---
title: "Shadow IT in Slack and Notion: How Third-Party App Marketplaces Quietly Expand Your Data Exposure Surface"
id: "35518"
type: "post"
slug: "shadow-it-in-slack-and-notion-how-third-party-app-marketplaces-quietly-expand-your-data-exposure-surface"
published_at: "2026-08-18T10:38:26+00:00"
modified_at: "2026-08-18T11:09:38+00:00"
url: "https://www.kitecyber.com/shadow-it-in-slack-and-notion-how-third-party-app-marketplaces-quietly-expand-your-data-exposure-surface/"
markdown_url: "https://www.kitecyber.com/shadow-it-in-slack-and-notion-how-third-party-app-marketplaces-quietly-expand-your-data-exposure-surface.md"
excerpt: "Table Of Content What Is Shadow IT, and Why Do Slack and Notion Make It Worse? What Security Risks Do […]"
taxonomy_category:
  - "AI Security"
  - "Cybersecurity"
  - "DLP"
  - "DLP Solutions"
  - "Off-Network Security"
  - "SaaS App Sprawl"
  - "Sensitive Data Theft"
  - "ZTNA"
---

Table Of Content

      - [What Is Shadow IT, and Why Do Slack and Notion Make It Worse?](#what-is-shadow-it-and-why-do-slack-and-notion-make-it-worse)
- [What Security Risks Do Third-Party App Marketplaces Actually Create?](#what-security-risks-do-third-party-app-marketplaces-actually-create)
- [How Should Security Teams Actually Close This Gap?](#how-should-security-teams-actually-close-this-gap)
- [About Kitecyber](#about-kitecyber)

   Related Posts

## [Multi-Framework Compliance Mapping: How to Satisfy HIPAA, GDPR, and CMMC With One Endpoint Data Control Set](https://www.kitecyber.com/multi-framework-compliance-mapping-how-to-satisfy-hipaa-gdpr-and-cmmc-with-one-endpoint-data-control-set/)

## [Shadow IT in Slack and Notion: How Third-Party App Marketplaces Quietly Expand Your Data Exposure Surface](https://www.kitecyber.com/shadow-it-in-slack-and-notion-how-third-party-app-marketplaces-quietly-expand-your-data-exposure-surface/)

## [Data Exfiltration Through Unmonitored Endpoints: Why Network Trust Models Fail in Hybrid Work](https://www.kitecyber.com/data-exfiltration-through-unmonitored-endpoints-why-network-trust-models-fail-in-hybrid-work/)

Table Of Content

      - [What Is Shadow IT, and Why Do Slack and Notion Make It Worse?](#what-is-shadow-it-and-why-do-slack-and-notion-make-it-worse)
- [What Security Risks Do Third-Party App Marketplaces Actually Create?](#what-security-risks-do-third-party-app-marketplaces-actually-create)
- [How Should Security Teams Actually Close This Gap?](#how-should-security-teams-actually-close-this-gap)
- [About Kitecyber](#about-kitecyber)

[ZTNA](https://www.kitecyber.com/ztna/)
[User Identity Theft](https://www.kitecyber.com/user-identity-theft/)
[Snowflake marketplace cybersecurity](https://www.kitecyber.com/snowflake-marketplace-cybersecurity/)
[Snowflake incident](https://www.kitecyber.com/snowflake-marketplace-cybersecurity/snowflake-incident/)
[Snowflake](https://www.kitecyber.com/snowflake-marketplace-cybersecurity/snowflake/)
[Sensitive Data Theft](https://www.kitecyber.com/sensitive-data-theft/)
[Secure Web Gateways](https://www.kitecyber.com/swg/)
[SaaS App Sprawl](https://www.kitecyber.com/saas-app-sprawl/)
[Private Access VPN](https://www.kitecyber.com/private-access-vpn/)
[Private Access Solution](https://www.kitecyber.com/private-access-solution/)

# Shadow IT in Slack and Notion: How Third-Party App Marketplaces Quietly Expand Your Data Exposure Surface

- August 18, 2026
- [Srikanth Chavali](https://www.kitecyber.com/author/shrikant/)

**Quick Answer:** AI Security Posture Management (AISPM), also called AI Posture Management, is the continuous process of discovering, monitoring, and controlling how AI tools, models, and agents interact with your company's data and systems. It covers everything from spotting an unapproved AI app on someone's laptop to blocking a customer record from being pasted into a public chatbot. Most teams that manage AI posture well pair a discovery layer with policy enforcement at the point where employees actually use AI, which is the endpoint.

Every Slack integration and Notion connector a team installs is a new door into your company’s data, and most of those doors get installed without security ever knowing they exist. The Slack App Directory now lists over 2,600 third-party apps, and Notion supports hundreds of integrations, with more than 250 available in its public gallery. Each one requests permissions, some broad, some narrow, and each one becomes a standing pipeline that can read messages, pull documents, or move data to a server your security team has never reviewed. This is shadow IT’s newest and least visible frontier: not rogue laptops or unsanctioned cloud drives, but sanctioned collaboration platforms quietly extended by apps nobody vetted.

## TL;DR

- Slack and Notion marketplaces let any employee grant a third-party app access to company data in seconds, often with permissions broader than the task requires.
- Roughly 10 to 11 percent of organizations report a breach or security incident tied directly to unauthorized shadow IT and third-party SaaS apps.
- Up to 60 percent of data breaches involve a third party somewhere in the chain, and the 2024 Disney incident, where an unapproved third-party app led to the exfiltration of 44 million internal Slack messages, shows what that looks like at scale.
- Marketplace apps and AI copilots inside these platforms create a data exposure surface that network firewalls and traditional DLP cannot see because the traffic never touches the corporate network perimeter.
- Endpoint-native visibility, where data movement is observed and controlled at the point the user or agent acts, closes the gap that app-store style integrations create.

**About the Author:** This article is written from Kitecyber’s vantage point as an endpoint-native data security company that works daily with engineering and security teams at companies like DuploCloud, Vanta, and Scrut Automation, helping them govern exactly the kind of SaaS and AI-driven data movement that Slack and Notion marketplaces enable.

## What Is Shadow IT, and Why Do Slack and Notion Make It Worse?

[Shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 is the use of software, hardware, or cloud services inside an organization without IT department approval or oversight [[cymulate.com]](https://cymulate.com/cybersecurity-glossary/shadow-it/)
. It used to mean an employee signing up for a file-sharing tool with a personal email. Today it more often means a marketing manager clicking “Add to Slack” on a scheduling bot, or an engineer connecting a Notion workspace to a third-party analytics tool, all in under a minute and without a procurement ticket or security review.

What makes Slack and Notion distinct from earlier [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 is that the apps live inside a platform IT already approved. The parent tool is sanctioned; the extensions are not. This is why [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 keeps expanding even in companies with mature SaaS policies: the marketplace model turns every employee into a potential integrator, and app installation typically requires nothing more than an OAuth click [[accessowl.com]](https://www.accessowl.com/blog/shadow-it-the-dangers-and-how-to-avoid-them)
[[read.ai]](https://www.read.ai/articles/what-is-shadow-it-explained-risks-management-tips)
. Security teams built processes to catch new SaaS vendors showing up on the expense report. They were not built to catch a workspace admin approving a Notion widget with read access to every page in the company knowledge base.

## What Are Concrete Examples of Shadow IT Inside These Platforms?

[Shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 examples in Slack and Notion environments tend to follow a pattern: a useful integration requests more access than its function requires, and nobody revisits that grant later. Common cases include:

- A Slack bot for standup reminders that is granted access to all channels, including ones containing credentials or customer data
- A Notion-to-CRM sync tool that pulls entire databases rather than the single table it needs
- A meeting-notes AI assistant added to Slack that ingests full conversation history to generate summaries
- Browser extensions that connect to Notion via personal API tokens, bypassing workspace-level admin controls
- Free-tier productivity apps installed by individual contributors that later get abandoned but retain live access tokens

Each of these is functionally [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 even though it happened inside an approved workspace, because IT and security had no visibility into the permission grant or the ongoing data flow [[cloudfuze.com]](https://www.cloudfuze.com/manage-shadow-it-in-your-organization/)
. Left unmanaged, this class of [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 and shadow AI is now one of the fastest-growing forms of third-party risk, because the access is quiet and persistent rather than a one-time event [[strac.io]](https://www.strac.io/blog/shadow-it-shadow-ai-third-party-risk)
.

## What Security Risks Do Third-Party App Marketplaces Actually Create?

The risk is not hypothetical; it is structural to how marketplace integrations work. Slack requires developers to use secrets management for credentials and offers Enterprise Key Management with data residency options, and Notion requires public integrations to pass a security review and comply with API rate limits. Those controls matter, but they govern the platform vendor’s side of the relationship. They do not govern what the third-party app does with the data once it has been granted access, nor do they see how an employee’s own AI copilot might summarize or forward that data downstream.

Documented risks include:

- **Overly broad permissions:** An app requests workspace-wide read access when it only needs a single channel, and that excess scope becomes a standing liability
- **Token theft:** Stolen employee tokens have been used to access private repositories via connected Slack integrations
- **Alleged credential exposure:** Reports of massive credential leaks have exposed Notion workspace details tied to third-party connections
- **Abandoned integrations:** Apps installed for a single project that retain live access long after the project ends
- **AI ingestion without boundaries:** Copilots and summarization bots that pull full message or page histories into external models

The scale of the problem shows in the numbers: up to 60 percent of data breaches involve a third party, and 10 to 11 percent of organizations report incidents or breaches directly attributed to unauthorized [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 and third-party SaaS applications. The 2024 Disney breach is the clearest illustration: an unapproved third-party app connected to Slack led to the exfiltration of 44 million internal messages, a volume of exposure that no single stolen laptop could match.

## Why Doesn't Traditional Security Catch This?

Traditional security stacks were built around a different threat model, and app-marketplace risk falls squarely in their blind spot. Network firewalls inspect traffic crossing a perimeter, but an OAuth grant to a Notion integration is an API call between two cloud services, not traffic that touches the corporate network. Legacy DLP tools were built to catch keywords in outbound email or files copied to USB drives; they were not built to evaluate whether a Slack app’s data pull matches its stated purpose. A cloud app security broker (CASB) can flag that an unsanctioned SaaS app is in use, but most were designed before marketplace-native integrations and AI copilots became the dominant vector, and many operate by inspecting network traffic rather than watching what happens on the device where the connection is actually approved.

This is the same structural gap that AI has opened across the endpoint more broadly. An AI copilot embedded in Slack or Notion can read, summarize, and move sensitive data at machine speed, faster than a human reviewer could evaluate the request, and it does so from inside a trusted app, using credentials the user already holds. Legacy endpoint tools look for [malware](https://www.kitecyber.com/glossary/malware/)
 signatures, not for a legitimate app quietly overreaching its scope. This is shadow AI risk in its purest form: not a hostile outsider, but a sanctioned tool behaving in ways nobody explicitly authorized.

## How Should Security Teams Actually Close This Gap?

The fix starts by treating the endpoint, not the network, as the place where these decisions get made, because that is where the user actually clicks “Allow” and where the AI agent actually pulls the data. Kitecyber’s operating model for this is straightforward: **See, Decide, Enforce, continuously.** The agent observes what a user or an AI agent is doing with sensitive data, whether that is a browser session authorizing a Slack app, a Notion export, or a GenAI prompt; evaluates that action in context, considering who is acting, what data is involved, and where it is headed; and enforces the appropriate response in real time, whether that is allow, warn, coach, block, or log.

A practical framework for reducing marketplace-driven [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 looks like this:

- **1. Discover what's already connected.**Inventory every third-party app with access to Slack and Notion workspaces, including ones installed by individual users rather than admins [[cloudfuze.com]](https://www.cloudfuze.com/manage-shadow-it-in-your-organization/) .
- **2. Classify data before deciding on access.** An endpoint DLP solution that understands document context, not just keyword matching, can tell the difference between a public roadmap and a customer contract moving through the same channel.
- **3. Set real-time enforcement at the point of risk**, not after the fact. By the time a network log shows unusual data volume, the export has already happened.
- **4. Extend policy to AI agents and copilots**, not just human users. Agentic workflows now touch the same data paths that shadow IT apps do, and often with less friction.
- **5. Consolidate rather than stack more tools.** Adding a separate CASB, a separate SaaS security posture management tool, and a separate DLP agent creates the same fragmentation problem that let shadow IT grow in the first place.

That last point is where Kitecyber’s model differs from stitching together point products. Rather than layering multiple tools on top of each other, Kitecyber runs one lightweight agent that gives [endpoint DLP](https://www.kitecyber.com/glossary/endpoint-dlp/)
, SaaS app protection, and AI-agent visibility from a single control plane, closing the blind spots that occur when point solutions do not talk to each other. For teams evaluating a Zscaler alternative or looking to replace a fragmented stack of Safetica, Netwrix, or Cyberhaven agents, consolidation eliminates the gaps that [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 exploits by reducing reliance on separate disconnected tools.

#### About Kitecyber

Kitecyber is an endpoint-native data security company designed for environments where AI copilots and third-party integrations move sensitive data at scale. Instead of stacking a CASB, a DLP agent, and a SaaS monitoring tool, Kitecyber runs one lightweight agent that sees data movement across browsers, SaaS apps, GenAI prompts, and files, decides whether that movement matches policy, and enforces the right action in real time. It is used by security and IT teams at companies including DuploCloud, Vanta, Lily AI, Sarvam, and Scrut Automation to replace fragmented point solutions with a single source of truth for where sensitive data goes. That consolidation approach is why teams evaluating alternatives to legacy DLP and SSE vendors increasingly look to Kitecyber for prevention over reaction.

[Shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 in app marketplaces is not going away; it is expanding as AI copilots become standard features inside every collaboration tool. Visit [Kitecyber](https://kitecyber.com)
 to see how endpoint-native data security can help your team innovate with confidence.

#### References

1. [What Is Shadow IT? Risks & How to Manage It](https://cymulate.com/cybersecurity-glossary/shadow-it/) (cymulate.com)
2. [Shadow IT Management: Complete Guide for IT Teams | AccessOwl – AccessOwl Blog](https://www.accessowl.com/blog/shadow-it-the-dangers-and-how-to-avoid-them) (accessowl.com)
3. [What is Shadow IT Explained: Risks & Management Tips](https://www.read.ai/articles/what-is-shadow-it-explained-risks-management-tips) (read.ai)
4. [How to Manage Shadow IT in 2026: A Clear 6-Step Framework](https://www.cloudfuze.com/manage-shadow-it-in-your-organization/) (cloudfuze.com)
5. [Shadow IT & Shadow AI: The Third-Party Risk You Can’t See](https://www.strac.io/blog/shadow-it-shadow-ai-third-party-risk) (strac.io)

## Frequently Asked Questions

[What is shadow IT in simple terms?](#collapse-63098cb6a8491d3e0994)

[Shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 is any software, app, or service used inside a company without formal approval or visibility from the IT or security team [[cymulate.com]](https://cymulate.com/cybersecurity-glossary/shadow-it/)
. In Slack and Notion, this most often takes the form of third-party integrations installed directly from an app marketplace.

[What are the biggest shadow IT risks specific to Slack and Notion?](#collapse-96023976a8491d3e0994)

The main risks are overly broad app permissions, tokens that persist after a project ends, and AI copilots ingesting more data than intended. Documented incidents include stolen tokens used against connected repositories and a 2024 breach where an unapproved app exposed 44 million Slack messages.

[How common are breaches tied to shadow IT?](#collapse-573c5b46a8491d3e0994)

Around 10 to 11 percent of organizations report a cyber incident or data breach directly tied to unauthorized [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 or third-party SaaS apps, and third parties are involved in up to 60 percent of breaches overall.

[Is a cloud app security broker enough to manage this risk?](#collapse-0a6f8d26a8491d3e0994)

A CASB can identify unsanctioned SaaS usage, but most were built to inspect network-level traffic, not the app-store style permission grants and AI-driven data pulls that now happen inside approved platforms like Slack and Notion. Endpoint-level visibility fills that gap.

[How is shadow AI different from traditional shadow IT?](#collapse-e36a0036a8491d3e0994)

Shadow AI refers specifically to unsanctioned AI tools, copilots, or agents that read, summarize, or move data, often faster than a human could review the action. AI agent security risks compound [shadow IT](https://www.kitecyber.com/glossary/shadow-it/)
 risk because agentic workflows operate with the same access as the human who deployed them, but at machine speed.

[Can CMMC compliance software help with marketplace app risk?](#collapse-6af1da76a8491d3e0994)

CMMC compliance software focused solely on network and access controls will miss the data movement happening through app integrations and AI copilots. Compliance programs need visibility into SaaS and AI data flows, not just [network segmentation](https://www.kitecyber.com/glossary/network-segmentation/)
, to meet the intent of CMMC's data protection requirements.

[What's the first step to reducing this exposure?](#collapse-19655da6a8491d3e0994)

Start with discovery: inventory every third-party app connected to Slack and Notion, review permission scopes against actual function, and remove access for anything abandoned or over-provisioned.

[https://www.kitecyber.com/author/shrikant/](https://www.kitecyber.com/author/shrikant/)

[Srikanth Chavali](https://www.kitecyber.com/author/shrikant/)

With over a decade of experience steering cybersecurity initiatives, my core competencies lie in network architecture and security, essential in today's digital landscape. At Kitecyber, our mission resonates with my quest to tackle first-order cybersecurity challenges. My commitment to innovation and excellence, coupled with a strategic mindset, empowers our team to safeguard our industry's future against emerging threats. Since co-founding Kitecyber, my focus has been on assembling a team of adept security researchers to address critical vulnerabilities and enhance our network and user security measures. Utilizing my expertise in the Internet Protocol Suite (TCP/IP) and Cybersecurity, we've championed the development of robust solutions to strengthen cyber defenses and operations.

[mailto:skc@kitecyber.com](mailto:skc@kitecyber.com)
[https://www.kitecyber.com/](https://www.kitecyber.com/)

Posts: 83

[https://www.kitecyber.com/author/shrikant/](https://www.kitecyber.com/author/shrikant/)

[Srikanth Chavali](https://www.kitecyber.com/author/shrikant/)

With over a decade of experience steering cybersecurity initiatives, my core competencies lie in network architecture and security, essential in today's digital landscape. At Kitecyber, our mission resonates with my quest to tackle first-order cybersecurity challenges. My commitment to innovation and excellence, coupled with a strategic mindset, empowers our team to safeguard our industry's future against emerging threats. Since co-founding Kitecyber, my focus has been on assembling a team of adept security researchers to address critical vulnerabilities and enhance our network and user security measures. Utilizing my expertise in the Internet Protocol Suite (TCP/IP) and Cybersecurity, we've championed the development of robust solutions to strengthen cyber defenses and operations.

[mailto:skc@kitecyber.com](mailto:skc@kitecyber.com)
[https://www.kitecyber.com/](https://www.kitecyber.com/)

Posts: 83
