TL;DR: SaaS management tools are being positioned as a way to discover shadow IT, track app usage, and automate onboarding and offboarding across SaaS estates, according to Zluri. The real governance issue is that app visibility and access control still break down when identities, contracts, and approvals are spread across too many systems.
At a glance
What this is: This is a SaaS management comparison piece that frames shadow IT as an identity governance problem, with discovery and workflow automation only partially closing the gap.
Why it matters: It matters because IAM, IGA, and SaaS administration teams need a single governance view across app usage, approvals, renewals, and access, otherwise shadow IT keeps reintroducing unmanaged identity and contract risk.
Context
SaaS management is the practice of discovering, governing, and optimising cloud applications that are bought and used outside a single control plane. In this article, the governance gap is not lack of inventory alone, but the split between usage data, purchase approvals, and access administration across many systems.
For identity teams, that split matters because onboarding, offboarding, app entitlement review, and renewal decisions all depend on the same underlying facts about who is using what and under which approved contract. When those facts live in different tools, shadow IT becomes an identity governance problem as much as a cost problem.
Key questions
Q: How should security teams govern shadow IT in SaaS environments?
A: Security teams should govern shadow IT by treating it as unmanaged access, not just unsanctioned software. Start with continuous discovery, then map each app to owners, data types, delegated scopes, and revocation paths. The control goal is to reduce hidden access paths before they become business-critical dependencies.
Q: Why does SaaS visibility matter for identity governance?
A: Because access control depends on knowing which applications, identities, and delegated permissions actually exist. If teams cannot see the app estate, they cannot certify access, revoke stale consents, or remove orphaned accounts. Visibility is the prerequisite for lifecycle governance across human, machine, and app-linked identities.
Q: What breaks when renewal, offboarding, and access review are separate?
A: When renewal, offboarding, and access review are separate, organisations keep paying for tools they no longer need and often leave residual access in place. The breakdown is organisational, but the security impact is practical: unmanaged entitlements survive past the point of business need.
Q: How should security teams govern Shadow IT without slowing users down?
A: Start with visibility, not prohibition. Classify shadow applications by business value and data exposure, then apply graded responses such as approve, warn, or block. Pair that with clear ownership so business teams can explain why a tool exists and IAM can prove who can access it. The goal is controlled adoption, not blanket prevention.
Technical breakdown
Why SaaS discovery does not equal governance
SaaS discovery finds applications through SSO logs, finance systems, APIs, browser signals, or desktop agents, but discovery is only the first layer of control. Governance begins when an organisation can connect each application to ownership, approval status, contract state, and access lifecycle. Without that linkage, teams may know an app exists while still failing to answer who approved it, who can still use it, and whether it should remain in the stack. In practice, the technical weakness is fragmented source systems, not a missing dashboard.
Practical implication: map discovery feeds to ownership and lifecycle records before treating app visibility as governance coverage.
How shadow IT turns into access sprawl
Shadow IT creates access sprawl when users adopt unsanctioned apps, connect them through SSO or OAuth, and keep those connections active outside formal review paths. The risk is not only the app itself but the identity relationships around it: tokens, approvals, licences, and delegated access can persist long after the original business need changes. SaaS management tools try to collapse that sprawl into one control view, but the underlying technical issue is that usage telemetry and permission authority often sit in different systems.
Practical implication: inventory third-party app connections alongside user access so offboarding can remove both login paths and residual approvals.
Why renewals and offboarding belong in the same control plane
A SaaS programme fails when renewals, offboarding, and access review are handled as separate processes. Renewal data tells you whether the organisation still pays for the app, offboarding tells you whether users should still have access, and access review tells you whether the entitlement remains justified. If those workflows are disconnected, organisations can retain inactive licences, leave orphaned approvals in place, and miss changes in business ownership. The technical pattern here is lifecycle fragmentation across procurement, IAM, and SaaS administration.
Practical implication: align renewal, offboarding, and certification workflows so the same record drives access removal and contract decisions.
NHI Mgmt Group analysis
Shadow IT becomes an identity governance failure when application discovery is not tied to lifecycle authority. Visibility alone does not answer who approved the app, who owns the contract, or who can still access it. That means the same entitlement can be visible, unmanaged, and still active across separate systems. Practitioners should treat SaaS inventory as a governance input, not a finished control state.
The real control gap is fragmentation across procurement, IAM, and SaaS administration. When renewal records, approval workflows, and offboarding actions live in different tools, no single team can reliably prove whether an application remains sanctioned. This creates a repeatable audit and access-control problem, not just a cost-management issue. The practical conclusion is that governance must follow the application lifecycle, not just the login event.
Shadow IT is now a lifecycle problem, not merely a discovery problem. Organisations can identify thousands of applications and still fail to govern them if ownership, usage, and renewal status are not bound together. That makes lifecycle management the decisive control plane for SaaS risk. Teams that separate discovery from decision-making will keep rediscovering the same unmanaged surface.
SaaS governance needs a single source of truth for approval, access, and renewal state. When those records are split, every new app can become a long-tail identity exception. The stronger operating model is to make each SaaS application legible to both security and procurement at the same time. Practitioners should design for one governed record, not three disconnected ones.
What this signals
Governance has to follow the SaaS lifecycle, not just the login event. Discovery tools are useful, but they do not close the gap until approval, access, and renewal data are managed as one operating model. For most organisations, the next maturity step is less about finding more apps and more about removing governance fragmentation.
SaaS sprawl is forcing identity teams, procurement teams, and application owners into the same control conversation. The organisations that get ahead will be the ones that treat offboarding and contract renewal as identity decisions, not back-office admin.
For practitioners
- Build a unified SaaS application inventory Combine SSO, finance, API, and browser-based discovery so each app record includes owner, approval status, and business purpose.
- Bind offboarding to SaaS entitlements Remove app access when users leave or change roles, and verify that OAuth connections, group membership, and direct accounts are all revoked.
- Align renewals with access review Require licence renewal decisions to reflect current usage, current ownership, and current entitlement justification before contracts roll over.
- Track sanctioned and unsanctioned apps separately Keep a governance record that distinguishes approved SaaS from discovered but unapproved tools so shadow IT can be remediated by policy, not just flagged.
Key takeaways
- Shadow IT in SaaS is not just an inventory problem. It becomes an identity governance problem when approval, ownership, and access records are split across different systems.
- Discovery can show what is in use, but it does not prove what is sanctioned or who is accountable for it. That gap leaves applications discoverable but still unmanaged.
- The practical fix is to connect discovery, offboarding, and renewal into one governed lifecycle so that access removal and contract decisions happen from the same record.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CSA Cloud Controls Matrix, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | SaaS governance here centers on access, approvals, and entitlement control across cloud apps. |
| Recommendation — Map SaaS discovery and entitlement workflows to IAM controls so sanctioned access stays current. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about controlling SaaS app access and authorisation state. |
| Recommendation — Apply PR.AA-05 to keep SaaS entitlements tied to current approval and ownership. | ||
| CIS Controls v8 | CIS-5 — Account Management | Shadow IT and offboarding issues show up as unmanaged accounts and stale access paths. |
| Recommendation — Use CIS-5 to remove dormant SaaS accounts and reconcile access during offboarding. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Overbroad SaaS access and lingering entitlements are least-privilege failures. |
| Recommendation — Enforce AC-6 so SaaS users keep only the access needed for their current role. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | SaaS accounts and app connections outliving business need is an offboarding failure pattern. |
| Recommendation — Treat abandoned SaaS accounts and app connections as NHI offboarding defects and revoke them promptly. | ||
Key terms
- Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
- SaaS Lifecycle Governance: SaaS lifecycle governance is the set of controls that manage applications from onboarding through access assignment, renewal, and decommissioning. It matters because the security value of SaaS management depends on whether the organisation can prove ownership, revoke access, and retire unused tools on demand.
- Entitlement review: A governance process that checks whether users, service accounts or systems still need their access. For modern identity programmes, the limitation is timing: if reviews happen too late or too rarely, access may already have been misused before the review occurs.
- Application Lifecycle Planning: Application lifecycle planning is the process of considering security, access, and operational requirements before a new tool is implemented. It helps teams avoid late-stage surprises by defining expectations early, including ownership, permissions, integration points, and control fit. Good planning reduces rework and improves adoption.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org