Because a renewal notice only says time is running out. It does not tell you whether seats are unassigned, tied to departed users, or sitting unused below a reasonable threshold. Without usage data, teams often renew the same quantity by default and keep paying for capacity they no longer need. Usage review turns a deadline into a rightsizing opportunity.
Why This Matters for Security Teams
SaaS renewals are usually decided under time pressure, which makes usage data a control input rather than a nice-to-have report. Without it, organisations tend to renew based on procurement timing, not actual consumption, and that can hide idle seats, orphaned accounts, and duplicate entitlements. In identity-heavy environments, the same blind spot shows up in non-human access too: NHIs outnumber human identities by 25x to 50x in modern enterprises, and NHIMG notes that only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs. The pattern is familiar: if usage is not measured before renewal, waste persists and risk stays embedded in the contract.
This is why security, IT, and procurement should treat renewal review as an evidence exercise. The question is not simply whether the tool is valuable, but whether every paid seat, license, or service account is still justified by actual use. Guidance from the OWASP Non-Human Identity Top 10 reinforces the broader principle that access without visibility is hard to govern. In practice, many security teams encounter overbuying only after a renewal has already been signed and the unused capacity has been paid for again.
How It Works in Practice
A useful renewal review starts by comparing what was purchased to what was actually used over a meaningful time window. For SaaS seats, that means looking at logins, last activity, role assignment, and whether users are active in the workflows that matter. For NHI-adjacent tooling, the same logic applies to service accounts, API keys, and integrations: if an identity is provisioned but not exercised, it still consumes governance effort and may still represent exposure. The lifecycle view in NHIMG’s NHI Lifecycle Management Guide is a helpful reference because it frames inventory, usage, rotation, and offboarding as linked decisions, not separate tasks.
Practically, teams should segment usage before renewal into a few buckets:
- actively used and tied to current business processes
- assigned but lightly used, where reclassification or downgrade may be possible
- unassigned, orphaned, or tied to departed users
- duplicate licenses across teams, subsidiaries, or projects
That review should also account for access risk, not just spend. A seat that has not been used in months may be harmless, or it may be a forgotten privilege path waiting to be abused. The Guide to the Secret Sprawl Challenge shows why organisations need inventory discipline before deciding what to keep, and NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls supports least-privilege and continuous monitoring as part of that discipline. These controls tend to break down when renewals are managed in spreadsheets disconnected from identity, usage, and offboarding systems.
Common Variations and Edge Cases
Tighter renewal review often increases administrative effort, requiring organisations to balance savings against the cost of collecting reliable usage evidence. That tradeoff is especially visible in environments with shared accounts, seasonal demand, contractors, or bundled enterprise agreements where one team’s quiet usage may still be business-critical. Current guidance suggests avoiding one-size-fits-all thresholds, because “unused” can mean different things depending on whether the product is customer-facing, internal, regulated, or tied to incident response.
There are also cases where low usage should not automatically trigger cancellation. A disaster recovery tool, a privileged admin console, or a rarely used integration may be intentionally dormant but still essential. The decision should be based on business purpose, not raw activity counts alone. That is why renewal reviews should combine usage data, owner validation, and risk review. For identities and credentials, the broader NHI lesson from Ultimate Guide to NHIs — Static vs Dynamic Secrets is clear: what is not being used still needs a governed decision, not an assumption. In practice, organisations get this wrong when they treat renewal as a finance event instead of a control checkpoint.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Renewal review depends on knowing who still has access and whether it is justified. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Usage visibility is foundational to governing non-human identities tied to SaaS and integrations. |
| NIST AI RMF | Usage-driven decision making supports governance and accountability for automated identity-related workflows. | |
| CSA MAESTRO | Agent and service usage data helps govern autonomous workloads and their access footprint. |
Maintain an accurate inventory of active identities, service accounts, and their usage before renewing contracts.