Technology Waste Audit · System 03 · deciding what happens to each finding
Cancel It, Merge It, or Ask Why It’s There
Shelfware, redundancy, and shadow IT all land on the same list by the end of Systems 01 and 02, and it’s tempting to run one decision process over all of them: cheapest fix first, most expensive last. That works for shelfware and mostly works for redundancy. It’s the wrong instinct for shadow IT, which needs a different first question before any decision about cost even applies.
The idea in one line: shelfware gets cancelled, redundancy gets merged once the migration cost is understood, and shadow IT gets a question before either — because unlike the other two, it might be showing you a need the sanctioned stack never actually solved.
01
Three findings, three decisions
Shelfware
The most straightforward. Once a seat is confirmed unused, cancelling or downgrading it has almost no downside to weigh against the cost.
Redundancy
Merging two overlapping tools is usually right, but only after checking migration cost, contract lock-in, and whether the overlap was actually legitimate. Rushing it can cost more than it saves.
Shadow IT
Different in kind. It can be waste, a security exposure, or both — but it can also be the clearest evidence in the whole audit that the sanctioned stack doesn’t do something people actually need. Ask why before deciding what.
02
Shelfware: cancel, and be honest about what’s actually recoverable now
Not every dollar of shelfware becomes cash in the same week. Keep these as four separate labels rather than one number.
Four buckets, never combined into one figure
Verified recoverable: a cancellation or downgrade you can execute this week — month-to-month seats, or ones already past minimum commitment.
Renewal-period savings: the contract change is real and justified, but locked until the renewal date. Log the date and revisit it, don’t forget it.
Potential exposure: looks like shelfware but needs a workflow or contractual check before you can be sure — a current employee with low usage, a seat held for someone returning from leave.
Productivity cost: not a software saving at all. The labor and error cost from fragmentation belongs to System 02’s findings, not this bucket.
A brief that reports “$40,000 in software waste” as one number is combining at least two of these, and the first hard question anyone asks — “when do we actually see that” — will expose it immediately.
03
Redundancy: merge only after checking the cost of moving
1
Confirm the overlap is real. Using System 02’s capability map as the evidence, rather than a category match on a spend report alone.
2
Check lock-in. A contract mid-term may make cancelling now cost more than waiting for renewal, even once the overlap is confirmed.
3
Price the migration, not just the seats. Data export, retraining, and the productivity dip while a team relearns a workflow are real costs that belong in the decision, not a footnote after it.
4
Merge toward the tool with the stronger reason to exist. Not automatically the cheaper one, and not automatically the one more people already use — the one whose “why this one” answer actually held up in System 02.
04
Shadow IT: sanction it, replace it, or shut it down — in that order
The instinct with an unsanctioned tool is to shut it down. That’s the right answer far less often than it feels like it should be.
1
Ask why it’s there. Before anything else. Somebody found this tool and started paying for it or using a free tier because something they needed wasn’t available through the sanctioned stack. Find out what that was.
2
Sanction it, if the need is real and the tool is sound. Bring it under proper procurement, security review, and billing instead of pretending it isn’t there. Sometimes the fastest fix is making the unofficial tool official.
3
Replace it, if the need is real but the tool itself is the problem. Wrong security posture, no support, or a worse version of something the company already licenses elsewhere. Fix the gap with something that meets the same need properly.
4
Shut it down, once the first two don’t apply. No real need behind it, data exposure with no offsetting value, or a need already met elsewhere that someone simply didn’t know about. This is the right call often enough — just not first.
Treating every unsanctioned tool as step 4 by default trains people to hide the next one better instead of asking for it properly, which makes the next audit’s job harder, not easier.
05
A worked example
Closing out the 40-person agency from Systems 01 and 02.
The decisions
Shelfware: 11 departed-employee seats. 3 verified recoverable this week ($1,900/year), 2 locked until renewal in four months ($4,500/year), and the design tool’s unclear seats moved to potential exposure pending a usage export the vendor has to run manually.
Redundancy: merge the Asana seats into ClickUp. Migration cost: two afternoons of board recreation, no contract lock-in since Asana renews monthly. Net positive within the first quarter.
Duplicate entry: connect Monday to the accounting system directly — the API supports it, nobody had checked. Removes the 40-minute weekly re-entry entirely.
Shadow IT: the design team has been expensing a file-conversion tool nobody in IT knew about. Asked why, the answer is that the sanctioned design tool doesn’t export to the format two key clients require. Sanctioned, not shut down — brought under the company’s billing and reviewed for data handling, because the need was real.
Four findings, four different actions, and the one that looked most like a policy violation turned out to be the one closest to a real, unmet business need.
Systems 01 to 03 are one method in three passes: reconcile what you’re actually paying for against who’s still here, map what’s genuinely redundant against what only looks that way, then give each finding the decision it actually needs. The complete system assembles them into something you can run start to finish on your own software spend, with the evidence to gather first and a master prompt to paste into whatever assistant you already use.