By NHI Mgmt Group Editorial TeamBased on Zluri: “KPIs for Modern IT Teams - 2026” (December 24, 2025)

TL;DR: SaaS sprawl, shadow IT, and license waste obscure identity control, access lifecycle discipline, and measurable security outcomes, according to Zluri’s KPI guide, which frames IT performance around availability, maintenance, compliance, and deployment success. IT metrics only matter when they translate into clearer identity governance and tighter operational accountability.


At a glance

What this is: This is an IT KPI guide that links operational metrics to SaaS sprawl, shadow IT, license waste, and identity governance gaps.

Why it matters: It matters because IAM, IGA, and IT operations teams need metrics that reveal whether access lifecycle, app inventory, and renewal discipline are actually being governed.


Context

IT KPIs are measurable indicators used to judge whether technology operations are meeting business objectives, but in SaaS-heavy environments they can hide as much as they reveal. When the metric set focuses on uptime, cost, and deployment success without lifecycle governance, teams miss the identity and access failures that accumulate across application sprawl.

The governance gap is not the absence of metrics. It is the absence of identity-aware metrics that connect onboarding, offboarding, vendor termination, license renewal, and shadow IT reduction to measurable control outcomes. In other words, IT performance becomes meaningful only when it shows whether access and application ownership are being controlled, not simply whether systems are running.


Key questions

Q: How can teams tell whether SaaS sprawl is becoming an identity governance problem?

A: Look for mismatches between application count, active usage, and revocation speed. If apps keep renewing after adoption falls, if ownership is unclear, or if offboarding does not remove access quickly, SaaS sprawl has moved from cost inefficiency to governance exposure. That is the point where IAM and procurement must act together.

Q: Why do uptime and deployment KPIs miss governance gaps in SaaS environments?

A: Because they measure service performance, not lifecycle control. A platform can stay available and still carry duplicate apps, stale subscriptions, and unmanaged access paths. Governance gaps appear when the KPI set ignores who owns the application, who can still use it, and when access should be removed.

Q: What breaks when onboarding and offboarding are not part of IT maintenance metrics?

A: Maintenance looks healthy while access drift continues underneath it. If joiner, mover, leaver activity is not part of the scorecard, then stale accounts, vendor access, and unneeded licences can remain active even when the team appears operationally efficient. That is a control failure, not a reporting issue.

Q: How do security and compliance KPIs support SaaS governance accountability?

A: They show whether policy is being executed across the application estate. Good compliance metrics should reveal whether access reviews, audit checks, and renewal decisions are actually happening on schedule and whether exceptions are being tracked. If they do not, the organisation is measuring intent rather than enforcement.


Technical breakdown

How SaaS sprawl distorts IT KPI signals

SaaS sprawl increases the number of applications, subscriptions, and access paths that IT must track, which makes broad operational KPIs less reliable unless they are tied to inventory and ownership. A dashboard can show strong availability or low support tickets while duplicate apps, unused licenses, and unmanaged subscriptions continue to accumulate. The real technical issue is not volume alone, but the loss of control over app discovery, entitlement visibility, and renewal decisions. In that state, the KPI becomes descriptive rather than governable.

Practical implication: align KPI reporting with app discovery, entitlement review, and subscription ownership so sprawl is visible in the metric itself.

Why onboarding and offboarding belong inside maintenance metrics

Maintenance efficiency in SaaS environments is not only about patching or restore operations. It also includes joiner, mover, and leaver handling, vendor termination, and license right-sizing because those are the lifecycle events that determine whether access persists after need has ended. If those events sit outside the KPI, then access control is treated as a side process rather than part of operational maintenance. That creates a blind spot where spend may be optimised while stale accounts and unneeded subscriptions remain active.

Practical implication: define maintenance KPIs to include lifecycle actions, not just technical uptime or support responsiveness.

How security and compliance KPIs expose governance quality

Security and compliance KPIs only become useful when they measure whether systems are actually aligned to policy and regulatory expectations across the SaaS estate. The article points to audit readiness, compliance checks, and risk reduction, which are all governance outcomes rather than tooling outcomes. This matters because a SaaS portfolio can look efficient on paper while still failing access review, offboarding discipline, or license control. In practice, the metric must tell you whether governance is enforced across the application layer, not merely whether policies exist.

Practical implication: use security and compliance KPIs to test governance execution across SaaS, not just to report policy presence.


NHI Mgmt Group analysis

SaaS sprawl is an identity governance problem before it is an IT operations problem: once app inventory fragments, access ownership fragments with it. Duplicate apps, unused licences, and unmanaged renewals all point to the same control weakness, which is that the organisation no longer knows who should own access decisions across the stack. The practical conclusion is that app sprawl metrics must be read as governance signals, not just cost signals.

Maintenance metrics are incomplete when they exclude lifecycle events: onboarding, offboarding, vendor termination, and licence downgrades are not administrative extras. They are the control points that determine whether access and spend remain bounded to business need. When those events are missing from the KPI design, the metric can improve while residual access and waste continue to grow.

Identity lifecycle discipline is the hidden variable behind deployment success: a deployment that launches cleanly but leaves unmanaged subscriptions, shadow IT, or unowned access paths is not operationally successful in governance terms. Zluri’s framing shows that deployment success should be judged by whether the new service is absorbed into a controlled identity and asset model. The practitioner lesson is to treat deployment KPIs as governance checks, not go-live celebrations.

IT performance becomes measurable only when it can be tied to control outcomes: availability, cost savings, and compliance are useful only if they translate into clearer entitlement visibility, faster deprovisioning, and fewer unmanaged applications. That is where a named concept emerges: identity-aware IT KPIs, meaning operational metrics that expose access lifecycle and SaaS governance quality rather than technology throughput alone. Teams should use this model to connect operations reporting to IAM and IGA accountability.

The governance gap is not lack of measurement, but mismeasurement: many IT dashboards reward uptime and spend control while leaving shadow IT and access drift outside view. That creates a false sense of control because the organisation can look efficient while governance debt accumulates underneath. The practitioner conclusion is to redefine KPIs so they reveal whether the SaaS estate is actually governed.

What this signals

Identity-aware IT KPIs: the useful metric is the one that reveals whether app ownership, access lifecycle, and renewal decisions are governed. In SaaS-heavy environments, pure operational reporting can look healthy while entitlement drift and shadow IT continue underneath, so the programme needs metrics that expose control failure rather than hide it.

When IT reporting separates deployment success from governance success, teams can identify where new services enter the estate without a durable owner, review path, or offboarding trigger. That shift matters for IAM and IGA teams because it turns dashboard work into lifecycle control work.

The clearest signal here is that SaaS sprawl is not just an application management issue. It is a governance stress test for identity processes, because every unmanaged subscription or duplicate tool creates another place where access, ownership, and renewal accountability can decay.


For practitioners

  • Define identity-aware IT KPIs Tie availability, maintenance, security, and deployment metrics to app ownership, entitlement visibility, and lifecycle outcomes so the dashboard reflects governance quality, not just service performance.
  • Include onboarding and offboarding in maintenance scoring Measure user and vendor lifecycle actions alongside restore work, renewals, and downgrade activity so maintenance efficiency captures access removal and subscription hygiene.
  • Track shadow IT as a KPI input Make discovered unsanctioned apps, duplicate tools, and unused licences part of the operating scorecard so sprawl is visible before it turns into audit or cost exposure.
  • Separate deployment success from governance success Assess whether each new SaaS rollout has an owner, a review path, and a renewal decision point before calling the deployment successful.
  • Use compliance metrics to test control execution Check whether security and compliance measures actually change access handling, audit readiness, and policy enforcement across SaaS rather than serving as reporting only.

Key takeaways

  • SaaS sprawl turns ordinary IT reporting into a governance test, because availability and cost metrics can improve while access control weakens.
  • The strongest signals in the article are lifecycle related, especially onboarding, offboarding, renewals, and licence right-sizing across the SaaS estate.
  • Teams should make KPI design reflect ownership and entitlement control, or the dashboard will keep rewarding activity that does not reduce risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingOffboarding and vendor termination are central to the maintenance gap discussed in the article.
NHI-05 — Overprivileged NHIUnused licences and unmanaged subscriptions often preserve excess access beyond business need.
Recommendation — Treat offboarding as a tracked control and verify that access removal is reflected in KPI reporting. Review SaaS entitlements for overprovisioning and remove access that KPI data shows is no longer used.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article repeatedly points to entitlement visibility and access control as hidden governance gaps.
Recommendation — Measure whether access permissions and entitlements are owned, reviewed, and removed as part of IT governance.
CIS Controls v8CIS-5 — Account ManagementThe KPI discussion maps directly to account lifecycle, renewals, and stale access control.
Recommendation — Use account management metrics to track joiner, mover, leaver outcomes across SaaS and vendor accounts.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeSaaS sprawl and unused licences are symptoms of access that exceeds current business need.
Recommendation — Apply least privilege reviews to reduce entitlement drift across the SaaS estate.

Key terms

  • SaaS Sprawl: SaaS sprawl is the uncontrolled spread of software-as-a-service applications across teams and business units. It creates fragmented ownership, duplicated functionality, and weak visibility into who can access what. For IAM and NHI teams, the main risk is not only cost but persistent entitlements that outlive business need.
  • Identity-aware KPI: An identity-aware KPI is an operational metric that measures more than system performance. It connects service delivery to access ownership, lifecycle control, and entitlement governance so teams can see whether the technology estate is being run safely and not just efficiently.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org