By NHI Mgmt Group Editorial TeamBased on Zluri: “How to Choose a SaaS Management Platform? [Updated - 2026]” (March 12, 2026)

TL;DR: SaaS management platforms are evaluated here through four pillars: discovery, cost optimisation, risk management, and automation, with Zluri stating that nine discovery methods, over 300 direct integrations, and 30/15/1 day renewal alerts shape effective control. The core issue is that SaaS management is really identity governance for apps, users, and access lifecycles, not just spend reporting.


At a glance

What this is: This is a SaaS management platform buying guide arguing that discovery is the foundation and that platform choice should be judged through identity, access, risk, and lifecycle control.

Why it matters: It matters because IAM, IGA, and SaaS operations teams need a buying model that measures coverage of apps and access lifecycles, not just cost optimisation features.


Context

SaaS management platform selection often fails when teams treat it as procurement or spend optimisation first. The underlying issue is identity governance: if you cannot find an app, you cannot govern its users, access paths, renewal exposure, or offboarding state.

The article argues that the discovery engine is the foundation of an SMP, because every later control depends on whether an app has been surfaced into inventory. That framing matters for SaaS governance, where shadow IT, unused licences, and lingering access all sit inside the same lifecycle problem.


Key questions

Q: How should security teams evaluate a SaaS management platform for access governance?

A: Start with discovery coverage, then test whether the platform can propagate joiner, mover, and leaver changes into live app access. A platform that cannot see the app estate cannot govern it, and one that cannot revoke access reliably leaves privilege behind after offboarding. Focus on evidence, not feature lists.

Q: Why do unmanaged SaaS apps create access risk even when SSO is in place?

A: Because SSO only governs the apps it covers. Employees can still use browser tools, local accounts, and OAuth-linked services outside federation, which leaves access invisible to standard identity reporting. The risk is not the absence of authentication, but the absence of complete lifecycle control over what users can actually reach.

Q: What breaks when SaaS discovery is incomplete?

A: Incomplete discovery leaves shadow apps, duplicate subscriptions, and employee-purchased tools outside the control model. That means invoices cannot be matched cleanly, renewal decisions are based on partial data, and ownership remains ambiguous. In practice, the organisation pays for services it cannot reliably govern or retire.

Q: Why does SaaS renewal management matter to IAM teams?

A: Because renewals often preserve active accounts, licences, and permissions even when the business case has ended. If IAM and procurement do not work from the same data, the organisation can keep paying for access it no longer needs. Renewal control is therefore part of lifecycle governance, not just spend management.


Technical breakdown

Why discovery coverage determines everything else

A SaaS management platform cannot govern what it cannot see. Discovery is the inventory layer that connects app visibility, user mapping, and downstream controls such as license management, risk scoring, and offboarding. The article’s core point is that the app library and discovery methods determine whether the platform can identify apps across web, desktop, and mobile usage, and whether it can see both free and paid applications. In identity terms, this is about establishing a reliable system of record before any governance action can be trusted.

Practical implication: validate discovery breadth first, because incomplete inventory makes every later governance decision partial.

How direct integrations change access intelligence

Direct integrations provide usage data from the application source rather than inference from indirect signals. That matters because governance decisions about dormant access, licence tiering, and renewals depend on evidence that reflects actual use, not assumptions. The article also emphasises that user discovery is as important as app discovery, because a SaaS estate is only governable when accounts and entitlements can be tied back to real users and departments. For IAM teams, this is the operational bridge between app inventory and access oversight.

Practical implication: prefer platforms that expose direct integration data for entitlement and usage review, not just dashboard summaries.

Why renewal alerts and offboarding are identity controls

Renewal management is not just a finance function when licences map directly to access. The article’s 30-day, 15-day, and 1-day alerts show that contract timing becomes a governance control when it helps teams decide whether access should continue, shrink, or end. Offboarding is the same logic in reverse: revoking access at departure is an identity lifecycle task, not a procurement afterthought. In practice, SaaS management is where access governance and vendor governance meet.

Practical implication: align contract renewal workflows with access reviews and offboarding so entitlement decisions happen before auto-renewal locks them in.


Threat narrative

Attacker objective: The objective is to preserve access to SaaS data and business workflows after governance should have removed that access.

  1. Entry occurs when shadow SaaS applications or unmanaged integrations enter the environment outside the central inventory.
  2. Credentialed access then persists through users, vendors, and dormant accounts that remain connected after role change or offboarding.
  3. Escalation happens when overexposed apps or excessive permissions allow broader data exposure than the business intended.
  4. Impact is continued access to company data, wasted spend, and governance blind spots that delay containment and termination.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Discovery is the control plane, not a feature list: SaaS management only becomes governance when the organisation can continuously identify apps, users, and access paths. The article is right to place the discovery engine first, because every downstream decision depends on whether the estate is actually visible. Without complete discovery, renewal, risk, and offboarding workflows are operating on partial truth.

SaaS buying is identity lifecycle buying: The real evaluation criteria are whether the platform can support joiner, mover, and leaver decisions across apps, not whether it can produce prettier spend reports. That makes the procurement question broader than IT automation. The platform has to connect app inventory, user assignment, and access termination into a single governance loop.

App discovery and access governance are now inseparable: The article shows that app visibility, user visibility, and deprovisioning all sit in the same operational chain. That is why SaaS management should be assessed as an extension of IAM and IGA, not a separate software category. Practitioners should treat every undiscovered app as an undisclosed identity surface.

Renewal management is an access decision disguised as a finance process: Auto-renewals become a governance failure when contracts continue after the underlying access should have been reviewed or removed. The platform value is not the reminder alone, but the ability to connect contract timing to entitlement state. Teams that separate procurement from identity lifecycle will keep paying for access they no longer need.

Offboarding is where SaaS governance proves itself: The article’s emphasis on revoking users at departure reflects the control that most clearly converts intent into security outcome. If former employees or ex-vendors still hold access, the platform has not solved governance, regardless of its reporting quality. The practical test is whether deprovisioning happens as part of lifecycle closure, not as a manual cleanup activity.

From our research library:

What this signals

Identity governance for SaaS only works when discovery is exhaustive: once apps are hidden, renewal alerts, access reviews, and offboarding workflows all degrade into partial controls. The operational lesson for SaaS programmes is that app inventory quality is now a security metric, not a housekeeping detail.

The next maturity step is to treat SaaS renewal, deprovisioning, and app ownership as one lifecycle, with the same accountability model used for other identity estates. That is how teams stop buying software faster than they can govern access to it.


For practitioners

  • Map SaaS discovery to identity inventory, verify that the platform can find apps through multiple signals, then reconcile each discovered app to named users, departments, and account owners before trusting any governance report.
  • Test offboarding against real leaver cases, run a sample departure through the platform and confirm that app access is revoked, ownership is reassigned, and any residual entitlements are surfaced for review.
  • Tie renewals to access review decisions, use renewal alerts to force a decision on whether the app should be renewed, reduced, or terminated based on actual usage and business ownership.
  • Use direct integrations for entitlement evidence, prefer platforms that pull usage from source applications so licence and access decisions are based on observed behaviour rather than inferred activity.

Key takeaways

  • SaaS management becomes an identity governance problem when discovery, access reviews, and offboarding are treated as one lifecycle rather than separate tasks.
  • The article’s central message is that a platform can only control apps it can discover, and hidden apps create blind spots in renewals, licensing, and revocation.
  • Practitioners should evaluate SaaS tooling by how well it ties app visibility to ownership, entitlement state, and leaver processing.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centres on revoking SaaS access at departure.
NHI-03 — Vulnerable Third-Party NHIThe article warns that ex-vendors may retain access to company data.
NHI-05 — Overprivileged NHIThe article discusses excessive permissions and risky app access.
Recommendation — Automate leaver revocation so SaaS access ends when the account should end. Track and revoke third-party SaaS access as part of vendor lifecycle offboarding. Review SaaS permissions for excess scope and reduce access to the minimum needed.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsSaaS discovery and entitlement review are central to the governance model here.
Recommendation — Use entitlement review to keep SaaS access aligned with account ownership and business need.
CIS Controls v8CIS-5 — Account ManagementThe article focuses on user visibility, renewal, and offboarding controls.
Recommendation — Maintain a complete account inventory and remove SaaS access when it is no longer required.

Key terms

  • SaaS Discovery: SaaS discovery is the process of identifying all sanctioned and unsanctioned software-as-a-service applications in use across the organisation. It matters because cloud assurance increasingly depends on seeing where apps share data, what permissions they hold, and which identities can reach them.
  • Access Lifecycle Management: Access lifecycle management is the discipline of creating, changing, reviewing, and removing access over time. For NHI security, it is essential because machine credentials often lack natural offboarding points, so rotation and revocation must be engineered into the operating model, not handled ad hoc.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Direct integration: A connection that pulls data straight from the SaaS application rather than inferring it from indirect signals. In this context, direct integrations improve usage evidence, entitlement accuracy, and renewal decisions because the platform can see activity closer to the source of truth.

Deepen your knowledge

Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org