Atlassian

Jun 2026

Shadow IT

Role

Product Designer User Researcher

Timeline

M1 May 2023 - Sep 2023 M2 Oct 2023 - Apr 2024 M3 Jul 2024 - Oct 2024

Team

Product Manager Engineers Content Designer Guard Team

Skills

Product Design Product Strategy User Research Prototyping

Role

Product Designer User Researcher

Timeline

M1 May 2023 - Sep 2023 M2 Oct 2023 - Apr 2024 M3 Jul 2024 - Oct 2024

Team

Product Manager Engineers Content Designer Guard Team

Skills

Product Design Product Strategy User Research Prototyping

────────────────────────────────────────── · · ✿✿✿ · · ──────────────────────────────────────────

.overview

Empowering enterprise admins to proactively manage, remediate, and prevent unsanctioned product across the Atlassian platform

Shadow IT apps and Shadow IT controls are two features in Atlassian Administration that helps admins prevent and remediate unsanctioned products across their Atlassian platform. Shadow IT refers to the creation of product instances by users outside the visibility and control of central IT admins. The challenge was building functionality that allows admins to prevent and manage shadow instances at scale. The proliferation of shadow IT was blocking cloud migrations, driving up operational costs, and eroding trust with enterprise customers.

Exploring different dashboard concepts focused on hierarchy, transaction visibility, and clearer everyday financial workflows.

.my role

I was the lead designer responsible for designing the end-to-end Shadow IT apps and Shadow IT controls experience, ensuring admins have the tools to proactively manage, remediate, and prevent shadow IT. I worked alongside Content design, Product, Engineering, and Guard team and I owned the research, product design, and final delivery of the Shadow IT program.

.impact

36%

Enterprise customer adoption

-18%

Reduction in Shadow IT

-18%

Reduction in Shadow IT

+32%

Admin engagement

+32%

Admin engagement

29%

Conversion rate for adding products

Shadow IT apps became a foundational feature for Atlassian Guard and Cloud Enterprise Entitlement, with 36% adoption across enterprise customers. This contributed to $20M+ in retained/expanded contracts by resolving critical access and compliance escalations.

With Shadow IT controls, organizations reduced shadow IT by 18% when adopting Cloud Enterprise. This helped organizations block purchases of unnecessary licenses by individual teams and discontinue independent sites that had been procured outside their enterprise license. This feature drove a 29% conversion rate for adding products and a 32% increase in admin engagement.

Key outcomes

Strategic Alignment

Shadow IT controls are now table-stakes for enterprise, regulated, and high-growth customers—unlocking cloud migrations and supporting Atlassian’s System of Work.

Business Outcomes

Protected $20M+ in at-risk revenue, and enabled new upsell/cross-sell motions for CEE and Guard.

Customer Trust

Restored confidence in Atlassian’s enterprise cloud maturity, with positive feedback from marquee customers and recognition at Atlassian Team24.

────────────────────────────────────────── · · ✿✿✿ · · ──────────────────────────────────────────

.problem

Organization admins need visibility and controls over unsanctioned products created by users

01

Gaps in visibility

The existing feature did not include all Atlassian products creating a gap in visibility over the scope of an organizations shadow IT. All products were not integrated with the feature.

02

Lack of controls

Admins didn’t have a way to prevent new products from being created nor the ability to remediate unsanctioned products.

────────────────────────────────────────── · · ✿✿✿ · · ──────────────────────────────────────────

.designs

Prevention and Remediation

Shadow IT as a feature area is made up of 2 pillars: Prevention - Shadow IT controls that prevent the proliferation of unsanctioned product instances and Remediation - Shadow IT apps that provide the visibility and functionality to manage existing unsanctioned product instances.

Shadow IT controls

Shadow IT controls is a feature that allows admins to set proactive controls that prevent managed users from creating new product instances without admin approval. This security feature allows admins to control how end users can create new product instances. This feature allows controls over products with an enterprise entitlement, enabling admins to review requests for Bitbucket, Confluence, Jira, Jira Service Management, and Trello.

With controls configured, new product creation is blocked and admins can review requests. This flexible workflow allows admins to mark as resolved, deny, or approve these requests. The approve flow allows an admin to create a new workspace.

Shadow IT apps

Shadow IT apps surfaces all existing Atlassian product instances created by managed users outside the parent organization. While visibility is helpful, admins need an effective way to remediate these rouge instances. We enabled admins to “Join as Admin” on shadow organizations, providing a path to investigate, remediate, and consolidate rogue instances. We built detailed analytics and export capabilities, allowing admins to prioritize remediation based on user count, activity, and risk.

────────────────────────────────────────── · · ✿✿✿ · · ──────────────────────────────────────────

.key decisions

Packaging strategy tarnishing customer trust

The current packaging strategy behind our Shadow IT features requires enterprise entitlements in order to enforce controls over shadow IT. This decision is a bitter pill for enterprise admins to swallow as prevention of shadow IT is their highest priority. Working with my product manager, we continue to influence a change in this strategy and surface enterprise customer feedback and alternative packaging proposals for consideration.

Probably the biggest gap is the fact that we have to, in order to be able to block it, we have to have an enterprise license. That's not great, especially since we don't intend on purchasing enterprise licenses for some of the products that are available. We should be able as an org to be able to block any managed user from being able to create any Atlassian product outside of our org without our express permission. And right now, uh, certain products they're able to just spin up and create because there is no blocking functionality for that.

Interview participant

Enterprise Organization Admin

Our proposed solution is policy-driven controls that address the current per-product limitations and scaling limitations. By establishing shadow IT as a policy, we would align with the Guard team's policy strategy and provide a consistent, cohesive experience for our admin customers.

01

Control scope

02

Condition parameters

03

Block controls

Proposed policy-driven solution for scalable Shadow IT controls

Lack of remediation controls that scale and improve efficiency

With the lack of engineering resources, we weren't able to deliver solutions that would address user concerns specifically around blocking all activation flows. This required product teams active participation in integrating with our Shadow IT policies. This still remains an ongoing challenge with product teams and enforcement is necessary in order to provide a holistic solution to shadow IT.


We were also unable to address remediation at scale again due to the lack of engineers resourced for this body of work. I developed proposals to implement bulk actions and integration with delete and merge flows in order to help admins streamline remediation at scale. Without bulk actions and these integrations, admins are stuck remediating on a per app basis which is a time consuming flow.

01

List view by organization

Shifting view to focus on shadow organizations provides a high level view of rogue organizations.

02

Bulk actions

Performing actions at scale help small admin teams remediate more quickly.

Proposed Shadow IT apps supporting bulk actions

────────────────────────────────────────── · · ✿✿✿ · · ──────────────────────────────────────────

.lessons

Building solutions that improve efficiency and scale

This project failed to meet our admins main goal to prevent shadow IT at scale that is not limited by their subscription tier. I am continuing to work with my product manager to influence the business operation team to reconsider how the Shadow IT features are packaged that is scalable for all our customers. This project failed to lock down all activation flows due to the lack of participation from product teams. A necessary change in Atlassian is to enforce product teams to integrate with Shadow IT policies to ensure that their products are integrated with the controls and not falling outside these controls and worsening the issue for admins. These failures are decisions beyond the Admin Experience team's control and require more strategic conversations with leadership.

────────────────────────────────────────── · · ✿✿✿ · · ──────────────────────────────────────────