Shadow IT was a process failure, not a discipline problem
Palewind Ops had a vendor request form. Almost nobody used it.
Engineers who wanted a tool asked in a channel, got told to email security, and either did or quietly expensed the tool on a corporate card. Nine requests in 2024 were lost outright: sent to a shared inbox, read by somebody who assumed a colleague had it, and never answered. Each of those was a team that concluded the process did not work and stopped trying.
The security team’s own view was blunter. A form that lives outside the tools people work in is a form that measures compliance with the form, not risk.
Intake where the work already happens
Requests now start with /vendor-review in Slack. The engineer types the vendor’s name; the command
comes back with what is already known — whether the vendor has been reviewed, whether a current tier
exists, whether anyone else in the company is already using it. About a third of requests end there,
because the answer is “we already have this, here is who owns it”.
The rest become a review with a thread attached. Status changes post back into the thread, so the requester can see where it is without asking, and the approval is a message in a channel rather than a mail nobody can find later.
“Half the value was not speed. It was that people stopped going around us, because going through us stopped being the slow option.”
Two quarters in
- 94% of requests arrive through the command. The remaining 6% are mostly from Finance, who do not live in the engineering workspace.
- Zero requests lost, against nine known losses the year before — and the real figure for the old process is unknowable, which was itself part of the problem.
- Median time from request to decision fell from 21 days to five. A third of that improvement is simply the requests that end at “we already have this”.
What’s next
Palewind Ops is adding renewal notices to the same threads, so the team that asked for a tool is the team told when its evidence is about to expire.
About Palewind Ops
Palewind Ops builds observability tooling for platform teams. 450 people distributed across nine countries, SOC 2 Type II certified. Dani Restrepo leads the security engineering group that owns vendor review.


