By NHI Mgmt Group Editorial TeamBased on Zluri: “How Zluri Saves Time and Money for IT Teams” (June 26, 2025)

TL;DR: Automated SaaS discovery, onboarding and offboarding, renewal controls, and license management reduce shadow IT, wasted spend, and access risk for IT teams, according to Zluri. The governance takeaway is that visibility and lifecycle control matter more than point fixes when SaaS sprawl and delegated access keep expanding, while its own example highlights 225,000 apps in the discovery library and idle software costs of $259 per desktop.


At a glance

What this is: This is a vendor article on SaaS governance automation that argues discovery, onboarding, offboarding, renewals, and licensing controls are the practical levers for reducing shadow IT and access sprawl.

Why it matters: For IAM and IGA teams, it shows why SaaS control problems are lifecycle problems, not just inventory problems, and why offboarding, approval, and renewal workflows need governance around them.

By the numbers:

  • Zluri says the typical cost of idle software is $259 per desktop.

Context

SaaS governance automation is the practice of discovering, approving, provisioning, renewing, and removing app access through controlled workflows. In this article, the central issue is not the software category itself but the way SaaS sprawl creates shadow IT, unmanaged access, and spending that IT teams struggle to see or control.

The governance gap is that manual processes do not scale with modern SaaS adoption. Once employees can request, adopt, and keep applications outside a central system of record, identity governance has to cover discovery, ownership, renewal, and deprovisioning together rather than as separate tasks.

Zluri frames this around SaaS management, but the underlying problem is broader IAM and IGA discipline. If an app is not discovered, approved, and offboarded through governed lifecycle steps, access and cost drift become the default state.


Key questions

Q: What breaks when SaaS discovery finds apps but no one owns them?

A: Discovery without ownership breaks governance because the organisation can identify an application but cannot prove who approved it, who should review it, or who is responsible for offboarding. The result is visibility without control, which leaves shadow IT in place even after it has been detected.

Q: Why do hidden SaaS renewals create security risk as well as cost waste?

A: Hidden renewals keep software and its access paths alive after the original business need may have ended. That means dormant integrations, stale administrative accounts, and forgotten data sharing can persist unnoticed. The risk is not only budget leakage. It is the continued existence of access that no one is actively reviewing.

Q: How can teams tell whether SaaS governance is actually working?

A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow. If the platform can only report on SaaS usage but cannot drive deprovisioning or entitlement review, governance is still fragmented.

Q: Should IAM teams prioritise SaaS lifecycle control over point fixes?

A: Yes, when SaaS sprawl is the dominant problem. Point fixes can reduce friction in a single app, but they do not solve the larger issue of discovery, ownership, renewal, and offboarding across the portfolio. Lifecycle control is the only approach that scales with ongoing application growth.


Technical breakdown

How SaaS discovery engines expose shadow IT

SaaS discovery is the control layer that identifies which cloud applications exist, who is using them, and how they entered the environment. Effective discovery usually combines signals from identity providers, directories, finance systems, endpoint agents, browser telemetry, and direct app integrations. That multi-source approach matters because no single control surface sees the full SaaS estate. In governance terms, discovery is not just inventory. It is the prerequisite for policy enforcement, app ownership, license control, and offboarding decisions. Without discovery, every downstream lifecycle workflow is operating blind.

Practical implication: build SaaS discovery from multiple telemetry sources, not a single tool feed, or shadow IT will remain invisible.

Why onboarding and offboarding workflows shape SaaS governance

Onboarding and offboarding are the lifecycle controls that turn app access into a managed process instead of one-off admin action. Onboarding assigns the right applications based on role or department, while offboarding revokes access, backs up data, and reassigns ownership when people leave. These workflows matter because SaaS access often persists after employment changes unless there is a formal deprovisioning path. In identity terms, this is classic lifecycle governance applied to SaaS entitlements and app ownership, not just human account creation. The same logic applies to delegated access inside business apps.

Practical implication: tie SaaS onboarding and offboarding to role-based playbooks so access removal happens as part of the leaver process, not afterward.

How renewal and license controls limit spend and access drift

Renewal and license management extend governance beyond access provisioning into financial and operational control. Renewal calendars, approval gates, and utilization data help teams decide whether to renew, reduce, or retire an app before auto-renewal locks in another cycle. License optimization also exposes overbuying, idle subscriptions, and hidden contract charges. From an identity perspective, unused licenses are a form of standing entitlement that outlives business need. When renewal review and license ownership are disconnected from actual usage, SaaS sprawl becomes both a cost problem and an access-control problem.

Practical implication: connect renewal decisions to usage and ownership data so stale licenses do not become permanent, unreviewed entitlements.


NHI Mgmt Group analysis

SaaS governance fails when discovery, access, and cost control are treated as separate problems. Shadow IT is not just an inventory issue. It is a lifecycle problem in which applications enter the estate faster than governance processes can approve, assign, renew, and retire them. The practitioner lesson is that the control plane has to follow the app from first sight to final removal.

Visibility is the first control, but not the last one. A SaaS programme can know an application exists and still fail to govern it if ownership, approval, and offboarding are missing. That is why discovery engines, app catalogues, and renewal calendars matter together. The practical conclusion is that inventory without lifecycle enforcement only documents risk.

App ownership is the hinge between SaaS sprawl and accountable governance. Once no one owns an application, renewal decisions, access reviews, and compliance checks lose their decision-maker. In practice, abandoned apps create both budget leakage and control gaps. Teams should treat ownership as a required governance attribute, not an administrative convenience.

License waste is a lifecycle signal, not just a finance problem. Idle or underused subscriptions often indicate that access decisions were never tied to real demand. That is the sort of drift identity teams should care about because it shows where standing entitlement is accumulating outside business need. The practitioner takeaway is to align procurement, IAM, and app ownership around actual use.

Named concept: SaaS lifecycle drift. This is the gap that appears when discovery, onboarding, renewal, and offboarding are managed in different systems or by different teams. The result is that apps and entitlements persist longer than business intent. Practitioners should treat this as a governance design flaw, not a tooling inconvenience.

What this signals

SaaS lifecycle drift: When discovery, approval, renewal, and offboarding are split across different teams or tools, the organisation loses the ability to govern apps as a single identity surface. That means access can remain active after business need has ended, and procurement can keep renewing software that no longer has a real owner.

For IAM and IGA teams, the practical implication is that SaaS governance has to be designed as a lifecycle programme, not a collection of admin tasks. Discovery tells you what exists, but ownership, deprovisioning, and renewal decisions determine whether the estate stays governable.


For practitioners

  • Implement multi-source SaaS discovery Combine identity provider, expense, directory, endpoint, browser, and direct app signals so new SaaS use is visible early. A single feed will miss part of the estate and leave shadow IT ungoverned.
  • Automate SaaS offboarding playbooks Make deprovisioning part of the leaver process so access removal, data backup, and ownership reassignment happen together instead of relying on manual follow-up.
  • Attach ownership to every business app Require named app owners before an application can be renewed, approved, or exception-handled. Unowned software should be treated as a governance exception, not a normal state.
  • Use renewal reviews to retire idle licenses Compare usage, contract cost, and business need before renewal dates so unused subscriptions can be reduced or removed before they roll forward automatically.
  • Link app approval to role-based access patterns Build onboarding workflows around role and department so app access is granted with a repeatable policy rather than ad hoc requests from individual users.

Key takeaways

  • SaaS governance breaks down when discovery, ownership, renewal, and offboarding are handled as separate tasks rather than one lifecycle.
  • The article’s own examples point to large-scale app discovery and material idle-software cost, which shows why shadow IT is also a spend-control issue.
  • Identity teams should treat SaaS lifecycle automation as a governance control plane, because visibility without lifecycle enforcement does not close the risk gap.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHISaaS apps and delegated access create third-party identity governance exposure.
NHI-01 — Improper OffboardingThe article centers on revoking SaaS access when employees leave or apps are retired.
Recommendation — Inventory third-party SaaS identities and enforce ownership, approval, and offboarding controls. Tie deprovisioning to leaver workflows so access is removed when business need ends.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsSaaS discovery and offboarding are permission and entitlement governance problems.
Recommendation — Review SaaS entitlements regularly and remove access that no longer matches business need.
CIS Controls v8CIS-5 — Account ManagementThe article focuses on lifecycle control over app accounts and access removal.
Recommendation — Maintain authoritative account ownership and disable stale SaaS access promptly.
NIST Zero Trust (SP 800-207)Section 3.1 — Verify explicitlySaaS access should be continuously verified rather than assumed from initial approval.
Recommendation — Apply continuous verification to SaaS access decisions instead of trusting static approval.

Key terms

  • SaaS Discovery: SaaS discovery is the process of identifying all sanctioned and unsanctioned software-as-a-service applications in use across the organisation. It matters because cloud assurance increasingly depends on seeing where apps share data, what permissions they hold, and which identities can reach them.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • SaaS offboarding: The process of removing a departing user from software access while also closing the related account, subscription, and data-handling obligations. In mature programmes, it includes license recovery, file transfer, inbox ownership changes, and evidence that the app lifecycle has ended cleanly.
  • License Optimisation: License optimisation is the process of matching software entitlements to actual use so organisations do not pay for access they no longer need. In identity terms, it is a governance function because entitlement reduction often requires review, downgrade, or deprovisioning decisions.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org