Because usage data, procurement records, and identity assignments are often managed in separate systems. When those signals are not reconciled, licences renew automatically and dormant access persists. Mature environments still leak spend when no one owns the lifecycle of subscriptions end to end.
Why unused SaaS licences persist even in mature environments
Mature environments usually do not have a visibility problem in one system, they have a reconciliation problem across several. The licence may be active in procurement, the seat may be assigned in the SaaS admin console, and the user may already have changed role or left the organisation. When those records drift apart, renewal logic keeps running and dormant access stays funded.
The important nuance is that “unused” often means “not recently observed,” not “fully removed.” SaaS products rarely revoke entitlement just because usage drops, and finance teams rarely see the identity-side signal needed to confirm that a subscription is truly dead. That gap creates a quiet accumulation of waste, especially where subscriptions are renewed in bulk or purchased by business units rather than centrally governed.
Maturity can actually make the problem stickier. Large environments tend to have multiple procurement paths, multiple admins, and local exception handling, so no single owner sees the full lifecycle from request to assignment to review to offboarding. SalesBleed Salesforce Agentforce 2026 is a useful reminder that SaaS access does not only create cost leakage, it can also create security exposure when identities and tool access are left active without a clear lifecycle owner.
Where the control breakdown usually starts
The control failure is usually not one dramatic mistake. It is the absence of a closed loop between demand, entitlement, and actual use. Procurement records can show what was bought, IAM or directory records can show who was assigned access, and SaaS audit logs can show who actually used the product, but those datasets are often reviewed by different teams on different schedules.
That separation matters because each system answers a different question. Finance asks whether the subscription renewed, IT asks whether the account still exists, and the application owner asks whether anyone complained. None of those questions by itself proves that the licence is still justified. If offboarding is not linked to access review and subscription governance, dormant licences persist long after their business purpose has ended.
Seasoned teams also underestimate how often exceptions become the default. Temporary project seats become permanent, manager approvals become annual rubber stamps, and old service accounts or shared accounts remain attached to paid subscriptions because the environment can still authenticate into the vendor tenant. The result is a steady background of spend leakage that looks small at the row level and material at portfolio scale.
What mature teams need to measure, not just observe
The practical test is not whether a licence was used once recently, but whether the subscription has a documented owner, a current business purpose, and a revocation path when that purpose ends. You need to know which licences are tied to active roles, which are tied to dormant identities, and which are tied to workflows that have not been validated since the last renewal cycle.
Strong environments track seat utilisation, but they also track entitlement age, last-use age, renewal dates, and offboarding lag. That gives you a way to separate seasonal inactivity from true waste. The goal is to identify licences that are still payable but no longer defensible, then remove them before renewal rather than after the invoice has landed.
For access-heavy SaaS platforms, the identity layer should be part of the same review. If a user no longer needs the application, the corresponding account, token, or connected integration should be removed or downgraded in the same change window. NIST SP 800-53 Rev 5 Security and Privacy Controls is a useful control reference for treating access governance, auditability, and configuration discipline as linked responsibilities rather than separate chores.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Unused licences persist when account lifecycle and assignment are not governed end to end. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Actual use evidence is needed to reconcile procurement, assignment, and utilisation. | |
| Recommendation — Review, disable, and remove SaaS accounts and entitlements when no longer required. Correlate SaaS logs with entitlement records to flag dormant paid access. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | SaaS licence waste often reflects stale access rights that were not withdrawn on time. |
| Recommendation — Periodically review and remove access rights that no longer have a business need. | ||
| CIS Controls v8 | CIS-5 — Account Management | Licence sprawl is driven by weak account and subscription governance. |
| Recommendation — Inventory, review, and reclaim unused accounts and subscriptions on a fixed cadence. | ||
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Licence leakage is a recurring governance risk that needs ownership and decision criteria. |
| Recommendation — Define ownership and thresholds for reclaiming unused subscriptions before renewal. | ||
Practitioner Guidance
What to prioritise: Start with the SaaS products that have the largest seat counts, the highest unit cost, or the weakest ownership model. Those are usually the fastest wins because a small percentage of reclaimable licences can create a disproportionate saving.
What to verify: For each subscription, confirm three things before renewal, an accountable owner, a current business purpose, and evidence that the active assignment list matches actual users. If any of those are missing, treat the licence as a candidate for recovery rather than continuation.
Decision rule: If a subscription cannot be tied to a current role, workflow, or approved exception, do not renew it automatically. Freeze, review, and either reassign or retire it, because renewal without ownership is how mature environments keep paying for abandonment.
Practitioner takeaway: Unused SaaS licences are usually a governance failure disguised as a cost issue, so the fix is not better counting, it is tighter lifecycle ownership across procurement, identity, and renewal.
Related resources from NHI Mgmt Group
- Why do unused SaaS licences keep creating cost even when teams stop using the app?
- Why do overprivileged identities keep showing up in mature programmes?
- Why do over-entitled accounts keep showing up in mature IAM programmes?
- How should security teams prioritise NHI remediation in cloud environments?