TL;DR: SaaS management platforms are increasingly judged not by inventory alone but by whether they can connect discovery, usage, access level, and automated remediation across shadow IT and AI app adoption, according to Zluri. The governance gap is no longer about finding apps; it is about deciding whether access should exist at all and acting on that decision continuously.
At a glance
What this is: This is a SaaS management platform roundup that argues the category is most useful when it connects discovery, usage, access level, and automated governance rather than inventory alone.
Why it matters: For IAM, IGA, and security teams, the article underscores that SaaS governance fails when app discovery is separated from access decisions, license rightsizing, and enforcement.
Context
SaaS management is no longer just a software inventory problem. The core issue is whether an organisation can connect app discovery to actual usage, access permissions, and governance decisions fast enough to keep shadow IT and shadow AI from becoming unmanaged access paths.
The article frames this as a gap between visibility and governance. In practice, that means a platform may find apps, but unless it can also show who is using them, at what level of access, and whether that access should continue, it still leaves the hardest identity governance decisions unresolved.
Key questions
Q: What breaks when SaaS management stops at app inventory?
A: When SaaS management stops at inventory, teams can see applications but not whether access is justified, active, or connected to unmanaged identities. That leaves entitlement drift, shadow IT, and dormant accounts outside the control loop. The result is visibility without governance, which is enough for reporting but not enough for security decisions.
Q: Why does SaaS and AI sprawl create budget and governance risk for organisations?
A: SaaS and AI sprawl creates risk because organisations lose sight of what is in use, who can access it, and how ownership changes over time. That weakens governance, makes spend harder to control, and increases the chance that dormant or unnecessary access remains active. The result is budget drift, poor accountability, and more difficult lifecycle management.
Q: What signals show that SaaS governance is not working?
A: Look for delayed offboarding, repeated manual exports, inconsistent access review responses, and inactive accounts that still carry paid licenses. Those signals indicate that entitlement ownership and usage data are not reconciled often enough to support reliable governance.
Q: What is the difference between shadow IT and shadow AI?
A: Shadow IT is the use of unapproved software, while shadow AI is the use of unapproved or unmanaged generative AI services and embedded copilots. Shadow AI is harder to govern because it often hides inside sanctioned SaaS tools and can move data into external model systems without obvious signs.
Technical breakdown
Discovery without governance creates an incomplete control surface
A SaaS management platform can discover applications through API integrations, SSO data, browser activity, and financial system connections, but discovery alone does not establish control. The technical issue is that inventory data, usage telemetry, and entitlement context are separate signals, and only their combination tells you whether a SaaS app is sanctioned, shadow IT, or simply underused. That distinction matters because the governance decision is not just whether the app exists, but whether the identity connected to it still needs access. Without that join, teams get visibility without enforceable policy.
Practical implication: Treat discovery as an intake layer, not a control outcome, and require entitlement context before making access decisions.
Shadow AI governance depends on continuous enforcement
The article treats AI app adoption as part of the same SaaS governance problem, which is accurate from an identity perspective. If employees can independently adopt GenAI tools, the governance challenge becomes real-time monitoring of usage, policy enforcement, and rapid restriction when an app is not approved. This is not the same as retrospective reporting. The control point shifts to continuous observation of app use and immediate action when a restricted service is accessed, which is closer to identity enforcement than catalogue management.
Practical implication: Extend SaaS governance policies to AI app adoption and enforce them at the point of use, not only during review cycles.
License optimisation becomes an identity signal, not just a finance task
The article shows how license reclamation, downgrades, and inactivity detection can be automated from usage thresholds. That changes the technical role of license data: it becomes a signal for lifecycle governance, not only spend optimisation. When an account has not been used in 60 days, or a license is clearly overprovisioned, the relevant question is whether access should be removed or reduced across the app stack. In other words, usage analytics can feed deprovisioning and access review workflows when the platform is integrated with identity governance.
Practical implication: Use license and inactivity data as triggers for access review and deprovisioning, not only for procurement reporting.
Threat narrative
Attacker objective: The practical objective is to keep unauthorized or overprivileged SaaS access alive long enough to bypass governance and expose data or operational controls.
- Entry occurs when employees adopt sanctioned or unsanctioned SaaS and AI applications outside the approved inventory, creating a governance blind spot from the start.
- Credential or access exposure follows when those applications are used at permission levels that the organisation cannot continuously validate or review.
- Escalation happens when unmanaged apps and stale licenses persist without automated enforcement, allowing risky access to continue after the business need has faded.
- Impact is governance drift, where shadow IT, shadow AI, and over-retained licenses remain connected to live identities and unmanaged data flows.
Breaches seen in the wild
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Visibility without entitlement context is not governance. A platform that can list applications but cannot bind each app to active users, permission levels, and sanction status only solves the first half of the problem. The governance failure is the assumption that inventory equals control. In SaaS environments, the decisive question is whether access should exist at all, and that cannot be answered from discovery alone.
Shadow AI collapses the old SaaS boundary model. SaaS governance used to assume a relatively stable app portfolio with periodic review cycles. That assumption breaks when employees can adopt AI tools independently and begin moving data through them before IT sees them. The implication is that the control plane has to move closer to live usage and policy enforcement, not just catalogue maintenance.
Automated rightsizing only matters when it is tied to identity lifecycle. Reclaiming licenses and downgrading unused access are useful only if the action reaches the identity that holds the entitlement. Otherwise organisations merely optimise cost while leaving dormant access paths in place. The field should treat usage analytics, access reviews, and deprovisioning as one governance loop, not three separate projects.
SaaS management is becoming an identity governance layer, not a standalone category. The article reflects a market shift toward platforms that combine discovery, access context, and automated remediation. That direction validates the convergence of SMP, IGA, and security enforcement around the same data set. Practitioners should expect the category to be judged on whether it can change access state, not just report on software sprawl.
SaaS governance now includes machine-like usage behaviour in human workflows. When employees self-adopt tools, the risk is not only shadow IT but unreviewed data movement and unmanaged permissions across consumerised app adoption. That broadens the remit of IAM teams: they must govern sanctioned apps, unsanctioned apps, and AI-assisted workflows as one identity surface. The practical conclusion is that app governance and identity governance now need shared telemetry and shared remediation.
From our research library:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
What this signals
Identity governance now sits inside SaaS operations. The meaningful control point is no longer the app list, but the decision engine that can turn discovery and usage into revocation, downgrade, or review. That is why SaaS management is converging with IGA rather than remaining a separate inventory discipline.
Licence data should be treated as lifecycle evidence. When usage drops, the question is not only whether spend can be reduced, but whether the entitlement should still exist. Teams that separate procurement optimisation from access governance will keep paying for dormant rights while leaving unnecessary access in place.
For practitioners
- Map SaaS discovery to entitlement context Require every discovered app to be paired with user activity, access level, and sanction status before it enters governance review.
- Extend governance to shadow AI Treat approved and unapproved GenAI tools as part of the SaaS control surface, with policy enforcement tied to live usage rather than periodic audit.
- Automate license-driven lifecycle actions Use inactivity thresholds and underused license data to trigger access review, downgrade, or deprovisioning across the relevant app stack.
- Unify spend and access decisions Bring procurement, IAM, and SaaS administration into the same workflow so renewal, rightsizing, and revocation are decided from the same usage evidence.
Key takeaways
- SaaS management only becomes governance when discovery is tied to user activity, access level, and enforcement.
- Shadow IT and shadow AI are the same operational problem once employees can adopt tools outside approved workflows.
- License optimisation should feed access review and deprovisioning, not sit in a separate cost-management process.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CSA Cloud Controls Matrix, NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | The article centres on SaaS identity context, entitlement visibility, and governance enforcement. |
| Recommendation — Apply IAM controls to bind SaaS discovery to user entitlement and access decisions. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | SaaS governance here depends on knowing and governing who can access each app. |
| Recommendation — Review SaaS entitlements against PR.AA-05 and remove access that no longer has a business need. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article repeatedly points to inactive accounts, provisioning, and deprovisioning across SaaS apps. |
| Recommendation — Automate account lifecycle actions under CIS-5 for SaaS users and unmanaged application access. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The core governance gap is over-retained access and permission levels that exceed current need. |
| Recommendation — Enforce AC-6 to rightsize SaaS permissions and revoke excess access promptly. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | When SaaS access stays active after demand drops, offboarding and entitlement cleanup are incomplete. |
| Recommendation — Use NHI-01 to track SaaS offboarding workflows until each entitlement is removed or reassigned. | ||
Key terms
- SaaS Lifecycle Governance: SaaS lifecycle governance is the set of controls that manage applications from onboarding through access assignment, renewal, and decommissioning. It matters because the security value of SaaS management depends on whether the organisation can prove ownership, revoke access, and retire unused tools on demand.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Entitlement Context: Entitlement context is the link between a data asset and the identities that can access it, use it, or move it. It matters because classification alone does not tell a security team who can act on the data, which is the information governance needs to set real boundaries.
- License rightsizing: The process of matching purchased SaaS seats or tiers to real consumption. Rightsizing is more than cost cutting because it also exposes overprovisioned access, underused features, and subscriptions that should be downgraded or reclaimed before they roll into another billing cycle.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org