Methodology

How the indexes are built

Every Torii Research index is built from real, anonymized SaaS usage data, not surveys. Here is the data, the formulas, and the limits.

Data

Torii Research aggregates anonymized workplace usage data from companies across industries and sizes. Every figure is reported as a percentage, a rank, or a score. No single organization can be identified.

The four indexes

Adoption Index

Top apps by org-level adoption, benchmarked against a 12-month rolling average of overall adoption.

Viral App Radar

The fastest-growing apps across workplaces, published annually.

Shadow IT Index

Apps most often discovered outside sanctioned flows.

AI Breakout

A ranking of AI-driven apps by real usage.

Themes

Every app has one primary theme from a fixed list of 14, assigned by Torii Research from what the product does rather than the vendor's own category. AI-native marks apps in the five AI themes plus AI-first apps in other themes. A theme's share is its apps divided by the apps listed in an edition, so it describes the list, not usage volume. See Themes.

Viral score

Apps are scored on a 0 to 10 scale using a weighted average of three factors, each normalized to 0 to 1:

  • Organizations factor: how many organizations use the app
  • Growth factor: how quickly the app's users double inside an organization
  • Shadow factor: the app's Shadow IT index divided by 100

Viral score = 1 + 9 × average(organizations factor, growth factor, shadow factor)

See viral score and days to double.

Shadow IT index

Based on how often organizations leave an app categorized as "discovered" rather than sanctioned through SSO or procurement. Well-known apps such as AWS and Slack baseline at about 44% discovered because of detection mechanics.

Shadow IT index = (percentage discovered − 0.44) × 1.785, shown as 0 to 100

See Shadow IT index.

Rank change

Rank change compares an app's rank with the previous published edition of the same index, so every value can be checked. Apps that were not in that edition are marked New. See rank change.

Compliance claims

Reports show whether an app's vendor publicly claims ISO 27001, GDPR, or SOC 2, based on vendor documentation or public trust portals. These claims can be inaccurate or outdated, especially for fast-emerging apps. Verify with the vendor before a procurement or security decision.

Limitations

  • The data comes from the Torii customer base, which is broad but not the whole market.
  • Org-level adoption is weighted more heavily than individual seats.
  • Enterprise staples can appear as shadow IT because of detection mechanics; the baseline normalizes for this.
  • Compliance information can lag a vendor's real status.
  • Fast-moving app launches can produce anomalies in a single edition.

Corrections

When something in a report is wrong, it is corrected and logged. Every edited page carries a changelog with the date, the type of change (correction, update, or clarification), and a one-line description. The Markdown copy and data files carry the full reason.

Citing this research

Every report has a Cite button with APA, MLA, Chicago, and BibTeX formats, CSV and JSON downloads, an embeddable top-10 widget, and a plain-text Markdown copy. Figures are free to quote with attribution to Torii Research and a link to the report.

Questions

What is the sample?
Anonymized usage data from companies across industries and sizes. Figures are reported as percentages, ranks, and scores only, and no single organization is identifiable.
How is "viral" defined?
A weighted score based on how many organizations use an app, how fast it grows inside them, and its Shadow IT factor.
What is "shadow IT" here?
Apps discovered outside sanctioned SSO or procurement, measured by how often organizations leave the app as "discovered."
Why is a well-known app in shadow IT?
Enterprise apps often surface as "discovered" before IT reclassifies them. The index normalizes with a baseline of 0.44.
Is this survey data?
No. It is real usage data from SaaS management, not a survey.
How are compliance badges determined?
They reflect what vendors publicly claim for ISO 27001, GDPR, and SOC 2. They are informational and do not replace due diligence.
How does the Adoption Index work over time?
Each month's top apps are compared against a 12-month rolling average, showing which apps are above or below long-term adoption trends.
Can an organization see its own data?
Reports are aggregate only. No organization-level data is shared publicly.
What happens when something is wrong?
It is corrected and logged. Every edited page has a changelog with the date, the type of change, and what changed.

Get each index the day it lands.

One email a month with the new rankings. No spam, unsubscribe any time.

Subscribe to the newsletter