Z-Insights: Audit Shadow IT and SaaS Usage
Keywords
shadow IT, unsanctioned apps, SaaS security, CASB, cloud access, risk score, data exfiltration, SaaS compliance, unauthorized applications, cloud apps, IoT devices, device visibility, shadow IT report, app governance
Overview
Audit your organization's shadow IT exposure and SaaS application usage using Zscaler Analytics (Z-Insights). This skill discovers unsanctioned applications, assesses their risk, monitors CASB-protected cloud services, tracks data transfers, and inventories IoT devices on the network. Shadow IT represents a significant security and compliance risk -- users adopting cloud applications without IT approval can lead to data leaks, compliance violations, and expanded attack surface.
Use this skill when: A security or compliance team needs to discover unauthorized SaaS usage, generate shadow IT risk reports, review CASB findings, assess IoT device sprawl, or support compliance audits (SOC2, ISO 27001, HIPAA).
Important constraints:
- Z-Insights only supports historical data with a 24-48 hour processing delay
- Shadow IT summary supports time ranges of 1, 7, 15, or 30 days
- Shadow IT apps supports time ranges up to 30 days
- CASB supports time ranges up to 90 days
- IoT device stats show current state (no time range needed)
Workflow
Follow this 5-step process to audit shadow IT and SaaS usage.
Step 1: Understand the Audit Scope
Gather from the requester:
- What is the audit goal? (compliance, risk assessment, incident investigation, routine review)
- Time period to review? (7 days for recent, 14 days for broader view)
- Specific application categories of concern? (file sharing, messaging, AI/ML, storage)
- Compliance framework? (SOC2, ISO 27001, HIPAA, PCI-DSS, GDPR)
- Need IoT device inventory?
Step 2: Get Shadow IT Summary
Get the overall shadow IT dashboard:
This returns a comprehensive summary including:
- total_apps: Total number of shadow IT applications discovered
- total_bytes: Total data transferred to/from shadow apps
- total_upload_bytes: Data uploaded (potential data exfiltration)
- total_download_bytes: Data downloaded
- group_by_app_cat_for_app: Applications grouped by category
- group_by_risk_index_for_app: Applications grouped by risk level
Key metrics to highlight:
- Total unsanctioned apps vs sanctioned
- Total data volume (especially uploads -- data exfiltration vector)
- High-risk application count
- Category breakdown (file sharing, messaging, etc.)
Step 3: Discover Shadow IT Applications
Get detailed shadow IT application list:
Each application entry includes:
- application: Application name
- application_category: Category (file sharing, messaging, social media, etc.)
- risk_index: Risk score (higher = more risk)
- sanctioned_state: Whether the app is sanctioned by IT
- data_consumed: Total data transferred
- authenticated_users: Number of users accessing the app
Prioritize by risk:
Step 4: Review CASB SaaS Application Usage
Get CASB application report:
CASB (Cloud Access Security Broker) provides data and threat protection for data at rest in cloud services. This report shows:
- Which SaaS applications are being accessed
- Usage volume per application
- Application adoption trends
Cross-reference CASB data with shadow IT findings to identify:
- Sanctioned apps with unexpected usage patterns
- SaaS applications that should be added to the sanctioned list
- Applications with declining usage (candidates for decommissioning)
Step 5: Inventory IoT Devices
Get IoT device statistics:
IoT Device Visibility uses AI/ML to automatically detect, identify, and classify IoT devices. Returns:
- devices_count: Total devices on the network
- iot_devices_count: IoT devices (cameras, printers, sensors, etc.)
- user_devices_count: Unmanaged user devices (BYOD)
- server_devices_count: Server devices
- un_classified_devices_count: Devices not yet classified
- entries: Detailed breakdown by device classification
IoT devices represent shadow IT at the hardware level -- unmanaged devices connecting to the corporate network without IT oversight.
Present Audit Report
Validation
Before presenting the final report, sanity-check each tool's response. The four ZINS reads are independent — one of them returning empty does NOT mean the audit failed. It usually means a specific feature isn't licensed or no data exists for the window.
Edge Cases
No Shadow IT Detected
IoT Visibility Not Enabled
Partial Data (Some Calls Succeed, Others Fail)
If one of the four ZINS reads returns an error or empty payload while the others succeed, present the available sections and clearly flag the gap — do not fail the whole audit. Most common cause: an add-on (IoT Device Visibility, CASB) is not licensed on the tenant, or the requested window exceeds a per-tool limit. Mark the missing section as "Not available — feature not licensed / data not collected" so the requester can see the scope of what was audited.
Quick Reference
Primary workflow: Scope → Shadow IT Summary → App Details → CASB → IoT → Report
Shadow IT tools:
zins_get_shadow_it_summary()-- dashboard overview (totals, categories, risk groups)zins_get_shadow_it_apps()-- detailed app list with risk scores and data volumes
CASB tools:
zins_get_casb_app_report()-- SaaS application usage report
IoT tools:
zins_get_iot_device_stats()-- IoT device inventory and classifications
Time range notes:
- Shadow IT summary: supports 1, 7, 15, and 30-day ranges
- Shadow IT apps: up to 30 days
- CASB: up to 90 days
- IoT: current state (no time range needed)


