By NHI Mgmt Group Editorial TeamBased on Zluri: “Top Tools for IT Teams in 2026” (December 24, 2025)

TL;DR: SaaS discovery, lifecycle automation, and offboarding are now core operational concerns for IT teams, especially where app sprawl and access ownership overlap, according to Zluri’s 2026 overview of IT tools. The practical lesson is that tool choice is increasingly an identity governance decision, not just an IT productivity one.


At a glance

What this is: This is an analysis of IT tooling for SaaS operations that shows identity governance is embedded in discovery, provisioning, renewal, and offboarding workflows.

Why it matters: It matters because IAM and IGA teams cannot separate operational SaaS management from access control, especially when app sprawl, self-service requests, and leaver handling affect governance quality.


Context

IT teams are being asked to manage SaaS sprawl, access requests, and employee offboarding with tools that often sit outside traditional IAM and IGA ownership. In practice, that means the control surface is split across discovery, licence usage, approval workflows, and deprovisioning, even when the governance risk is the same.

The governance gap is not that organisations lack tools. It is that they often treat SaaS operations as an IT productivity problem first and an identity lifecycle problem second, which leaves ownership, access reviews, and offboarding controls inconsistent across the application estate.


Key questions

Q: What breaks when identity governance is not aligned with modern access control in SaaS environments?

A: When governance lags behind access control, organisations lose visibility into who has access, why it was granted, and whether it is still needed. That gap increases unauthorized access risk, weakens segregation of duties, and makes compliance evidence harder to produce. In SaaS-heavy environments, the result is often inconsistent enforcement and delayed revocation.

Q: When should teams prioritise offboarding over new app onboarding?

A: When there is evidence of stale access, incomplete app inventory, or manual deprovisioning, offboarding should come first because it reduces existing exposure before expanding the environment further. Removing unnecessary access also reveals where provisioning controls are already out of sync with actual usage.

Q: What are the signs that SaaS discovery is missing part of the environment?

A: Common signs include apps used outside SSO, tools appearing only in browser or email data, and gaps created by mobile, incognito, VPN, or unmanaged devices. If reported app usage is lower than actual team behaviour, or if departments rely on different tools for the same work, visibility is incomplete. Those gaps usually mean one discovery method is being overtrusted.

Q: How should teams design self-serve access without losing governance?

A: Design self-serve access around a single governed workflow, not a chat shortcut. Intake, policy, approval, and provisioning must stay linked to one authoritative request record so the grant remains auditable and reversible. If any step is manual and detached, self-service becomes convenience without control.


Technical breakdown

SaaS discovery and app sprawl governance

SaaS discovery is the process of identifying what applications are actually in use, including sanctioned, shadow, and duplicated apps. In identity governance terms, discovery is the prerequisite for knowing where accounts exist, where access is granted, and which apps sit outside formal approval paths. Multiple discovery methods can improve coverage, but the governance question is whether those signals feed a controlled inventory that is actually owned and reviewed. Without that bridge, discovery becomes reporting rather than control.

Practical implication: tie SaaS discovery outputs to a governed application inventory and assign clear ownership for review and remediation.

Lifecycle automation for onboarding and offboarding

Lifecycle automation links joiner, mover, and leaver events to account creation, entitlement assignment, and access removal. The operational value is speed, but the governance value is consistency: onboarding should be role-aware, and offboarding should remove access, not just close an HR record. In SaaS-heavy environments, manual deprovisioning is where stale access accumulates because no single system sees the full access footprint. That makes lifecycle orchestration an identity control, not just an IT convenience.

Practical implication: align SaaS provisioning and deprovisioning workflows to the authoritative lifecycle source and verify that removal is enforced across every connected app.

Self-service app requests and entitlement control

Employee app stores and ad hoc request flows reduce ticket volume, but they also shift access decisions into faster, more distributed approval paths. That can be useful when pre-approved apps and role-based suggestions are tightly governed, but risky when request fulfilment bypasses entitlement review or ownership checks. The governance issue is not self-service itself; it is whether request velocity outruns policy enforcement. If approvals are broad and poorly scoped, self-service becomes an access expansion channel rather than a controlled control plane.

Practical implication: constrain self-service requests to pre-approved apps and review entitlement policies for scope, approver quality, and recertification coverage.


NHI Mgmt Group analysis

Tooling choices now shape identity governance outcomes in SaaS operations: the article is not really about a list of IT products, it is about how discovery, provisioning, and offboarding controls are being implemented in operational workflows. When those workflows are fragmented, the governance outcome is fragmented too. The practical conclusion is that SaaS operations and IGA cannot be managed as separate programmes.

SaaS discovery is an identity inventory problem before it is an operations problem: without reliable discovery, organisations cannot know where access exists, which apps are duplicated, or which systems sit outside formal ownership. That is why discovery belongs in the governance stack, not just the admin console. The practitioner implication is to treat app visibility as a control prerequisite, not a reporting feature.

Lifecycle governance is the real value driver hidden inside the article: onboarding and offboarding only work when provisioning and revocation are connected to authoritative lifecycle signals. The moment those flows become manual, SaaS access outlives employment or role need. Practitioners should read this as a warning that access removal quality is a governance metric, not an administrative task.

Self-service access only scales safely when approvals are narrow and pre-approved: app stores and ad hoc requests reduce friction, but they can also expand access if policy scope is too broad. The named concept here is identity control-plane drift, where operational convenience overtakes entitlement discipline. Teams should measure whether request automation is tightening or diluting access governance.

The article validates a broader market shift from IT productivity to governed SaaS operations: vendors are increasingly packaging discovery, lifecycle, and compliance together because those functions now determine access risk. That does not mean every tool claim maps to strong governance. It does mean practitioners should evaluate whether their SaaS operations stack can support reviews, ownership, and revocation at scale.

From our research library:

What this signals

Identity control-plane drift: the hidden risk in SaaS operations is that convenience features like app stores, workflow playbooks, and automated provisioning can slowly outrun entitlement discipline. Once that happens, governance becomes reactive because ownership, approval, and revocation no longer move together.

SaaS operations teams should expect identity governance to be evaluated through practical control outcomes, not platform breadth. Discovery only matters if it supports ownership, revocation, and review, and lifecycle automation only matters if it actually removes access across every connected application.


For practitioners

  • Map SaaS discovery to governed application ownership Build a single inventory that connects discovered apps to business owners, access approvers, and review cadences so visibility turns into accountable action.
  • Automate leaver revocation across every connected app Ensure offboarding workflows remove access from all integrated SaaS services, including apps discovered through SSO, finance, and browser-based signals.
  • Tighten self-service app approval scopes Limit the employee app store to pre-approved apps and require role, department, or seniority-based policy checks before granting access.
  • Review licence and entitlement sprawl together Use usage and access data to identify redundant apps, duplicate entitlements, and stale permissions that inflate risk and cost at the same time.

Key takeaways

  • SaaS tooling becomes an identity governance issue when discovery, provisioning, and offboarding are treated as separate operational functions instead of one lifecycle control.
  • The article’s practical signal is that access ownership, app sprawl, and leaver handling now determine whether SaaS operations are governed or merely managed.
  • Teams should focus on governed discovery, scoped self-service, and complete deprovisioning to prevent stale access from accumulating across the SaaS estate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article repeatedly centres deprovisioning and ex-employee access in SaaS operations.
NHI-05 — Overprivileged NHIThe article highlights redundant apps and access overlap that inflate entitlement scope.
Recommendation — Harden offboarding workflows so SaaS access is revoked across all connected applications. Review SaaS entitlements for excess access and reduce privileges to role-appropriate scope.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe topic is governed access permissions across SaaS apps, owners, and lifecycle events.
Recommendation — Map SaaS approvals and deprovisioning to PR.AA-05 and verify entitlements stay authorised.
CIS Controls v8CIS-5 — Account ManagementThe article is about account lifecycle control across many SaaS systems.
Recommendation — Apply CIS-5 to standardise account provisioning, review, and removal across SaaS tools.

Key terms

  • SaaS Discovery: SaaS discovery is the process of identifying all sanctioned and unsanctioned software-as-a-service applications in use across the organisation. It matters because cloud assurance increasingly depends on seeing where apps share data, what permissions they hold, and which identities can reach them.
  • Lifecycle Automation: The automation of identity events such as onboarding, access changes, and revocation so governance follows the full user or account lifecycle. It reduces manual errors, shortens exposure windows, and helps organisations enforce consistent access controls at scale.
  • Self-Service Access: Self-service access lets users request, approve, or obtain access to systems and data through a controlled workflow without manual intervention from an administrator. It usually relies on policy checks, identity verification, and automated provisioning, so access is granted only when the request matches defined roles, attributes, risk conditions, and approval rules.
  • Identity Control Plane Drift: Identity control plane drift happens when policy, access records, and operational reality no longer match across systems. The result is a governance programme that can report on access but cannot reliably explain or prove the state of that access at a given moment.

Deepen your knowledge

Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org