Run a full inventory of any mature Azure DevOps organization and you will find them: build definitions with no recent commits to their repos but scheduled triggers still firing; pipelines cloned for an experiment that became load-bearing; classic definitions predating the current team entirely. None of them appear in the security program, because the program only knows about pipelines someone registered.
How pipelines go shadow
- Team reorganizations that orphan projects without deleting them.
- Clone-and-modify workflows that copy everything except the security configuration.
- Vendor and contractor projects created outside the standard process.
- Migrations that leave the old pipeline 'temporarily' running alongside the new one.
Why registration-based coverage fails
Any process that requires humans to tell the security program about pipelines will undercount, permanently. The only trustworthy denominator comes from discovery: enumerating what the platform APIs actually report, continuously, and classifying every result as enrolled, excluded-with-reason, or unaccounted.
Discovery as a standing process
Kangl's inventory synchronization enumerates organizations, projects, repositories, and build pipelines directly from Azure DevOps on a schedule — so a pipeline created on Tuesday appears in coverage accounting by Wednesday, not at the next annual review. Shadow pipelines stop being invisible; they become a queue with an owner.

