By NHI Mgmt Group Editorial TeamBased on Zluri: “Top 8 SaaS Discovery Methods In 2026” (March 20, 2026)

TL;DR: SaaS discovery is positioned as the way to find hidden apps, reduce wasted spend, and improve security across a sprawl of sanctioned and unsanctioned tools, according to Zluri. The real governance issue is not discovery alone, but whether identity and access programmes can keep pace with software use that escapes central control.


At a glance

What this is: This article explains eight SaaS discovery methods and argues that the hardest problem is not finding apps, but governing them once they sit outside central control.

Why it matters: It matters because IAM, IGA, and SaaS owners need a reliable inventory before they can enforce access reviews, lifecycle controls, and shadow IT remediation across sanctioned and unsanctioned apps.


Context

SaaS discovery is the process of finding and mapping the applications people actually use across an organisation, including tools that never pass through central approval. In identity terms, the issue is not just inventory. It is whether governance processes can keep up with software adoption that fragments across departments, devices, and spending paths.

The article frames discovery as a visibility problem with security, cost, and compliance consequences. That framing is directionally useful, but the deeper control question is who owns lifecycle, access, and offboarding once a SaaS app is discovered after the fact. For IAM and IGA teams, the discovery layer is only useful if it feeds decisions fast enough to change access posture.


Key questions

Q: How should security teams govern SaaS apps that are outside formal approval channels?

A: Start by treating unapproved SaaS as an identity and data governance issue, not just an app inventory problem. Classify the app, identify the identities using it, and decide whether access should be approved, constrained, or removed. The goal is to bring unmanaged usage into the same control path as sanctioned applications.

Q: Why does SaaS discovery not eliminate shadow IT risk on its own?

A: Discovery removes blind spots, but it does not automatically assign accountability or enforce lifecycle controls. Shadow IT remains risky because users can create access before central governance knows the app exists. The control failure is the delay between usage and formal oversight, not the absence of detection alone.

Q: What are the signs that SaaS discovery is missing part of the environment?

A: Common signs include apps used outside SSO, tools appearing only in browser or email data, and gaps created by mobile, incognito, VPN, or unmanaged devices. If reported app usage is lower than actual team behaviour, or if departments rely on different tools for the same work, visibility is incomplete. Those gaps usually mean one discovery method is being overtrusted.

Q: Why does SaaS discovery matter for IAM teams?

A: Discovery matters because every governance decision depends on knowing which apps, users, and entitlements actually exist. If the inventory is incomplete, access reviews miss applications, offboarding leaves orphaned access behind, and spend controls operate on partial data. Discovery is the prerequisite for trustworthy identity governance in SaaS.


Technical breakdown

How SaaS discovery methods build the inventory layer

SaaS discovery methods work by collecting signals from network traffic, SSO logs, browser activity, endpoint agents, finance data, APIs, and directory records. Each method sees a different slice of the stack, which is why no single control gives a complete picture. CASBs are better at network-facing usage, API connectors are better at sanctioned apps, and endpoint methods see activity outside the browser. The technical limitation is that discovery depends on where the signal is generated, so coverage is always partial by design.

Practical implication: Treat discovery as a multi-source inventory problem, not a single-tool deployment, and decide which signals map to which parts of the SaaS estate.

Why shadow IT creates a governance blind spot

Shadow IT is not just unsanctioned software. It is software that creates identity and access obligations without creating the corresponding governance record. A team may provision users through an app, an expense line, or a browser session long before IAM or IGA has any visibility. That means entitlements, offboarding, and review cycles start late, if they start at all. Discovery methods expose the app, but they also reveal that governance was never attached to the app’s lifecycle in the first place.

Practical implication: Use discovery findings to trigger ownership, access review, and offboarding workflows for applications that entered the estate outside standard intake.

Why SaaS discovery does not equal access governance

Discovery answers what exists and where it is used. Governance answers who may access it, under what conditions, and how that access ends. Those are different control layers. A discovered SaaS application can still be unmanaged if identities are not tied to joiner-mover-leaver processes, if API tokens are not inventoried, or if SSO coverage gives a false sense of completeness. The operational mistake is assuming visibility closes the risk. It only creates the evidence needed to govern it properly.

Practical implication: Separate inventory from control enforcement, and ensure every discovered app is matched to an owner, access model, and lifecycle path.


Threat narrative

Attacker objective: The practical objective is to exploit unmanaged software adoption and incomplete visibility to leave access, cost, and compliance gaps in place long enough for abuse or waste to persist.

  1. Entry occurs when employees adopt sanctioned or unsanctioned SaaS applications through browser use, expense claims, or local workflow choices before central IT is aware of them.
  2. Credential and access state accumulate around those apps through SSO connections, direct logins, API connectors, and unmanaged subscriptions, creating a fragmented identity surface.
  3. Impact appears when teams lack a complete inventory, so unused licenses, orphaned access, and policy gaps persist across sanctioned and shadow SaaS.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Visibility without lifecycle governance is only partial control: SaaS discovery methods can reveal hidden applications, but they do not automatically create ownership, review cadence, or offboarding authority. The governance gap is not whether teams can find the app. It is whether discovery output is wired into the identity processes that decide who owns it, who may use it, and when access ends. Practitioners should treat discovery as a trigger for governance, not as governance itself.

SaaS discovery exposes the mismatch between usage and approval: Shadow IT becomes a control problem when applications are adopted before they are registered in IAM or IGA. That means the organisation is already operating with an identity surface wider than its approved inventory. The implication is that access policy, recertification, and licensing decisions must account for usage signals that arrive before formal intake.

Discovery is strongest when it is treated as an evidence layer for IGA: CASBs, API connectors, browser plugins, agents, finance records, and directories each contribute a partial view, but no single method closes the loop. The better model is federated evidence across control planes. That lets governance teams decide whether a discovered app belongs in sanctioned access paths, exception handling, or rapid retirement.

Shadow SaaS inventory debt: Unseen applications create accumulated governance debt because every day of missing inventory is another day of unmanaged access, unreviewed usage, and unclear accountability. This is not just an operational nuisance. It is a structural weakness in how identity programmes keep pace with decentralised software adoption. Security and IAM teams should treat inventory debt as a lifecycle failure mode, not a discovery inconvenience.

The market is moving from discovery to decisioning: The real value in SaaS discovery is shifting away from simple detection and toward actionable governance workflows. Organisations already know they have too many apps. What they need is the ability to convert discovery signals into access control, renewal decisions, and offboarding actions without waiting for a manual audit cycle. That is where identity programmes either mature or stall.

From our research library:

What this signals

Shadow SaaS inventory debt: The longer a SaaS app stays outside central visibility, the more governance debt accrues across ownership, access review, and offboarding. Discovery has to be operationally linked to IGA or it simply produces another list of unknowns.

Discovery should now be treated as an identity control input, not a reporting exercise. The useful output is not a dashboard of apps. It is a governed decision path that tells IAM, finance, and application owners what to approve, retire, or investigate next.


For practitioners

  • Build a federated SaaS inventory Combine CASB, SSO, API, browser, endpoint, finance, and directory signals so discovery coverage reflects how software is actually used across the business.
  • Map every discovered app to an owner Assign business and technical ownership as soon as an app appears, then require each owner to confirm access model, renewal path, and offboarding responsibility.
  • Tie discovery to access review workflows Feed discovered applications into recertification and exception handling so shadow IT does not sit outside review simply because it was found late.
  • Use finance data to find orphaned SaaS spend Compare invoices, reimbursements, and direct debits against the approved application list to uncover subscriptions that escaped IAM intake and renewal governance.
  • Close the gap between discovery and offboarding Retire unused or unsanctioned apps through a documented offboarding path that removes access, subscription renewal, and residual account state.

Key takeaways

  • SaaS discovery reveals the hidden application layer, but hidden apps become an identity problem when they are not tied to ownership and lifecycle controls.
  • The evidence problem is structural: different discovery methods see different slices of the estate, so no single source gives a complete SaaS picture.
  • The practical response is to connect discovery output to access review, offboarding, and renewal decisions so visibility becomes enforceable governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIShadow SaaS and external app sprawl create unmanaged third-party identity exposure.
NHI-01 — Improper OffboardingDiscovered apps often outlive their approval and offboarding path, leaving residual access behind.
Recommendation — Map discovered SaaS apps to third-party identity owners and retire any unmanaged access paths. Tie SaaS discovery to offboarding so unused apps and accounts are removed from the identity estate.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsSaaS discovery only becomes governance when access rights and entitlements are explicitly controlled.
Recommendation — Use PR.AA-05 to align discovered apps with approved entitlements and revoke exceptions quickly.
CIS Controls v8CIS-5 — Account ManagementShadow SaaS creates account sprawl that account management controls are meant to reduce.
Recommendation — Apply account management controls to identify, review, and remove accounts tied to unsanctioned SaaS use.

Key terms

  • SaaS Discovery: SaaS discovery is the process of identifying all sanctioned and unsanctioned software-as-a-service applications in use across the organisation. It matters because cloud assurance increasingly depends on seeing where apps share data, what permissions they hold, and which identities can reach them.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
  • Access Governance: Access governance is the policy and workflow layer that manages how access is requested, approved, certified, and revoked. In SaaS environments it helps standardise control across many applications, reducing inconsistency between teams. It is most effective when it covers both human accounts and non-human identities.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org