If you work in a large organization, you already know this, even if you have never named it. Most organizations have two versions of the same workflow. One appears in the process map. It has swim lanes, systems of record, approval paths, owners, and service-level expectations. The other lives in the work itself: the spreadsheet someone updates every morning because the dashboard cannot be trusted, the Slack thread that becomes the escalation path, the email chain where decisions happen, and the person every new hire learns to ask because she knows which exception matters.
Leaders often dismiss these workarounds as disorder. Some are exactly that. A few create compliance, safety, privacy, quality, or control risk and need to be corrected, not celebrated. But many workarounds are evidence of a missing operational capability. They show where process, data, ownership, judgment, and systems have drifted apart. That is where AI strategy should often begin.
For COOs, CIOs, transformation leaders, and AI program owners, the question is not where AI can be inserted. The question is where the organization has already invented unofficial work to compensate for missing capability. A missing operational capability is a recurring need the official workflow cannot satisfy: trusted data, accountable ownership, timely escalation, exception handling, cross-functional translation, decision rights, or usable visibility. A use-case list says what AI might do. A roadmap says which workflow constraints must change for AI to matter.
The next wave of agentic AI makes this more urgent. Organizations are being asked to approve agents that route work, prepare decisions, trigger actions, and coordinate across systems. If those agents are pointed at the visible artifacts of broken workflows, they may make the artifacts cheaper while leaving the operating problem intact. I have seen this play out enough times that it is now the first place I look.
The green dashboard problem
Consider a composite example from manufacturing. A production dashboard is green. The formal system says the process is healthy. But three people are watching three different systems. A camera feed shows something odd, but nobody owns the camera. No work order opens. No escalation rule triggers. A Slack channel fills with messages. Someone prints a screenshot. A huddle forms only after the line stops.
The dashboard did not fail because it was green. It failed because the real workflow was somewhere else. The real workflow was in the judgment that the camera mattered, the confusion about who owned the signal, the Slack thread that became the escalation path, and the human huddle that made a decision after formal mechanisms did not.
That is the conformance gap: the difference between the workflow as designed and the workflow as executed.
AI strategy often skips this gap. A team sees the Slack chaos and asks whether AI can summarize the thread. Someone sees the screenshot and asks whether computer vision can detect the issue. Another person sees the huddle and asks whether an agent can schedule meetings faster. Those questions may be useful later. They are not the first questions.
The first question is: why did the formal workflow fail to convert an observed signal into accountable action? The answer might be better instrumentation, clearer ownership, an escalation rule, workflow-native alerting, AI-assisted exception detection, or a change to the operating rhythm. In many cases, automating the visible artifact before addressing the underlying gap preserves the broken workflow at higher speed. In a few cases, automation can surface the failure and force redesign. Either way, the artifact is the clue, not the diagnosis.
The artifact is usually not the real problem
Workarounds announce themselves as artifacts: a 20-tab Excel dashboard, a daily status email, a duplicate tracker, a personal checklist, a side approval path, a risk log, a standing meeting, a shared spreadsheet that everyone pretends is temporary. The artifact is tempting because it is visible. You can point at it, count it, and imagine an AI tool producing it faster.
But the problem is rarely the spreadsheet. The problem is what the spreadsheet has been forced to become.
In frontline logistics, teams share spreadsheets and scheduled daily emails because the formal system does not give them enough confidence about tomorrow’s execution. Supplier updates sit buried in email. People reconcile status manually because no trusted communication layer shows what changed, who owns the next step, and what risk needs attention.
In a go-to-market handoff, the workaround might be a meeting between marketing and sales because the systems disagree. One team defines a lead one way. Another team reports pipeline another way. A CSM checks accounts in a separate place. The handoff depends on memory, relationships, and clarification after the fact. Adding AI to summarize the meeting does not fix unclear routing, missing fields, conflicting reports, or undefined response rules.
The same is true of the “ask Sarah” dependency. Sarah appears to maintain updates, send summaries, clean up docs, run coordination meetings, and remember the status of every exception. But Sarah is reading weak signals. She knows which stakeholder will object. She translates between teams that use the same words differently. She absorbs role ambiguity. She carries informal legitimacy that no system has been given. An AI system can draft Sarah’s update and summarize her meeting. It can generate a risk log. That may give Sarah more capacity for higher-value work. But if the organization has not captured the judgment, trust, timing, legitimacy, and informal feedback loops that made Sarah’s work matter, the AI will make the artifact cheaper and miss the capability.
Preserve the signal, not the workaround
This argument has a hard boundary. Some workarounds are not clever adaptations. They are control failures.
In financial services, regulators have fined major institutions after employees used private messaging apps and personal channels for business communications outside required record-keeping systems. That was a compliance failure, not a shadow workflow to productize.
Healthcare offers a different warning. Research on electronic health record workarounds has found that locally rational behavior can harm patient safety, quality, and efficiency at the system level. Clinicians may bypass a system to complete urgent work, but the workaround can break the audit trail, hide risk, or create downstream errors.
This is why leaders need a triage gate before they treat any workaround as an AI opportunity. If the behavior touches safety, regulated records, privacy, security, financial controls, auditability, or deliberate circumvention, the response starts with risk review, correction, and governance. A behavior that would not pass an audit should not be renamed innovation. If a person could be disciplined for the behavior, do not productize it before the control issue is resolved.
Workarounds are evidence. Evidence can show a missing capability. It can also show unsafe behavior, misconduct, poor training, user resistance, or a control design that people have learned to evade. The work is to tell the difference.
Why AI makes the gap matter more
Before AI, a broken workflow created human cost. People copied data, reconciled reports, chased approvals, sent reminders, and sat in meetings to rebuild context the system should have carried.
Now AI risks amplifying the cost of those failures when leaders misunderstand the work. The evidence on the magnitude of that effect is still developing, but the mechanism is straightforward. AI can produce more reports nobody acts on, route tasks through systems without clear owners, make recommendations from data nobody trusts, and automate approvals without knowing which exceptions require judgment.
McKinsey’s March 2025 State of AI survey found that workflow redesign was the attribute most strongly associated with reported EBIT impact from gen AI among 25 attributes tested. The same report found that only 21% of respondents at organizations using gen AI said their organizations had fundamentally redesigned at least some workflows.
That does not prove workflow redesign causes AI value. Organizations with stronger AI results may simply be more likely to redesign workflows, or another factor may explain both. But the finding is consistent with a practical lesson: AI value is tied to how work changes, not just whether tools get deployed.
Gartner has issued a related warning. In June 2025, it predicted that more than 40% of agentic AI projects will be canceled by the end of 2027 because of escalating costs, unclear business value, inadequate risk controls, or insufficient data quality. Gartner also warned that many use cases marketed as agentic do not need agentic implementation.
These are not abstract readiness categories. They show up in workarounds every day. A reconciliation spreadsheet is often a trust problem. A daily email is often a signal problem. An approval thread is often a decision-rights problem. An “ask Sarah” dependency is often an undocumented-judgment problem.
This is why workaround analysis is different from generic AI brainstorming. It begins with operational evidence. It asks where people already had to invent a shadow workflow to keep the business running, then tests whether fixing that workflow would change something that matters.
Before and after, treated carefully
Public examples are imperfect because many come from vendors. They are still useful when treated as illustrations, not neutral proof.
Axis Bank is one useful case. According to a Microsoft customer story, the bank had manual, email-based, and spreadsheet-driven workflows across branch operations, audit, finance, compliance, and approvals. These were not random bad habits. They signaled missing structured tracking, governance, visibility, and reusable workflow ownership. Axis Bank built a Power Platform Centre of Excellence and scaled governed low-code workflows. Microsoft reports that the bank created more than 120 solutions, reached more than 50,000 users, processed more than 100,000 transactions per month, and reduced operational latency by 40%.
The lesson is not “replace spreadsheets with apps.” What the shadow workflow revealed was a capability gap: structured tracking, governed workflow design, reusable components, and a clearer operating layer.
A similar pattern appears in finance operations. A ServiceNow customer story says Standard Chartered’s Global Finance Operations team moved multiple spreadsheet- and email-based processes into automated workflows, improving transparency and traceability and saving more than 16,800 annual hours. Again, the spreadsheet was not the diagnosis. It was the clue.
The shadow workflow diagnostic
Leaders need a practical way to turn shadow workflows into decisions. Not every workaround deserves investment, not every painful task is worth automating, and not every AI candidate is ready. In my experience, the following diagnostic helps teams decide what a workaround means and what response it deserves.
1. Triage the risk
Before diagnosis, screen the workaround. Does it involve safety, regulated records, privacy, security, financial controls, auditability, or deliberate circumvention? If yes, treat it as a risk issue first. The question is not, “Can AI make this easier?” The question is whether the behavior violates a control or creates unacceptable risk.
2. Observe the workaround
Capture the behavior without judging it too early. Ask what official workflow people bypassed, who uses the workaround, when it happens, what decision or exception it supports, what data people recreated, who became the informal owner, what artifact it creates, and what risk it introduces.
This step matters because many organizations diagnose from complaints instead of evidence. “The CRM is bad” is not enough. “Sales managers export pipeline data every Friday, reconcile it in a spreadsheet, and use that version in the forecast call because they do not trust stage definitions in the CRM” is evidence. Now there is something to study.
3. Measure friction and value
Score the pain, but do not stop there. Look at frequency, labor, delay, error risk, dependency load, and business value.
A workaround that forces 200 employees to copy data across systems every day deserves a closer look. It may also be the best available solution under current constraints. Frequency signals importance. It does not prove the answer.
Every candidate needs an outcome hypothesis. What should change if the workaround is fixed: cost, margin, cycle time, revenue, risk, quality, employee capacity, or customer experience? If no important measure changes, set it aside.
4. Diagnose the capability gap
Name the reason the workaround exists. Most shadow workflows trace back to one or more gaps: data, trust, visibility, ownership, platform fit, judgment, or governance.
A data gap means the system lacks needed information. A trust gap means people do not trust the data, default decision, or approval path. A visibility gap means nobody can see status, ownership, risk, or progress. An ownership gap means roles, queues, escalation paths, or service boundaries are unclear. A platform-fit gap means the system tracks records but does not support the flow of work. A judgment gap means the workflow depends on expertise, interpretation, or legitimacy that has not been captured. A governance gap means review, approval, audit, override, or risk controls are not explicit.
This is where many AI programs go wrong. They identify an artifact, skip the root cause, and automate the artifact.
Take access requests. A request may involve a ticket, an application owner, a manager, billing, license availability, and security review. The tempting answer is an AI agent that approves access. The better answer separates the routine path from the judgment path. If 90% of requests match clear rules, automate that path. If 10% require a real decision, escalate them with context. The goal is to stop wasting human judgment on cases that do not need it while making the real exceptions more visible, not to remove approval altogether.
5. Classify the response
Choose the response before choosing the technology. A workaround may need to be eliminated, standardized, governed, redesigned, integrated, productized, automated, AI-enabled, or deferred.
High-friction, high-value workarounds with high readiness are prime opportunities. Those with low readiness are strategic dependencies: fix the data, ownership, controls, integrations, or process clarity first. High-friction, low-value workarounds are local efficiency problems. Simplify them, template them, or automate lightly. Low-friction, high-value workarounds are risk watches. Monitor, govern, instrument, or clarify ownership. Low-friction, low-value workarounds are noise.
“AI-enable” should trigger a readiness check. Is the data searchable, reusable, and trusted? Are the relevant systems connected? Are decision rights explicit? Are identity, access, authorization, and delegation governed? Can the organization monitor what the AI did and why? Are exceptions defined? Do users understand how their work will change? Is there a business metric tied to the change? If those answers are weak, the opportunity may still be real. It is just not ready.
Not process mining with a new name
Organizations already have ways to study work. Process mining uses event logs to show how processes run through systems. Task mining captures lower-level user activity: application use, clicks, spreadsheets, websites, and repeated desktop behavior. AI use-case workshops gather ideas about where AI could help. All three can be useful.
Shadow workflow analysis asks a different question: what recurring need does the official workflow fail to satisfy? It is especially useful where the important work happens outside clean event logs: judgment calls, verbal handoffs, political navigation, trust gaps, informal escalation, side spreadsheets, and expert dependencies. Process mining shows where work moves inside systems. Shadow workflow analysis shows where the human system repairs what the official system cannot handle. Use both when both are available.
Psychological safety is evidence quality
Shadow workflow discovery fails if people think it is surveillance, blame assignment, or a pretext for replacement. Call it a data-quality point instead of a soft culture point.
If surfacing a workaround feels like volunteering for punishment, the useful evidence will stay hidden. People will clean up the story before they tell it, describe the official process instead of the lived one, and protect the spreadsheet that protects them.
Harvard Business Impact, drawing on Amy Edmondson’s work, defines psychological safety as the ability to ask questions, admit mistakes, and challenge ideas without fear of embarrassment or retribution. In this context, the practical rule is simple: leaders must frame the inquiry as a study of where the system of work fails the work, not where employees failed the system.
That means a few operating rules. Name the purpose before collecting examples: “We are studying where the system forces workarounds, not who broke the process.” Separate discovery from discipline, unless a safety or legal issue requires escalation. Collect patterns before names. Protect the practical expert. The person everyone asks for help is often compensating for missing translation, context, or decision rights.
Make the response menu explicit. The outcome is not automatically automation or headcount reduction. It might be eliminating duplicate work, governing a risky behavior, redesigning a handoff, integrating systems, productizing a local practice, or deferring until the basics are fixed.
Show one closed loop quickly. Pick one low-risk workaround, diagnose it with the team, remove friction, and report back. Trust turns shadow workflow discovery from confession into repair.
The better AI question
The weakest AI strategies ask, “What can AI automate?” A stronger question is, “Where has the organization already created a shadow workflow because the official workflow cannot support the work?”
The strongest question is more precise: what failure made this workaround necessary, and what response would remove, govern, redesign, or productize the need for it?
That question forces leaders to slow down in the right place. It separates artifacts from causes, friction from value, opportunity from readiness, and useful adaptation from dangerous circumvention. It also respects the people doing the work.
A workaround is often a sign that someone cared enough to keep the business moving despite a system that did not fit the job. But respect does not mean preservation. Some workarounds should become supported capabilities, some should become governed workflows, some should disappear, and some should remain deliberately human with better tools around them rather than a new bureaucracy on top of them.
The person maintaining the spreadsheet, the team working in Slack after the dashboard stayed green, and Sarah carrying the unofficial map of how work gets done are not side characters in the AI strategy. They are showing leaders where the official system has lost contact with reality.
Follow that signal carefully. Protect the people who reveal it. Then decide what should be removed, governed, redesigned, productized, automated, or left human. The workaround is the clue, not the strategy.