TL;DR: C1.ai argues that SaaS management platforms show usage and spend, but identity governance enforces access controls, deprovisions accounts, and preserves auditability, making governance the root-cause control as pricing shifts toward usage and compute models across human, non-human, and agentic identities. License visibility is becoming a symptom metric, while access governance remains the security control that matters.
At a glance
What this is: This article separates SaaS management from identity governance and argues that visibility into usage and spend is not a substitute for access control, deprovisioning, and auditability.
Why it matters: IAM and NHI teams need this distinction because procurement-friendly dashboards can mask excessive access, orphaned accounts, and weak entitlement governance across human and non-human identities.
👉 Read C1.ai's analysis of identity governance vs. SaaS management
Context
SaaS management and identity governance are often treated as overlapping categories, but they solve different problems. SaaS management focuses on application usage and spend, while identity governance focuses on who can access what and whether that access is still justified.
The governance gap matters because visibility without enforcement does not reduce risk. For IAM, IGA, PAM, and NHI programmes, the question is not how much software is being used, but whether access, entitlements, and deprovisioning are controlled well enough to withstand audit and breach pressure.
Key questions
Q: What breaks when identity governance is not aligned with modern access control in SaaS environments?
A: When governance lags behind access control, organisations lose visibility into who has access, why it was granted, and whether it is still needed. That gap increases unauthorized access risk, weakens segregation of duties, and makes compliance evidence harder to produce. In SaaS-heavy environments, the result is often inconsistent enforcement and delayed revocation.
Q: Why does usage-based SaaS pricing change identity governance priorities?
A: When pricing moves away from per-user licences, licence optimisation stops being a meaningful security proxy. The programme has to focus on whether identities can be issued, reviewed, and revoked correctly across human, non-human, and agentic actors. Security value shifts from saving seats to controlling access scope.
Q: What are the signs that a SaaS visibility tool is being overused as a control?
A: The clearest sign is when teams can report on usage but cannot certify entitlements, revoke access quickly, or produce a defensible audit trail. If the main output is savings reports rather than access decisions, the tool is supporting procurement more than governance.
Q: How should organisations govern human, machine, and AI agent access in one programme?
A: Organisations should govern all three through one identity model, but with actor-specific controls for provisioning, review, and revocation. Human access still relies on authentication and lifecycle processes, machine identities need secret and credential governance, and AI agents need runtime authority boundaries. The goal is consistent ownership and auditability across different actors.
Technical breakdown
Why SaaS visibility does not equal access control
SaaS management platforms centralise data about application usage, spending, and sometimes last-access signals. That makes them useful for procurement, licence optimisation, and vendor rationalisation. But visibility alone does not enforce policy. A team can know a user is over-entitled and still lack the workflows to remove that access, certify it, or prove it was reviewed. In identity terms, the control plane is missing. The platform is observing the problem, not governing it. That distinction matters because security outcomes depend on entitlement enforcement, not on dashboards that describe the current state.
Practical implication: Treat SaaS visibility as an input to governance, not as a replacement for entitlement enforcement and review workflows.
How identity governance closes the root-cause gap
Identity governance platforms operate on the access lifecycle. They assign entitlements, automate deprovisioning, support access reviews, and preserve audit evidence for who had access, when, and why. That is materially different from reporting on application consumption. Where SaaS management answers cost questions, governance answers control questions. The root issue is not whether an app is in use, but whether access is appropriate, revocable, and traceable across joiner, mover, and leaver events. In practice, that is why audit readiness and least privilege depend on governance depth rather than software inventory.
Practical implication: Use governance workflows to prove entitlement ownership, remove stale access, and maintain a defensible audit trail.
Why usage-based pricing changes the identity problem
The article points to a structural shift from per-user SaaS pricing toward usage-based and compute-based models, especially where AI workloads are involved. That shift weakens the old licence-efficiency logic because per-seat savings no longer describe the real control problem. Identity programmes now need to govern access across human users, non-human identities, and agentic systems regardless of how software is billed. When pricing decouples from named users, licence visibility becomes even less relevant as a security measure. The practical security question becomes whether every identity that can act can also be governed.
Practical implication: Rebuild identity strategy around access governance and identity lifecycle control, not per-seat optimisation.
Threat narrative
Attacker objective: The attacker benefits from persistent, unjustified access that widens the blast radius and weakens accountability across the SaaS estate.
- Entry begins when organisations rely on SaaS management data instead of access governance, leaving excessive entitlements and orphaned accounts in place.
- Escalation follows when over-provisioned access remains unchecked because the platform can observe usage but cannot enforce least privilege or deprovisioning.
- Impact occurs when weak entitlement control persists across human, non-human, and agentic identities, increasing audit exposure and breach risk.
Breaches seen in the wild
- Scania insurance portal breach 2025: An attacker used an external user login, likely stolen by infostealer malware, to take insurance claim documents from a Scania portal.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
SaaS management is symptom management, not security governance: The article correctly separates visibility from control. Knowing what is used, what costs money, and which apps are active does not answer the security question of whether access is still justified. The root-cause gap is that reporting can expose waste while leaving entitlement risk untouched. Practitioners should stop treating usage dashboards as evidence of governance maturity.
Identity governance remains the control layer that matters: Access reviews, deprovisioning, entitlement assignment, and audit evidence are the functions that change security outcomes. That is why governance is not a companion feature to SaaS management but a different discipline altogether. The article’s core point is structurally sound: if you cannot revoke or certify access, you do not have control, only visibility. Programme owners should judge tools by enforcement depth, not reporting breadth.
Identity blast radius: The real problem is not how many applications are visible, but how many identities retain access without a governance decision attached. As pricing shifts toward usage and compute models, the old per-user optimisation lens becomes less informative and less defensible. That forces identity teams to manage the blast radius of every human, non-human, and agentic identity that can still act. Practitioners should re-centre governance on access scope, not cost allocation.
Cross-domain governance is now the baseline expectation: The article is strongest where it extends the argument beyond human users. Security teams increasingly need a single governance model that can accommodate human users, service accounts, and AI-driven actors without collapsing into licence reporting. That does not mean one tool for everything. It means one governance standard for access decisioning, lifecycle control, and auditability across identity types. Practitioners should align their operating model to that reality now.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
What this signals
Access visibility is not governance: Teams that rely on SaaS management dashboards to substitute for entitlement control will continue to miss orphaned access, stale approvals, and weak offboarding. The operational test is whether the programme can change access state, not merely describe application usage.
Usage-based pricing changes the identity strategy: As software economics move away from named users, per-seat savings become less useful as a security signal. Identity programmes need to follow the control plane instead, because risk now sits in who or what can act across human, non-human, and agentic identities.
Cross-actor governance becomes the default expectation: The same access lifecycle logic has to extend across employees, service accounts, tokens, and AI-driven actors. A programme that still treats these as separate governance problems will keep producing blind spots at offboarding and certification time.
For practitioners
- Separate visibility from control Use SaaS management data for spend and usage insight, but route entitlement decisions, approvals, and removals through identity governance workflows.
- Map orphaned and over-provisioned access Review accounts, entitlements, and last-access signals to identify access that exists without an active business owner or current need.
- Rebuild recertification around access risk Prioritise certifications for privileged, dormant, and cross-domain access instead of treating every application user equally.
- Extend governance to non-human and agentic identities Include service accounts, tokens, and AI-driven actors in the same access lifecycle rules used for human users.
Key takeaways
- SaaS management can reveal app usage and spend, but it does not enforce access decisions or clean up entitlement risk.
- The article’s core distinction is that identity governance controls the root cause while SaaS management mostly exposes symptoms.
- As pricing models shift toward usage and compute, teams need governance that covers human, non-human, and agentic access together.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centres on excess access that visibility tools do not remove. |
| NHI-01 — Improper Offboarding | The article highlights orphaned accounts and weak deprovisioning as the control failure. | |
| Recommendation — Map unmanaged SaaS access to NHI-05 and remove entitlements that exceed current business need. Apply NHI-01 controls to ensure offboarding revokes access, not just closes the HR record. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Credential and entitlement lifecycle management underpins the governance gap discussed here. |
| Recommendation — Use IA-5 to govern credential lifecycle and revoke access that no longer has a valid purpose. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about whether entitlements are controlled or merely observed. |
| Recommendation — Apply PR.AA-05 to ensure entitlements are approved, monitored, and removed when no longer needed. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account lifecycle and stale access are the practical issues underneath the SaaS management debate. |
| Recommendation — Use CIS-5 to maintain accurate account inventories and remove inactive or unjustified access. | ||
Key terms
- Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
- SaaS Management Platform: A SaaS management platform is a visibility and optimisation layer for cloud software use. It helps teams discover applications, track utilisation, and understand spend patterns, but it does not by itself enforce access policy, revoke permissions, or manage identity lifecycle state.
- Orphaned Account: An orphaned account is an identity that remains active without a clear owner or business purpose. These accounts are dangerous because they often escape review, retain unnecessary access, and provide attackers with low-friction entry points into otherwise governed environments.
- Entitlement: An entitlement is the permission set that defines what a non-human identity can do after it authenticates. It is usually expressed through roles, policies or access assignments, and unmanaged entitlements are a common reason machine identities become over-privileged over time.
What's in the full article
C1.ai's full blog covers the operational detail this post intentionally leaves for the source:
- How the vendor distinguishes SaaS management scope from identity governance controls in practice
- The specific access lifecycle functions that identity governance platforms are expected to automate
- How usage-based and compute-based pricing models change the way teams think about governance
- The vendor's framing of where SaaS management still adds value for procurement and finance teams
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org