By NHI Mgmt Group Editorial TeamBased on 1Password: “Why SaaS license waste is a cost and security problem” (January 15, 2026)

TL;DR: Unused SaaS licenses are framed as both budget waste and access risk in 1Password’s analysis, which argues that decentralised app buying, black-box usage data, and manual renewal checks leave IT unable to validate who still needs access. The real issue is that license governance and deprovisioning are now the same control problem, not separate finance and security tasks.


At a glance

What this is: This is an analysis of why unused SaaS licenses persist as both cost waste and access risk when IT cannot reliably see usage, ownership, and renewal exposure.

Why it matters: IAM and security teams need this because license sprawl, orphaned accounts, and weak offboarding all turn SaaS procurement into an access governance problem.


Context

Unused SaaS licensing becomes a governance problem when teams cannot prove who is actively using what, who owns the renewal decision, and which accounts should already have been removed. In practice, this is an IAM and offboarding issue as much as a finance issue, because access can outlive business need even when the contract has not changed.

The article describes a common operating model failure: decentralised app buying, usage data that sits behind vendor consoles, and manual reconciliation across contracts and finance tools. That combination leaves security, IT, and procurement working from partial records instead of one system of record for SaaS entitlements.


Key questions

Q: What breaks when SaaS renewals are handled without access recertification?

A: Renewal decisions become guesses instead of governance checks. Teams keep paying for seats that nobody uses, while dormant accounts remain available because no one confirmed that the entitlement should be removed at the same time as the contract was renewed.

Q: Why do unused SaaS licences create identity risk as well as cost waste?

A: Unused licences often indicate that apps are still licensed after the people or teams that justified them have changed. That usually means access review, account removal, and contract ownership are not aligned. The result is unnecessary spend plus a larger surface for stale access and administrative confusion.

Q: How can teams tell whether SaaS governance is actually working?

A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow. If the platform can only report on SaaS usage but cannot drive deprovisioning or entitlement review, governance is still fragmented.

Q: What is the difference between license reclamation and deprovisioning?

A: Deprovisioning removes or reduces a user’s access to an application, while license reclamation removes the paid seat from active use or makes it available for reassignment. Both need to be linked. If they are handled separately, organisations can still pay for access that no longer has a business need.


Technical breakdown

Why SaaS usage visibility breaks down

SaaS usage tracking fails when discovery, entitlement data, and login activity sit in separate systems. A finance ledger can show what was purchased, an identity provider can show who authenticated, and the application itself can show last-use dates, but none of those views alone tells you whether an account is still justified. The control gap is not the absence of a spreadsheet. It is the absence of a reconciled, real-time record that ties access to actual use across the whole SaaS estate.

Practical implication: build one reconciled inventory that links app discovery, login evidence, and contract entitlements.

Why renewal and true-up processes expose access blind spots

Renewals are where weak license governance becomes visible because teams suddenly have to prove utilisation, not just estimate it. When usage is a black box, organisations tend to renew on stale assumptions or overbuy to avoid disruption. That keeps dormant access alive longer than necessary and makes true-ups a symptom of poor entitlement governance rather than a procurement nuisance. The issue is not only wasted spend; it is unchallenged persistence of access that should have been reviewed earlier.

Practical implication: treat renewals as entitlement recertification points, not as finance-only transactions.

How offboarding and license reclamation become one control

When employees leave or change roles, the same review that should reclaim a license should also confirm that the associated account no longer needs access. This is standard lifecycle governance applied to SaaS: remove or downgrade what is no longer needed, and confirm the identity record, not just the invoice, reflects that change. If licence reclamation happens without access removal, dormant accounts remain available to attackers, contractors, or the next internal user who inherits a stale entitlement.

Practical implication: bind license reclamation to joiner-mover-leaver controls so entitlement removal and access removal happen together.


Threat narrative

Attacker objective: The objective is to exploit dormant SaaS access paths that should have been removed, allowing account misuse or opportunistic compromise.

  1. Entry occurs through inactive or orphaned SaaS accounts that remain provisioned after employees leave or stop using the application.
  2. Credential or account persistence is sustained because renewal and offboarding processes fail to remove access when usage drops to zero.
  3. Impact comes from retaining unnecessary account paths that enlarge the attack surface and keep budget tied to access that no longer has a business owner.
  • Okta support system breach 2023: A support service account credential saved in a personal Google profile let attackers take HAR files and hijack five Okta customers' sessions.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

License waste is really entitlement drift: Once an organisation cannot prove whether a user still needs an application, the renewal problem and the access problem collapse into the same governance failure. The article is describing a state where the financial record and the identity record have diverged. Practitioners should treat that divergence as a lifecycle control issue, not an optimisation exercise.

SaaS discovery is now an identity control, not an inventory exercise: Decentralised app buying creates a shadow entitlement layer that sits outside normal IAM visibility. That means procurement, IT, and security are all making decisions from incomplete context. The practical conclusion is that SaaS visibility must be wired into identity governance, or the organisation will keep certifying what it cannot actually see.

Unreclaimed licenses create identity blast radius: Every dormant account is both a sunk cost and a residual access path. The longer an account survives past its business need, the more likely it is to be reused, forgotten, or overlooked during incident response. Teams should measure license reclamation and access removal as one lifecycle outcome, not two separate metrics.

Manual renewal checks do not scale to modern SaaS sprawl: Black-box usage data forces teams into surveys, spreadsheet reconciliation, and point-in-time approvals. That operating model always lags the actual state of access, so stale licenses keep renewing by default. Practitioners need governance that can connect usage, ownership, and entitlement status before the renewal decision is made.

License governance and offboarding should share the same control owner: The article shows that who pays for a license and who can still use it are no longer separable questions. If those responsibilities sit with different teams, dormant access will survive handoffs between finance and IT. A single lifecycle owner for SaaS entitlement change is now the cleanest governance model.

From our research library:

What this signals

Licenses and access now need a shared lifecycle: The article points to a broader governance shift where SaaS spend management and identity control can no longer be run as separate disciplines. If a team only knows what it bought, or only knows who logged in, it will continue to miss dormant access that renewal cycles quietly preserve.

Unmanaged SaaS is a renewal-time identity gap: Black-box usage data pushes organisations toward manual reconciliation, but manual processes always trail the state of access. The better signal is whether entitlement removal is wired into joiner-mover-leaver governance, because that is what prevents access from surviving after business need disappears.


For practitioners

  • Map SaaS discovery to identity records Create a single inventory that ties discovered applications to identity provider accounts, last-login evidence, and entitlement ownership so dormant access is visible before renewal decisions.
  • Tie renewal reviews to access recertification Require business owners to confirm both license need and account need at renewal time, so contracts are not renewed on stale utilisation assumptions.
  • Automate license reclamation on leaver events Trigger removal or downgrade workflows when a user leaves, changes role, or stops using a tool, and verify that the account state matches the entitlement state.
  • Reconcile finance tools with access logs Cross-check purchased seats against authentication and usage data so finance, IT, and security see the same utilisation picture before true-ups or renewals.

Key takeaways

  • Unused SaaS licenses expose a governance failure that combines wasted spend with lingering account access.
  • The article says decentralised app buying, opaque usage data, and manual renewals are the main reasons teams lose control.
  • The practical fix is to link discovery, renewal review, and offboarding so access does not outlive entitlement need.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingDormant SaaS accounts remain active when leavers are not removed cleanly.
NHI-05 — Overprivileged NHIUnused seats and stale accounts represent standing access beyond business need.
NHI-07 — Long-Lived SecretsPersistent SaaS accounts and lingering credentials extend the life of unnecessary access.
Recommendation — Tie offboarding workflows to SaaS account removal so unused access is revoked when employment ends. Review SaaS entitlements for excess access and remove permissions that no longer map to active use. Shorten the lifespan of SaaS credentials and retire inactive accounts before renewal cycles.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about verifying and right-sizing SaaS entitlements and access.
Recommendation — Use PR.AA-05 to align SaaS entitlements with current business need and remove stale access.
CIS Controls v8CIS-5 — Account ManagementThe core issue is unmanaged accounts and stale license-linked access.
Recommendation — Apply CIS-5 to maintain accurate SaaS account inventories and remove inactive accounts promptly.

Key terms

  • SaaS Entitlement Drift: SaaS entitlement drift is the gradual mismatch between assigned access, actual usage, and current business need across a software estate. It appears when provisioning, renewal, and offboarding are managed separately, leaving stale permissions in place long after they stop serving a valid purpose.
  • Licence Reclamation: Licence reclamation is the removal or downgrade of software entitlements that are no longer justified by usage. In identity governance terms, it is a lifecycle action based on observed need, and it becomes more effective when usage telemetry is reliable enough to trigger automated review or deprovisioning.
  • License Recertification: A periodic review of whether assigned software access is still needed and being used. It is similar to access recertification in identity governance, but focused on paid application seats, ensuring dormant or duplicate licenses are removed before they become recurring waste.
  • SaaS Discovery: SaaS discovery is the process of identifying all sanctioned and unsanctioned software-as-a-service applications in use across the organisation. It matters because cloud assurance increasingly depends on seeing where apps share data, what permissions they hold, and which identities can reach them.

Deepen your knowledge

NHI governance, identity lifecycle, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org