Discovery should come first when the app estate is poorly understood, because you cannot govern what you cannot see. But access review must follow quickly, otherwise discovery becomes a static inventory exercise. The right sequence is discover, assign ownership, then recertify or remove access.
Why discovery belongs before review when the SaaS estate is unclear
Discovery is the first control step when organisations do not have a reliable view of their SaaS footprint. If you cannot identify which applications exist, who owns them, and which users or service accounts can reach them, access review is forced to operate on an incomplete target set. That creates a false sense of governance because the most exposed apps are often the least visible.
Discovery is not just a technical inventory exercise. It establishes the scope for ownership, risk ranking, and review cadence, so later controls can distinguish shadow IT from sanctioned platforms and high-risk apps from low-risk ones. A useful baseline is the Identity Visibility and Intelligence Platforms (IVIP) Guide, which focuses on turning fragmented identity data into a usable view of access.
The practical implication is that discovery should be broad enough to catch unsanctioned or forgotten SaaS, but precise enough to identify ownership and access paths. If the team stops at “what apps do we have?”, the programme stalls. If discovery also surfaces entitlements, dormant accounts, and app owners, it becomes the input to governance rather than a static catalogue.
Why access review still has to follow quickly
Access review is the mechanism that turns visibility into control. Once the app estate is known, the organisation has to confirm whether users, roles, and service connections still need access, whether the ownership is current, and whether stale permissions have accumulated. Review matters because SaaS environments tend to accumulate excess access faster than teams can manually track it.
That is why review should be treated as the next step after discovery, not a competing alternative. Discovery tells you what exists; review tells you whether the access is still justified. Access Reviews and Certification Guide is useful here because it frames review as a closed-loop control that should remove access, not simply document it.
In practice, the best sequence is to assign an accountable owner, then review the highest-risk SaaS first: apps with sensitive data, admin roles, external sharing, weak logging, or broad integration access. Where review is delayed, discovery can become shelfware, because the organisation has visibility without any decision on whether access should remain in place.
How to sequence discovery and review without creating governance theatre
The right order is discover, assign ownership, then recertify or remove access. That sequence matters because review without ownership turns into rubber-stamping, and ownership without discovery leaves blind spots untouched. The goal is to move from unknown apps to named accountability, then to verified entitlement decisions.
For SaaS programmes, the most useful operating model is to pair discovery with the first review cycle rather than waiting for a perfect inventory. That lets teams prove the process on the highest-risk applications while continuing to expand coverage. The IAM and IGA Basics guide is a strong fit for this sequence because it ties provisioning, access reviews, and entitlement governance together.
Discovery-first is the safer default when coverage is weak, but it is not a reason to postpone review indefinitely. A mature programme treats discovery as the scope-setting step and access review as the enforcement step, with both running in a tight loop until the app estate is under control.
Risk and Threat Considerations
When organisations delay discovery, they leave shadow SaaS, orphaned apps, and forgotten integrations outside governance. The main risk is not only missing an app, but missing the access paths attached to it, especially privileged accounts, dormant users, and long-lived third-party connections.
Failure mechanism: Unknown or poorly owned SaaS cannot be reviewed effectively, so excessive access persists, stale accounts survive, and untracked permissions accumulate across business units and tenants.
Impact: Attackers and careless insiders gain more opportunity to abuse uncontrolled access, while the organisation loses confidence that review results reflect the real estate rather than only the visible subset.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-1 — Enterprise Asset Inventory and Control | SaaS discovery depends on knowing the application estate that must be governed. |
| CIS-6 — Access Control Management | The question is about whether access should be reviewed and removed after discovery. | |
| CIS-5 — Account Management | SaaS discovery and review both expose stale accounts and unmanaged access paths. | |
| Recommendation — Build and maintain a SaaS inventory before attempting entitlement review. Review SaaS access and revoke unnecessary entitlements after ownership is assigned. Identify and disable dormant SaaS accounts discovered outside normal governance. | ||
| NIST SP 800-53 Rev 5 | CM-8 — System Component Inventory | Discovery is fundamentally about identifying the SaaS components in scope for governance. |
| AC-2 — Account Management | Access review must verify and remove accounts and entitlements tied to SaaS applications. | |
| AC-6 — Least Privilege | Review is the control that checks whether SaaS access has drifted beyond need. | |
| Recommendation — Inventory SaaS applications before running access certification. Recertify SaaS accounts and remove those without current business need. Reduce SaaS entitlements to the minimum required access. | ||
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | SaaS discovery is an asset inventory problem that must precede governance decisions. |
| A.5.15 — Access control | The review step is about deciding whether SaaS access remains justified. | |
| A.8.2 — Privileged access rights | SaaS estates often hide privileged accounts and admin access that must be reviewed. | |
| Recommendation — Maintain a current SaaS asset inventory before recertifying access. Apply access control reviews to remove unnecessary SaaS access. Review and restrict privileged SaaS access as soon as it is discovered. | ||
Practitioner Guidance
What to prioritise: Start with discovery when the estate is fragmented, but use the first pass to identify owners, administrators, and high-risk integrations rather than building a passive app list. That is the minimum needed to make review actionable.
Decision rule: If an app has no named owner, no confirmed business purpose, or no clear entitlement source, treat it as a review priority even if it is newly discovered. If an app is already well governed, review can be lighter, but it should not be skipped.
What to verify: Confirm that discovery outputs can be tied to named decision-makers and that review results can actually drive removals, not just attestations. A control that cannot revoke access is not yet a control.
Practitioner takeaway: Discovery comes first only to create the scope for governance, but access review must follow quickly enough to change access outcomes, otherwise the programme becomes inventory management instead of risk reduction.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- Should organisations prioritise secret rotation or access review first
- Should organisations prioritise discovery or access restriction first for shadow AI?
- Should organisations prioritise access review or lifecycle automation first?