Run a full inventory of any mature Azure DevOps organization and you will find them: build definitions with no recent commits to their repos but scheduled triggers still firing; pipelines cloned for an experiment that became load-bearing; classic definitions predating the current team entirely. None of them appear in the security program, because the program only knows about pipelines someone registered.

How pipelines go shadow

  • Team reorganizations that orphan projects without deleting them.
  • Clone-and-modify workflows that copy everything except the security configuration.
  • Vendor and contractor projects created outside the standard process.
  • Migrations that leave the old pipeline 'temporarily' running alongside the new one.

Why registration-based coverage fails

Any process that requires humans to tell the security program about pipelines will undercount, permanently. The only trustworthy denominator comes from discovery: enumerating what the platform APIs actually report, continuously, and classifying every result as enrolled, excluded-with-reason, or unaccounted.

Discovery as a standing process

Kangl's inventory synchronization enumerates organizations, projects, repositories, and build pipelines directly from Azure DevOps on a schedule — so a pipeline created on Tuesday appears in coverage accounting by Wednesday, not at the next annual review. Shadow pipelines stop being invisible; they become a queue with an owner.

KEEP READING