> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oleria.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Application Hygiene

> Discover shadow IT applications - the unsanctioned apps your users access outside your approved software catalog - and assess their risk before they become a vulnerability.

Application Hygiene gives you a centralized inventory of shadow IT applications: the unsanctioned apps your users are accessing outside your approved software catalog. Your security team can see which applications are being used without IT oversight, assess the risk they introduce, and act before they become a vulnerability. Detection runs automatically, with no additional configuration required.

## What you can do with Application Hygiene

* **Discover unsanctioned applications** - see every shadow IT application your users are accessing, detected automatically through your connected identity providers.
* **Assess application risk** - review who has access to a shadow application and how they authenticate, to judge whether it's a genuine risk or simply missing from your catalog.
* **Track application activity** - see when a shadow application was first detected and when it was last used, so you can prioritize the ones still actively creating risk.

## Use cases

### Closing shadow IT blind spots

Users adopt SaaS applications outside of IT's approval process to move faster - signing up with a work email or single sign-on without ever registering the app in your software catalog. Each one is a blind spot: an application holding company data and company accounts that your security team has no visibility into.

Oleria detects these unsanctioned applications automatically through your connected identity providers, giving your security team a single inventory of every shadow IT application in your environment.

### Prioritizing shadow IT risk

Not every unsanctioned application is equally risky - some are low-stakes tools a team adopted informally, while others hold sensitive data or broad account access. Reviewing them one by one with no starting point is slow.

Oleria surfaces who has access to each shadow application and how they authenticate, so you can quickly separate the applications worth bringing under management from the ones that need immediate action.

<Note>
  To automate the follow-up once a new shadow application is detected, see the [Detect and report Shadow IT](/posture/detect-report-shadow-it-workflow) workflow.
</Note>

## Application table

The application table lists every shadow IT application detected in your environment.

| Column               | Description                                                                                             |
| :------------------- | :------------------------------------------------------------------------------------------------------ |
| Application Name     | The name of the shadow application - for example, Lucid.                                                |
| Application Instance | The connected identity provider instance through which the application's sign-in activity was detected. |

Filter the table by application to narrow your review.

## Application details panel

Selecting an application opens its details panel.

**Application Hygiene details**

| Field         | Description                                                        |
| :------------ | :----------------------------------------------------------------- |
| Created Date  | The date Oleria first detected this application.                   |
| Last Activity | The date of the most recent sign-in activity for this application. |

**Accounts**

The accounts table lists every account signed in to the shadow application.

| Column       | Description                                                              |
| :----------- | :----------------------------------------------------------------------- |
| Account name | The name or email of the account signed in to the shadow application.    |
| Scope        | The permission scopes granted to the application - for example, `email`. |
| Login Method | How the account authenticated - for example, `OAuth2`.                   |

## Contact us

For questions, contact us at [support@oleria.com](mailto:support@oleria.com).
