By NHI Mgmt Group Editorial TeamBased on JumpCloud: “Best SaaS Management Platforms Compared (Aug. 2025)” (July 23, 2025)

TL;DR: Enterprise SaaS is expanding toward 85% of software spend, while shadow IT already accounts for 29% of IT security concerns, according to JumpCloud. The practical shift is that SaaS management now functions as identity governance for apps, accounts, and access, not just license cleanup.


At a glance

What this is: This is a SaaS management guide arguing that app discovery, access control, and account governance now belong inside identity governance, not alongside it.

Why it matters: It matters because IAM teams now have to govern SaaS sprawl as a living access problem, spanning shadow IT, unauthorized accounts, and lifecycle controls across the application estate.

By the numbers:

  • Almost 85% of all enterprise software will be SaaS applications, according to JumpCloud.
  • Shadow IT accounts for 29% of IT security concerns, according to JumpCloud.

Context

SaaS management is the practice of discovering, governing, and optimizing software-as-a-service usage across users, apps, accounts, and spend. In this article, JumpCloud frames that discipline as part of identity governance because the operational problem is no longer just license cleanup or app inventory.

As SaaS adoption expands, unmanaged apps, personal logins, and orphaned accounts create identity risk that traditional directory controls do not fully cover. The governance gap is that every new SaaS app becomes another access surface, another account lifecycle, and another place where policy can drift away from reality.


Key questions

Q: What breaks when SaaS spend management is treated separately from identity governance?

A: The organisation can remove licences without removing accounts, or keep accounts active without any clear business need. That split leaves shadow access in place, weakens ownership, and produces a false sense of control because the finance view and the identity view never meet.

Q: Why do shadow IT and SaaS sprawl break access governance?

A: Because governance only works on systems you can see. Shadow IT creates blind spots in entitlement data, which means reviews, deprovisioning, and SoD checks can miss real access paths. The result is entitlement drift, weak audit evidence, and a higher chance that access persists after the business no longer needs it.

Q: What are the signs that SaaS app permission governance is failing?

A: Common warning signs include users approving apps outside policy, security teams lacking visibility into permission changes, and integrations with broad access that no one can explain. If administrators cannot see app security settings or changes are not reviewed promptly, the organisation is operating with blind spots that attackers can exploit through consent phishing or existing integrations.

Q: How can organisations reduce wasted SaaS spend without weakening access control?

A: They should combine usage telemetry, renewal calendars, and access reviews so underused licences can be reclaimed without delaying legitimate work. The best result is not fewer licences at any cost, but cleaner assignment and faster recovery of dormant entitlements. That approach reduces waste while preserving operational continuity.


Technical breakdown

How SaaS discovery becomes identity discovery

SaaS discovery is not just application inventory. When discovery draws from browser extensions, native connectors, desktop agents, SSO logs, and email or expense signals, it is effectively mapping where identities are being used outside the core directory. That matters because shadow IT often appears first as an access pattern, not a procurement event. Once users can create accounts with non-company email addresses, the identity estate expands faster than governance teams can reconcile it.

Practical implication: inventory SaaS through both app and identity signals so unauthorized access paths are visible before they become normalised.

Why account governance matters more than license management

License management tells you what was bought and whether it is being used efficiently. Account governance asks a different question: who has access, under what identity, and whether that access still reflects policy. SaaS environments often accumulate shared accounts, former-employee accounts, and duplicate personal logins, which means the control failure is lifecycle drift rather than wasted spend alone. Without account context, cost optimisation can miss the security issue entirely.

Practical implication: pair usage analytics with account ownership and offboarding checks so dormant subscriptions do not hide active access risk.

Access enforcement in SaaS depends on identity context

Blocking or warning users only works when the platform can match a login to a person, a role, and an approved app. That is why integrations with directories such as Google Workspace or Microsoft Entra ID matter: they let administrators tie SaaS access back to identity records and policy decisions. The technical weakness in many SaaS tools is that they track apps but stop short of enforcing who should be able to use them, especially when OAuth permissions and app-to-app connections are in play.

Practical implication: enforce SaaS access through identity context, not just app visibility, so warnings and blocks reflect actual user entitlement.


NHI Mgmt Group analysis

SaaS management has crossed the line from portfolio hygiene into identity governance. Once discovery, account matching, access enforcement, and offboarding all become part of the same workflow, the old separation between SaaS administration and IAM stops making operational sense. The programme owner now has to treat SaaS applications as identity-bearing systems, not just software subscriptions. That is the governance shift this market has been heading toward.

Shadow IT is now an access-control problem before it is a procurement problem. Users rarely create governance risk by buying software alone. The real exposure begins when they authenticate with personal emails, reuse accounts, or connect unapproved apps through OAuth and SSO paths. That means the first useful control is often identity-based visibility, because spend data arrives too late to stop the access behaviour itself.

Account lifecycle drift is the named failure mode behind SaaS sprawl. Former-employee accounts, shared accounts, and unused but still active logins show that access outlives the business need unless offboarding is tied to SaaS governance. The implication is not simply better cleanup. It is that SaaS governance must inherit lifecycle discipline from IAM if it is to remain trustworthy.

Unified platforms are winning attention because the problem spans identity, device, and app governance at once. When one tool can see accounts, devices, and SaaS usage, practitioners reduce blind spots created by point solutions and disconnected reports. That does not remove the need for policy design. It does, however, change the architecture conversation from isolated SaaS administration to cross-domain control coverage.

Security teams should expect SaaS governance to be evaluated through compliance and access assurance, not just savings. Cost optimization remains part of the value story, but the stronger operational question is whether the organisation can prove who has access, who approved it, and whether offboarding actually removed it. That makes SaaS management a governance control surface, not a facilities function.

From our research library:

What this signals

Account lifecycle is now the core SaaS control problem: the risky state is not merely unused software, but access that survives the business need, especially when former employees, personal logins, or shared accounts remain attached to active SaaS services. IAM teams should expect SaaS governance to be measured by revocation quality, not just by application counts.

SaaS discovery only becomes actionable when it is tied to identity context: without matching users, accounts, and approved applications, shadow IT remains a list rather than a control surface. The practical shift is that security teams need an integrated view of discovery, entitlement, and enforcement if they want to govern SaaS sprawl at scale.


For practitioners

  • Map SaaS discovery to identity signals Use browser extensions, native connectors, and directory integrations together so unknown apps are tied back to actual users and accounts.
  • Review shadow IT as an access-risk queue Treat personally registered SaaS accounts, OAuth-connected apps, and unapproved logins as governance exceptions that require owner review.
  • Tie offboarding to SaaS account removal Ensure leaver workflows revoke SaaS access, remove shared access paths, and check for former-employee accounts that remain active.
  • Separate cost optimisation from access governance Track license usage, but do not let underused subscriptions obscure accounts that still have valid access or app-to-app permissions.
  • Enforce app approval before access becomes normal Use warning and block controls for unapproved or risky SaaS apps so access decisions happen before accounts proliferate across the estate.

Key takeaways

  • SaaS management is no longer just software inventory because the real risk sits in who can access which apps and whether that access is still legitimate.
  • Shadow IT, personal logins, shared accounts, and former-employee access show that SaaS sprawl is fundamentally an identity governance problem.
  • The strongest control pattern is unified discovery plus access enforcement, because visibility without revocation and approval workflows does not reduce risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingOffboarding failures surface in dormant and former-employee SaaS accounts.
NHI-10 — Human Use of NHIPersonal logins and user-driven SaaS access blur approved identity boundaries.
Recommendation — Tie SaaS offboarding to NHI-01 and revoke lingering access paths when users leave. Apply NHI-10 controls to stop personal accounts from becoming unmanaged access paths.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementSaaS account and credential lifecycle depends on controlled authenticators.
Recommendation — Use IA-5 to govern SaaS credential issuance, revocation, and reuse.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on SaaS entitlements, approval, and access enforcement.
Recommendation — Apply PR.AA-05 to align SaaS entitlements with approved business access.
CIS Controls v8CIS-5 — Account ManagementThe control problem is active, orphaned, and shared SaaS accounts.
Recommendation — Use CIS-5 to inventory, review, and remove unnecessary SaaS accounts.

Key terms

  • SaaS Lifecycle Governance: SaaS lifecycle governance is the set of controls that manage applications from onboarding through access assignment, renewal, and decommissioning. It matters because the security value of SaaS management depends on whether the organisation can prove ownership, revoke access, and retire unused tools on demand.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Account lifecycle: Account lifecycle is the full sequence of join, use, recovery, change, and removal for an identity. For passkeys, it includes enrollment, device replacement, credential binding, support escalation, and deprovisioning, because security breaks when any lifecycle step falls back to weaker controls.
  • Access Monitoring: Access Monitoring is the practice of querying event data to trace suspicious identity behavior across requests, logins, sessions, and administrative actions. It helps incident responders find lateral movement, privilege abuse, and hidden persistence. The value comes from turning telemetry into a timeline of who did what, when, and from where.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org