an abundance of SaaS tools that are free to use or have extensive free trials. This often lures employee's in "just trying" a platform and ending up importing critical company data. Slack and Loom are great examples of SaaS that profited from being "Shadow IT". They gained traction by employee's quickly self-onboarding onto the free-plan, without their IT or Security knowing what…

If you block marketing from using the tools they want, they will do it anyway but using personal email addresses like Gmail or something like that especially with the generous free tiers.

100%. Instead keep track of where they sign up with their business email and explain why they can't use those tools.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#23
post #17

Earlier quoted context omitted.

The biggest challenge is that there's an abundance of SaaS tools that are free to use or have extensive free trials. This often lures employee's in "just trying" a platform and ending up importing critical company data. Slack and Loom are great examples of SaaS that profited from being "Shadow IT". They gained traction by employee's quickly self-onboarding onto the free-plan, without their IT or Security knowing what…

If you block marketing from using the tools they want, they will do it anyway but using personal email addresses like Gmail or something like that especially with the generous free tiers.

Which makes it even worse because you cannot detect that then :/

Shouldn't people just be able to try out new things? How can a company be innovative otherwise? And at a specific point (e.g. putting customer data into it), they need to start a proper vendor assessment process.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#24
post #11

What do people think about companies (even small startups) having a rule against random employees signing up for SaaSes? On the one hand, such a rule sounds like stodgy company friction to "getting it done". On the other hand, I see employees putting crucial information across seemingly every SaaS they'd heard of, except for the official place it's actually supposed to go. Making it inaccessible to the people who nee…

Nobody without the power to sign contracts in company name can legally register and use a SaaS at work. They can make a personal account and using it amounts to extracting data out of the company.

From a legal point of view that might be true, but I believe people are not aware that this is a problem. They just register, check the "Agree terms of service" box and do whatever they want to do. I saw that often, especially with Marketing.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#25
> AccessOwl calculates billing based on the number of active Slack users, excluding Single-Channel Guests and service accounts, as this is usually the closest measure to your number of active employees. The billing amount is updated prorata each month and before each payment, based on the number of users in your Slack workspace.

https://www.accessowl.io/pricing

How does pricing work if Slack is not used?

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#26
post #25

> AccessOwl calculates billing based on the number of active Slack users, excluding Single-Channel Guests and service accounts, as this is usually the closest measure to your number of active employees. The billing amount is updated prorata each month and before each payment, based on the number of users in your Slack workspace. https://www.accessowl.io/pricing How does pricing work if Slack is not used?

I don't think that's possible, the "Start Trial" button immediately redirects to Slack.

This does seem like a weird restriction. Nothing about the product otherwise seems Slack-specific.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#27
post #25

> AccessOwl calculates billing based on the number of active Slack users, excluding Single-Channel Guests and service accounts, as this is usually the closest measure to your number of active employees. The billing amount is updated prorata each month and before each payment, based on the number of users in your Slack workspace. https://www.accessowl.io/pricing How does pricing work if Slack is not used?

Slack is required for AccessOwl. It's used for things like approval workflows, task management and notifications in general.

What do you use instead?

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#28

Earlier quoted context omitted.

Nobody without the power to sign contracts in company name can legally register and use a SaaS at work. They can make a personal account and using it amounts to extracting data out of the company.

From a legal point of view that might be true, but I believe people are not aware that this is a problem. They just register, check the "Agree terms of service" box and do whatever they want to do. I saw that often, especially with Marketing.

It's not just legal but also the practical point of view. They committed fraud when they clicked that checkbox. It's exactly the same as signing a contract with someone else's name.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#29
post #25

> AccessOwl calculates billing based on the number of active Slack users, excluding Single-Channel Guests and service accounts, as this is usually the closest measure to your number of active employees. The billing amount is updated prorata each month and before each payment, based on the number of users in your Slack workspace. https://www.accessowl.io/pricing How does pricing work if Slack is not used?

Slack is required for AccessOwl. It's used for things like approval workflows, task management and notifications in general. What do you use instead?

This severely limits the usefulness of a product like this.

Core aspects of the product like workflows and task management should not be tied to a chat vendor in my opinion, and would make me extremely nervous as a potential buyer due to your complete dependence on what SF does with Slack.

I’ve also worked places that strongly dislike Slack and won’t touch it since it was acquired by Salesforce. Ironically, your product would cause Shadow IT deployments (of Slack) in such environments.

Sharing these concerns because I think the product is a really useful concept, but your roadmap for these core functions would mean the difference between considering and completely passing over AccessOwl, i.e. for some subset of potential customers, the hard dependency on Slack is a complete blocker.

Re: Show HN: Shadow IT Scan – Uncover SaaS Apps, Users and Risky OAuth Scopes

#30
post #29

Earlier quoted context omitted.

Slack is required for AccessOwl. It's used for things like approval workflows, task management and notifications in general. What do you use instead?

This severely limits the usefulness of a product like this. Core aspects of the product like workflows and task management should not be tied to a chat vendor in my opinion, and would make me extremely nervous as a potential buyer due to your complete dependence on what SF does with Slack. I’ve also worked places that strongly dislike Slack and won’t touch it since it was acquired by Salesforce. Ironically, your prod…

Depending on the point of view it can also be a strength. Actually many of our customers like that we're in Slack because their people are already there:

- no login required to request an access - they don't need to "learn a new application"

So for end users that's great. There is still a web app for admins with more details.

But I can see where you're coming from. We plan to offer an alternative to Slack to be independent if the customers want that.

Post reply on HN