Every organization has two operating models.
The first is the one leadership presents in PowerPoint. The second is the one employees use every day.
One is documented. The other often gets the work done.
We talk a lot about Shadow IT: unsanctioned SaaS tools, unofficial databases, local spreadsheets and departments bypassing central IT.
But Shadow IT is only part of the story.
The bigger issue is Shadow Operations: the unofficial workflows, decisions, exceptions and workarounds that keep an organization moving when the formal operating model does not fully support reality.
For me, this is particularly visible because I started my career in the operational grind myself. I know what it feels like to run into systems that are supposed to help work move faster, but in practice slow it down, fragment it or sometimes prevent it from happening altogether.
When that happens, people adapt.
They do not usually create workarounds because they want to bypass governance. More often, they do it because the customer, colleague, deadline or business process cannot wait.
That is an important distinction.
Shadow Operations can look like:
- A spreadsheet that quietly becomes the real source of truth.
- A Teams chat where approvals happen faster than in the official workflow.
- A trusted colleague who is called directly because the ticketing route takes too long.
- A personal checklist that captures exceptions missing from the formal process.
- A manual reconciliation step that compensates for poor system integration.
- A senior employee who knows exactly how things really work, but whose knowledge is not documented anywhere.
None of this automatically means people are doing the wrong thing.
Often, it means people are trying to keep the business running despite imperfect systems, limited change capacity or process design that no longer matches operational reality.
That does not make Shadow Operations harmless.
In regulated, security-sensitive or audit-heavy environments, undocumented workflows can create serious risk. Approvals may not be traceable. Customer data may move through uncontrolled channels. Manual steps may create errors. Segregation of duties may be bypassed without anyone noticing.
This is where operational resilience, auditability and sociotechnical reality meet.
A process is not resilient because it exists in a policy document. It is resilient when the people, systems, controls and evidence flows behind it still work under pressure.
An audit trail is not strong because the process says approval is required. It is strong when the actual approval path is visible, repeatable and defensible.
And an operating model is not effective because it looks clean in a diagram. It is effective when it reflects how people, technology and business constraints interact in practice.
So the point is not to romanticize workarounds.
The point is to understand what they reveal.
Most senior leaders do not know the full detail of what happens in daily operations. And they should not need to. A CIO, COO, CFO or business director should not be expected to understand every exception, every manual correction and every informal dependency.
But they should be aware that these invisible workflows exist.
Because they often show where the formal operating model and the real operating model have drifted apart.
Leadership may see clean process diagrams, governance models, RACI matrices and dashboards. Everything can appear under control.
Meanwhile, the organization may depend on side channels, tribal knowledge, undocumented decisions and people acting as human middleware between broken processes and disconnected systems.
This works remarkably well.
Until it does not.
The risk becomes visible when:
- A key employee leaves, retires or becomes unavailable.
- A transformation program removes a system that was still quietly business critical.
- An audit asks for evidence that was never captured.
- A compliance incident exposes an unofficial approval route.
- A data migration reveals spreadsheets that contain essential operational logic.
- A process redesign fails because it only mapped the formal process, not the real one.
Nobody usually designs this situation deliberately.
Organizations adapt over time. Processes grow. Systems age. Governance expands. Business needs change faster than tooling. Employees find practical ways to close the gaps.
That is not employee failure.
It is organizational feedback.
Shadow Operations are symptoms of something deeper:
- Tooling that does not support the actual work.
- Processes designed for control, but not for usability.
- Governance optimized for audits, but not for execution.
- Underfunded or overloaded change capacity.
- IT and business teams that have drifted apart.
- Legacy systems that remain operationally critical long after they were supposed to be replaced.
The instinctive leadership response is often to eliminate unofficial processes.
That rarely works.
If the underlying friction remains, new workarounds will appear. People will always find the path that allows the work to continue.
A better response is to map Shadow Operations deliberately.
Not to punish people. Not to create another bureaucracy. But to understand where the organization actually runs.
Ask:
- Which spreadsheets are treated as sources of truth?
- Which approvals happen outside official workflows?
- Which people are critical because of undocumented knowledge?
- Which manual steps compensate for system or integration gaps?
- Which processes would break if one specific person were unavailable?
- Which controls exist on paper, but not in daily execution?
The objective is not to eradicate every informal workflow.
Some should be formalized. Some should be automated. Some should be controlled more tightly. Some should be retired. And some may be legitimate operational shortcuts that reveal a better way of working.
The real value is in making the invisible visible.
Because hidden inside many unofficial workflows is an honest description of how work actually happens.
Organizations that understand this can improve process design, reduce operational risk, strengthen compliance and make transformation programs more realistic.
Organizations that ignore it are flying blind.
The real operating model is rarely the one documented in SharePoint.
It is the one people use when the work still needs to get done.
#Leadership #DigitalTransformation #OperationalExcellence #ITLeadership #ShadowIT #BusinessTransformation #EnterpriseArchitecture #TechDebt #ProcessImprovement #ChangeManagement #CIO #FutureOfWork
Originally published on LinkedIn. View all blog posts.