Join our Newsletter — 33% off our NHI Course

Should organisations treat SaaS spend tools as part of IGA or finance operations?

They should treat them as part of both, but with identity governance taking priority whenever access, ownership, or lifecycle decisions are involved. Finance teams care about cost efficiency, while IAM and IGA teams control who can still use the application and when that access should end. The strongest programmes connect those functions instead of running them as separate workstreams.

How SaaS Spend Tools Fit Into Governance and Operations

SaaS spend tools sit at the boundary between cost control and access control. They are useful to finance because they expose subscription waste, unused seats, and vendor spend. They are also useful to IGA because they surface who has access, whether that access is still justified, and which accounts should be removed when an employee leaves or a role changes.

The practical distinction is that finance owns spend optimisation, while identity governance owns entitlement decisions. If a tool only reports invoices or licence consumption, it belongs in finance operations. If it can drive deprovisioning, certification, or ownership workflows, it has moved into IGA territory as well. That is why programme design should follow the control outcome, not the procurement category. For a broader governance baseline, IAM and IGA Basics is the right starting point.

Where spend tools become most valuable is in the connection between SaaS inventory, access review, and joiner-mover-leaver handling. If a platform can show dormant accounts, orphaned tenants, or unmanaged application ownership, it is supporting identity lifecycle governance, not just cost reporting. That makes it adjacent to IGA even when the original purchase was led by finance. Joiner-Mover-Leaver (JML) Guide and Access Reviews and Certification Guide show why these lifecycle and review controls matter to SaaS cleanup.

Where the Boundary Breaks Down in Real Programmes

The boundary usually breaks down when organisations treat licence reclamation as a substitute for access governance. Reclaiming a seat may reduce spend, but it does not answer whether the account still exists, whether it can still authenticate, or whether an owner can re-enable access later without review. That gap is where shadow access and stale entitlements persist. SaaS spend tools that map users to applications, owners, and usage patterns can help close that gap, especially when paired with role and ownership data from IGA.

Another common failure is duplicate ownership. Finance may optimise the contract, while IT may administer the tool, but neither group may know who certifies access or approves removal of a business user. In those cases, the organisation gets reporting without accountability. The tool should therefore be treated as part of the control plane whenever it supports ownership, attestation, or offboarding, and as a finance system only when it stops at billing insight. IGA Buyer’s Guide is useful here because it frames connectors, lifecycle, and governance as selection criteria, not afterthoughts.

For SaaS environments with many dormant accounts and irregular application usage, the most useful controls are the ones that join spend intelligence to entitlement intelligence. Top 10 NHI Issues is also relevant when the same platform exposes service accounts, automation accounts, or shared credentials that finance-only reporting would miss.

What Good Operating Model Design Looks Like

A strong model separates concerns without separating the data. Finance should own vendor economics, renewal decisions, and budget controls. IGA should own application ownership, access recertification, leaver deprovisioning, and exception handling. The spend tool should feed both teams, but its most important integration is into identity workflows, because reducing licence count is less important than removing unnecessary access safely.

The best practice is to define clear decision rules for each workflow. If the question is “How much are we paying?”, finance owns it. If the question is “Should this person still have the app, and can we prove it?”, IGA owns it. If the answer changes when someone moves roles or leaves, the process belongs in identity governance even if finance first detected the licence as idle. For programmes that need to design reviews and cleanup at scale, Role Mining and Role Design Guide helps connect app entitlement decisions to a manageable access model.

Where an organisation has both licence optimisation and access governance goals, the cleanest operating pattern is a shared dashboard with separate actions: cost reduction for finance, access removal for IGA. That avoids the common mistake of letting a spend report become the only signal that access is no longer needed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management SaaS seat and access lifecycle decisions map to account provisioning, review, and removal.
IA-5 — Authenticator Management SaaS tools may expose credentials or session-enabled access that must be governed.
Recommendation — Align spend-tool workflows to account lifecycle controls and remove access when no longer justified. Track and rotate any credentials the SaaS tool manages or reveals.
ISO/IEC 27001:2022 A.5.18 — Access rights The question is about who should control application access and when it should end.
Recommendation — Assign access-right ownership and review cadence for SaaS applications.
CIS Controls v8 CIS-6 — Access Control Management SaaS spend tools influence user access removal, review, and entitlement hygiene.
Recommendation — Use SaaS inventory data to revoke unneeded application access promptly.
CSA Cloud Controls Matrix IAM — Identity and Access Management SaaS spend tools intersect cloud application access, ownership, and lifecycle governance.
Recommendation — Integrate SaaS spend visibility into cloud identity and entitlement governance.

Practitioner Guidance

What to prioritise: Treat any SaaS spend tool that can identify active users, owners, or dormant accounts as governance-relevant first, because those attributes drive access decisions and offboarding risk. Use the finance view for renewal and licence efficiency, but do not let it own the final access decision.

What to verify: Confirm whether the tool is read-only, advisory, or capable of triggering deprovisioning, certification, or workflow tasks. If it can change access outcomes, you need IGA oversight, not just procurement or finance ownership.

Common mistake: Teams often equate reclaimed licences with removed risk. A removed subscription and a removed entitlement are not the same control outcome, and only one of them reduces the chance of unwanted access.

Practitioner takeaway: The right operating model is not “finance or IGA”, it is “finance for spend, IGA for access”, with the boundary drawn at who can still use the application and who is accountable when that access should end.