TL;DR: The Substly Extension complements other integrations to provide organizations real-time visibility into SaaS usage. It helps detect Shadow IT and supports compliance with NIS2, ISO 27001, and GDPR while protecting employee privacy.

The Substly Extension is a lightweight browser add-on that helps track SaaS tools across your organization, including services without SSO. This surfaces shadow IT, identifies high-risk services, and finds unused accounts without compromising personal privacy.

What the Substly Extension Does

The extension passively monitors visits to cloud-based services in Substly's vendor database to provide insights such as:

  • Usage rates -- frequency and volume of service usage
  • Adoption rates -- percentage of those with access who actually use a service
  • Unused user accounts -- identifies dormant accounts
  • Unsanctioned usage -- employees using unauthorized services

Substly monitors SaaS usage, not employees. Only visits to recognized B2B tools are monitored.

Why Use the Substly Extension?

Most companies can only list tools they know about--insufficient for compliance. The extension fills this gap by monitoring actual usage, including services lacking SSO, which often carry higher risk profiles.

Compliance frameworks supported:

  • NIS2 -- EU-wide cybersecurity directive
  • DORA -- Digital Operational Resilience Act
  • ISO 27001, SOC 2, GDPR -- frameworks requiring vendor transparency and data accountability

Business value highlights:

  • Detect shadow IT and unapproved services
  • Support compliance efforts with vendor visibility
  • Optimize SaaS spending by identifying unused tools
  • Improve IT operations with actual usage visibility
  • Increase decision-making confidence with objective data

How the Extension Works

Supported browsers: Google Chrome, Microsoft Edge, Firefox, Safari, and most Chromium-based browsers.

  • Passive monitoring: Runs quietly in the background without interrupting users
  • URL-based detection: Checks visited URLs against Substly's SaaS database
  • Scope limitation: Only monitors known B2B services
  • Silent deployment: Automatic installation via Google Workspace, Microsoft Intune, or other MDM systems
  • Tamper prevention: Admins can prevent logout or uninstallation

Personal Integrity & Privacy

Core privacy principles:

  • Only B2B SaaS tools are monitored
  • No personal browsing tracked (news, social media, banking, etc.)
  • No content or sensitive data logged (page content, search terms, messages)
  • Only domain and basic path captured (no query strings or parameters)
  • All matching occurs locally; data sent only upon vendor database match
  • Design aligns with GDPR, ISO 27001, and NIS2 requirements

Respecting time, not usage depth: The extension measures "how often" a service is accessed per day rather than time spent, protecting privacy while assessing actual usage.

What Data Is Captured

When users visit monitored B2B SaaS tools, the following may be logged:

  • Tool accessed (based on URL match)
  • User identifier (based on Substly user)
  • Timestamped access (date of usage)
  • Frequency of visits (aggregated daily)

Admin Controls & Customization

  • Deploy silently across browsers via MDM tools
  • Authenticate users automatically using corporate browser profiles
  • Restrict uninstall or logout options
  • Enable anonymous monitoring mode for strict privacy policies
  • Set up policy-based notifications for policy violations