Table Of Content
Shadow IT in Slack and Notion: How Third-Party App Marketplaces Quietly Expand Your Data Exposure Surface
-
August 18, 2026
-
Every Slack integration and Notion connector a team installs is a new door into your company’s data, and most of those doors get installed without security ever knowing they exist. The Slack App Directory now lists over 2,600 third-party apps, and Notion supports hundreds of integrations, with more than 250 available in its public gallery. Each one requests permissions, some broad, some narrow, and each one becomes a standing pipeline that can read messages, pull documents, or move data to a server your security team has never reviewed. This is shadow IT’s newest and least visible frontier: not rogue laptops or unsanctioned cloud drives, but sanctioned collaboration platforms quietly extended by apps nobody vetted.
TL;DR
- Slack and Notion marketplaces let any employee grant a third-party app access to company data in seconds, often with permissions broader than the task requires.
- Roughly 10 to 11 percent of organizations report a breach or security incident tied directly to unauthorized shadow IT and third-party SaaS apps.
- Up to 60 percent of data breaches involve a third party somewhere in the chain, and the 2024 Disney incident, where an unapproved third-party app led to the exfiltration of 44 million internal Slack messages, shows what that looks like at scale.
- Marketplace apps and AI copilots inside these platforms create a data exposure surface that network firewalls and traditional DLP cannot see because the traffic never touches the corporate network perimeter.
- Endpoint-native visibility, where data movement is observed and controlled at the point the user or agent acts, closes the gap that app-store style integrations create.
What Is Shadow IT, and Why Do Slack and Notion Make It Worse?
Shadow IT is the use of software, hardware, or cloud services inside an organization without IT department approval or oversight [cymulate.com]. It used to mean an employee signing up for a file-sharing tool with a personal email. Today it more often means a marketing manager clicking “Add to Slack” on a scheduling bot, or an engineer connecting a Notion workspace to a third-party analytics tool, all in under a minute and without a procurement ticket or security review.
What makes Slack and Notion distinct from earlier shadow IT is that the apps live inside a platform IT already approved. The parent tool is sanctioned; the extensions are not. This is why shadow IT keeps expanding even in companies with mature SaaS policies: the marketplace model turns every employee into a potential integrator, and app installation typically requires nothing more than an OAuth click [accessowl.com][read.ai]. Security teams built processes to catch new SaaS vendors showing up on the expense report. They were not built to catch a workspace admin approving a Notion widget with read access to every page in the company knowledge base.
What Are Concrete Examples of Shadow IT Inside These Platforms?
- A Slack bot for standup reminders that is granted access to all channels, including ones containing credentials or customer data
- A Notion-to-CRM sync tool that pulls entire databases rather than the single table it needs
- A meeting-notes AI assistant added to Slack that ingests full conversation history to generate summaries
- Browser extensions that connect to Notion via personal API tokens, bypassing workspace-level admin controls
- Free-tier productivity apps installed by individual contributors that later get abandoned but retain live access tokens
What Security Risks Do Third-Party App Marketplaces Actually Create?
The risk is not hypothetical; it is structural to how marketplace integrations work. Slack requires developers to use secrets management for credentials and offers Enterprise Key Management with data residency options, and Notion requires public integrations to pass a security review and comply with API rate limits. Those controls matter, but they govern the platform vendor’s side of the relationship. They do not govern what the third-party app does with the data once it has been granted access, nor do they see how an employee’s own AI copilot might summarize or forward that data downstream.
Documented risks include:
- Overly broad permissions: An app requests workspace-wide read access when it only needs a single channel, and that excess scope becomes a standing liability
- Token theft: Stolen employee tokens have been used to access private repositories via connected Slack integrations
- Alleged credential exposure: Reports of massive credential leaks have exposed Notion workspace details tied to third-party connections
- Abandoned integrations: Apps installed for a single project that retain live access long after the project ends
- AI ingestion without boundaries: Copilots and summarization bots that pull full message or page histories into external models
Why Doesn't Traditional Security Catch This?
Traditional security stacks were built around a different threat model, and app-marketplace risk falls squarely in their blind spot. Network firewalls inspect traffic crossing a perimeter, but an OAuth grant to a Notion integration is an API call between two cloud services, not traffic that touches the corporate network. Legacy DLP tools were built to catch keywords in outbound email or files copied to USB drives; they were not built to evaluate whether a Slack app’s data pull matches its stated purpose. A cloud app security broker (CASB) can flag that an unsanctioned SaaS app is in use, but most were designed before marketplace-native integrations and AI copilots became the dominant vector, and many operate by inspecting network traffic rather than watching what happens on the device where the connection is actually approved.
This is the same structural gap that AI has opened across the endpoint more broadly. An AI copilot embedded in Slack or Notion can read, summarize, and move sensitive data at machine speed, faster than a human reviewer could evaluate the request, and it does so from inside a trusted app, using credentials the user already holds. Legacy endpoint tools look for malware signatures, not for a legitimate app quietly overreaching its scope. This is shadow AI risk in its purest form: not a hostile outsider, but a sanctioned tool behaving in ways nobody explicitly authorized.
How Should Security Teams Actually Close This Gap?
The fix starts by treating the endpoint, not the network, as the place where these decisions get made, because that is where the user actually clicks “Allow” and where the AI agent actually pulls the data. Kitecyber’s operating model for this is straightforward: See, Decide, Enforce, continuously. The agent observes what a user or an AI agent is doing with sensitive data, whether that is a browser session authorizing a Slack app, a Notion export, or a GenAI prompt; evaluates that action in context, considering who is acting, what data is involved, and where it is headed; and enforces the appropriate response in real time, whether that is allow, warn, coach, block, or log.
A practical framework for reducing marketplace-driven shadow IT looks like this:
- 1. Discover what's already connected. Inventory every third-party app with access to Slack and Notion workspaces, including ones installed by individual users rather than admins [cloudfuze.com].
- 2. Classify data before deciding on access. An endpoint DLP solution that understands document context, not just keyword matching, can tell the difference between a public roadmap and a customer contract moving through the same channel.
- 3. Set real-time enforcement at the point of risk, not after the fact. By the time a network log shows unusual data volume, the export has already happened.
- 4. Extend policy to AI agents and copilots, not just human users. Agentic workflows now touch the same data paths that shadow IT apps do, and often with less friction.
- 5. Consolidate rather than stack more tools. Adding a separate CASB, a separate SaaS security posture management tool, and a separate DLP agent creates the same fragmentation problem that let shadow IT grow in the first place.
That last point is where Kitecyber’s model differs from stitching together point products. Rather than layering multiple tools on top of each other, Kitecyber runs one lightweight agent that gives endpoint DLP, SaaS app protection, and AI-agent visibility from a single control plane, closing the blind spots that occur when point solutions do not talk to each other. For teams evaluating a Zscaler alternative or looking to replace a fragmented stack of Safetica, Netwrix, or Cyberhaven agents, consolidation eliminates the gaps that shadow IT exploits by reducing reliance on separate disconnected tools.
About Kitecyber
Kitecyber is an endpoint-native data security company designed for environments where AI copilots and third-party integrations move sensitive data at scale. Instead of stacking a CASB, a DLP agent, and a SaaS monitoring tool, Kitecyber runs one lightweight agent that sees data movement across browsers, SaaS apps, GenAI prompts, and files, decides whether that movement matches policy, and enforces the right action in real time. It is used by security and IT teams at companies including DuploCloud, Vanta, Lily AI, Sarvam, and Scrut Automation to replace fragmented point solutions with a single source of truth for where sensitive data goes. That consolidation approach is why teams evaluating alternatives to legacy DLP and SSE vendors increasingly look to Kitecyber for prevention over reaction.
Shadow IT in app marketplaces is not going away; it is expanding as AI copilots become standard features inside every collaboration tool. Visit Kitecyber to see how endpoint-native data security can help your team innovate with confidence.
References
- What Is Shadow IT? Risks & How to Manage It (cymulate.com)
- Shadow IT Management: Complete Guide for IT Teams | AccessOwl – AccessOwl Blog (accessowl.com)
- What is Shadow IT Explained: Risks & Management Tips (read.ai)
- How to Manage Shadow IT in 2026: A Clear 6-Step Framework (cloudfuze.com)
- Shadow IT & Shadow AI: The Third-Party Risk You Can’t See (strac.io)