Gateway Activity Logs Now Surface Unapproved SaaS Use
Organizations routinely approve a set of SaaS tools, yet employees can easily drift toward alternatives that feel more familiar. A user comfortable with Google Drive might store work files there even when OneDrive is the sanctioned choice. That single act can spread: files get shared, coworkers sign up, and suddenly sensitive data lives in a service IT never vetted. Cloudflare for Teams now offers a way to spot and act on that class of “Shadow IT” directly from the Gateway dashboard.
Turning Traffic Logs Into an Application Inventory
Gateway already routes all outbound Internet traffic through Cloudflare’s network, and every HTTP request is logged in the Activity Log with user, action, and request details. That data includes the destination application and its category—for instance, Google Drive under Collaboration and Online Meeting. Shadow IT Discovery builds on those logs, aggregating and sorting them into a usable catalog without requiring extra configuration.
The feature runs in an observation mode first: it catalogs every application users access and marks each one unreviewed by default. From there, an administrator can review the list and, in one or two clicks, designate applications as approved or unapproved—either individually or in bulk.
The overview helps administrators track which approved and unapproved services are most popular, giving a clearer picture of their actual security posture. A drill-down view supports bulk actions, letting teams move several newly discovered applications at once or filter by application type to spot redundancy—for example, two competing file-sharing tools both in active use.

Shadow IT Discovery also shows whether an application is already protected by Cloudflare Access, in a column labeled Secured. If an app is not secured, administrators can begin that process with Access for SaaS. Two new tutorials for that setup were published this week.
Unapproved Status Doesn’t Mean Blocked
Marking an application unapproved does not immediately block it. Cloudflare for Teams is designed so organizations can flag a service, then check with the users who rely on it before cutting off access. If the team is ready to enforce the decision, they can apply a Gateway rule to block the application going forward.

License Cost Visibility
Beyond security, the new feature also addresses a spending concern. Shadow IT Discovery counts unique users per application over different time intervals. IT teams can compare those numbers against active licenses and right-size subscriptions instead of paying for seats nobody uses.
The same usage data helps administrators spot popular applications earlier in the procurement cycle, so they can start assessing a tool before employees adopt it at scale—rather than discovering it after the fact.
Getting Started
Shadow IT Discovery is available now. To use it, deploy HTTP filtering for the organization with the Cloudflare for Teams client. Automation to block unapproved applications directly in Gateway is planned for a future release.



