Join our Newsletter — 33% off our NHI Course

What should teams do first when SaaS spend starts to drift upward?

Start with identity-led discovery, not a budget freeze. Pull SSO logs, OAuth grants, invoices, and AP records into one inventory, then compare purchased seats with meaningful activity in the last 90 days. That sequence finds both hidden applications and the easiest seats to reclaim.

Why This Matters for Security Teams

SaaS spend drift is often a control problem before it is a finance problem. When subscriptions rise without a matching increase in active use, teams usually have shadow apps, stale seats, and abandoned OAuth grants hiding in plain sight. The fastest way to recover value is to identify who can still reach what, then measure whether that access is being used. That is why identity-led discovery beats a blanket freeze, which tends to block legitimate work while leaving the real waste untouched.

Pulling SSO logs, OAuth grants, invoices, and AP records into one inventory gives teams a defensible view of both sanctioned and unsanctioned SaaS usage. Comparing purchased seats with meaningful activity over the last 90 days then exposes accounts that are paid for but no longer operationally necessary. That same inventory also improves security oversight because dormant accounts and overbroad grants are often the easiest path for excess exposure to persist unnoticed. In practice, many teams discover their largest SaaS savings only after they already have overlapping renewal, access, and ownership problems.

How It Works in Practice

The first step is to build a joined inventory, not a budget target. Security, procurement, and finance each hold part of the picture, and drift becomes visible only when those views are reconciled. SSO logs show authentication activity, OAuth grants show delegated access, invoices show what was bought, and AP records show what was actually paid. When those records are aligned, teams can separate three classes of spend: active and justified, inactive but recoverable, and unknown or unmanaged.

The 90-day activity check matters because it balances confidence and practicality. A seat can be formally assigned yet operationally idle, and a recent sign-in does not always mean the user is still doing real work. Teams usually get better results when they define meaningful activity up front, such as recent login plus application use, rather than treating any token refresh as proof of value. That prevents reclaimed seats from bouncing back into circulation because the signal was too weak to trust.

  • Inventory every SaaS app that appears in SSO, finance, and procurement records.
  • Match paid seats to named users, service accounts, and delegated OAuth grants.
  • Flag seats with no meaningful activity in the last 90 days for owner review.
  • Separate dormant accounts from applications that are still business-critical but poorly measured.
  • Reclaim only after validating that the access path is no longer needed.

Used this way, the same process supports cost recovery and access governance at the same time. The inventory becomes a living control surface, not a one-time cleanup exercise. These controls tend to break down when SaaS ownership is split across departments because no one team can confirm whether a paid seat is truly inactive.

Common Variations and Edge Cases

Tighter spend control often increases coordination overhead, so organisations have to balance reclaim speed against disruption risk. The standard playbook works best for employee SaaS licenses, but it becomes less clean when apps are shared across teams, when contractors rotate quickly, or when a product bundles multiple functions into one subscription. In those cases, seat counts alone can mislead, because one dormant named account may still sit behind a critical shared workflow.

Another common edge case is delegated access. An application may look inactive from the user perspective while its OAuth grant is still active and pulling data in the background. That is why activity checks should include granted access, not just interactive logins. Likewise, finance records can show spend that security tools cannot see, especially when business units buy outside central procurement. The right response is not to force every case into the same rule, but to apply a clear exception path for shared, seasonal, or integration-heavy services.

Risk and Threat Considerations

Uncontrolled SaaS drift creates both financial waste and security exposure. The main risk is that purchased access remains live long after it stops being useful, which increases the chance that stale accounts, overbroad grants, or forgotten integrations continue to hold data access. The same inventory gap also makes it harder to spot shadow IT and unsupported applications before they become governance problems.

Failure mechanism: Drift usually materialises when procurement, identity, and app ownership are managed in separate systems, so no one can prove whether access is still justified. That separation leaves dormant seats, unused OAuth grants, and untracked applications outside normal review cycles.

Impact: Teams overpay for idle licenses, lose visibility into who can access which SaaS data, and delay revocation of access paths that should have been closed. In a larger estate, that can also hide concentration risk because one unmanaged application may expose many accounts at once.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 5 — Account Management Identity-led SaaS discovery depends on reconciling active and dormant accounts.
6 — Access Control Management Seat reclamation requires validating who still has access to each SaaS app.
Recommendation — Review and remove inactive SaaS accounts and grants on a defined cadence. Enforce least privilege and revoke access paths that are no longer needed.
NIST CSF 2.0 ID.AM — Asset Management Joining SSO, finance, and AP data creates the inventory needed to find drift.
Recommendation — Maintain an authoritative inventory of SaaS assets, owners, and access relationships.

Practitioner Guidance

What to prioritise: Start with the inventory join, not the cleanup. If the team cannot reconcile SSO, OAuth, invoice, and AP data into one view, any reclamation effort will be partial and easy to reverse.

Decision rule: Treat a seat as reclaimable only when it has no meaningful 90-day activity and the owner can confirm there is no dependent workflow behind the account or grant. If either condition fails, move it to exception review rather than immediate removal.

What good looks like: The organisation can explain, for each major SaaS product, who owns it, who uses it, what was paid for, and which access paths are still active. That is the point where spend control and access governance begin to reinforce each other instead of competing.

Practitioner takeaway: The best first move is to prove which SaaS access is still real, because once usage is visible, waste and risk usually appear in the same places.