TL;DR: SaaS management platforms are moving from app inventory into access governance because Zluri says modern teams need to know not just which apps exist, but who uses them, at what permission level, and whether that access should exist at all. That shift makes SaaS discovery an identity problem, not only a cost problem.
At a glance
What this is: This article argues that SaaS management has moved beyond inventory into access governance, because organisations need visibility into who uses each app, how it is used, and whether access is still justified.
Why it matters: IAM, IGA, and security teams need this shift to understand SaaS sprawl as an identity problem, since unmanaged app usage now affects access reviews, deprovisioning, and policy enforcement across both sanctioned and shadow tools.
Context
SaaS app sprawl is a governance problem when the organisation can list applications but cannot explain who is using them, at what access level, or whether those permissions should still exist. That gap turns SaaS discovery into an identity and entitlement problem, not just an inventory exercise.
The article’s central point is that SaaS management platforms become useful to IAM programmes only when they connect discovery, usage, and governance. Once that happens, shadow IT, shadow AI, license waste, and access risk stop being separate conversations and start becoming one control surface.
Key questions
Q: What breaks when SaaS management stops at app inventory?
A: When SaaS management stops at inventory, teams can see applications but not whether access is justified, active, or connected to unmanaged identities. That leaves entitlement drift, shadow IT, and dormant accounts outside the control loop. The result is visibility without governance, which is enough for reporting but not enough for security decisions.
Q: How should security teams govern shadow AI in SaaS environments?
A: Security teams should inventory AI-enabled features, classify the data those features can touch, and enforce approved-use rules at the application and identity layers. The practical goal is not to block every model interaction. It is to ensure that prompts, file uploads, and connected data sources stay within defined risk boundaries.
Q: How should teams decide whether SaaS access still belongs?
A: Teams should base that decision on real usage, permission level, business role, and application risk, not on whether the app was once approved. If usage has stopped or the entitlement no longer matches the role, the access should be removed, downgraded, or recertified through identity governance workflows.
Q: When should SaaS governance trigger deprovisioning instead of review?
A: Deprovisioning should be triggered when the platform has reliable usage evidence that an account is inactive, over-permissioned, or associated with an unmanaged application. Review still has value, but it should not delay action when the governance signal already shows the access no longer fits the identity lifecycle.
Technical breakdown
Why app inventory is not the same as identity governance
SaaS inventory tells you what exists. Identity governance tells you who can use it, whether that access is justified, and whether the organisation can act on that insight. In practice, many SMPs stop at discovery and spend optimisation, which leaves entitlements, offboarding, and policy enforcement outside the control loop. The article is pointing at the gap between knowing an app is present and knowing whether the identities inside it are still valid. That gap matters because unmanaged access is often the real exposure, not the app itself.
Practical implication: Treat SaaS discovery as an input to IGA workflows, not as a finished control.
How shadow AI changes the SaaS governance surface
Shadow AI extends the SaaS problem because employees can adopt GenAI tools outside approved procurement and governance channels. The article frames this as a visibility and policy issue: organisations need to know which users are touching approved or restricted AI apps, what is being shared, and when access should be blocked or reviewed. That is not a traditional software inventory task. It is a policy-enforcement problem that sits at the intersection of SaaS governance, data handling, and access control.
Practical implication: Fold AI app usage into the same governance process used for unapproved SaaS and high-risk entitlements.
Why automated remediation matters once usage data is trustworthy
The value of SaaS intelligence increases when the platform can act on what it learns. The article highlights automated reclamation, downgrading, deprovisioning, and policy triggers based on real usage rather than static reports. That matters because stale access and unused licenses are both symptoms of the same underlying governance failure: controls that observe but do not enforce. When access data is reliable enough, governance shifts from review-only activity to continuous remediation.
Practical implication: Prioritise platforms and processes that can close the loop from discovery to deprovisioning.
NHI Mgmt Group analysis
SaaS app sprawl is now an identity governance problem, not a tooling problem: Once organisations cannot map users to applications and entitlements, the real issue is governance drift. Inventory alone cannot answer whether access is still justified, which means the control gap sits inside IAM and IGA, not just procurement. Practitioners should evaluate SaaS management through the lens of entitlement control, not software catalogue depth.
Shadow AI turns SaaS management into policy enforcement: SaaS platforms that only record application presence miss the operational risk created when employees adopt GenAI tools outside approval workflows. The governance question is no longer whether the app exists, but whether the organisation can constrain who may use it, what data may enter it, and when that usage should trigger action. That widens the scope from spend management to access governance and data control.
Continuous remediation is the dividing line between visibility and control: A platform that detects unused access but leaves action to humans still produces a backlog, not governance. Automated license reclamation, deprovisioning, and policy-triggered review change SaaS oversight from periodic cleanup to continuous enforcement. The implication for practitioners is clear: if the platform cannot act on identity and usage data, it is reporting on governance rather than delivering it.
Ephemeral SaaS usage requires a lifecycle view across sanctioned and unsanctioned apps: SaaS governance works only when joiner, mover, and leaver processes extend beyond core enterprise apps into the broader SaaS estate. The same identity can move between approved and shadow tools without any formal lifecycle event, which means access reviews must be tied to actual usage signals. Teams should treat SaaS lifecycle control as a cross-application entitlement discipline, not a list-management exercise.
From our research library:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
What this signals
Discovery is only the first control layer: SaaS programmes that stop at cataloguing applications still leave entitlement drift and shadow adoption unresolved. The practical shift is to tie app visibility to access governance so that reviews, deprovisioning, and policy enforcement happen from the same evidence base.
SaaS sprawl now sits on the boundary between IAM, IGA, and data governance. When employees can adopt approved and unapproved tools quickly, practitioners need controls that follow usage patterns rather than relying on annual audits or self-reported inventories.
For practitioners
- Map SaaS discovery to identity records Connect app inventory, SSO, browser activity, and finance data to the user and entitlement records that explain who actually has access.
- Extend access reviews into SaaS sprawl Trigger recertification when unmanaged apps, inactive accounts, or unusual permission levels appear in the SaaS estate, not only on a calendar schedule.
- Define policy for shadow AI adoption Decide which AI apps are approved, which data types are prohibited, and what events should block or flag usage for review.
- Automate stale-access remediation Use usage thresholds to reclaim, downgrade, or deprovision licenses and accounts when activity drops below the governance threshold.
Key takeaways
- SaaS sprawl becomes an identity problem when organisations can no longer map users, permissions, and business justification to the apps they run.
- The article’s core message is that discovery, usage, and enforcement need to sit together if SaaS governance is going to work at enterprise scale.
- Practitioners should treat unmanaged SaaS and shadow AI as entitlement issues, then connect those signals to review, deprovisioning, and policy enforcement.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP API Security Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centres on entitlement visibility and governance inside SaaS apps. |
| Recommendation — Apply PR.AA-05 to align SaaS access rights with verified business need and remove stale entitlements. | ||
| CIS Controls v8 | CIS-5 — Account Management | SaaS sprawl creates account lifecycle and unused-access problems across apps. |
| Recommendation — Use CIS-5 to inventory accounts across SaaS tools and retire unused access paths quickly. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Inactive SaaS accounts and shadow app usage expose offboarding gaps for non-human and user-linked access. |
| NHI-05 — Overprivileged NHI | The article highlights permission level as a central governance question for SaaS apps. | |
| Recommendation — Map stale SaaS accounts to NHI-01 and revoke access when usage or ownership ends. Review SaaS entitlements for overprivileged access and reduce permissions to the minimum necessary. | ||
| OWASP API Security Top 10 | API9 — Improper Inventory Management | The article emphasises discovery across many connected SaaS apps and tools. |
| Recommendation — Maintain an accurate inventory of SaaS-connected applications and revoke access paths you cannot track. | ||
Key terms
- SaaS Management Platform: A SaaS management platform is a visibility and optimisation layer for cloud software use. It helps teams discover applications, track utilisation, and understand spend patterns, but it does not by itself enforce access policy, revoke permissions, or manage identity lifecycle state.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Entitlement Governance: Entitlement governance is the discipline of deciding who or what should have access, for how long, and under what business justification. It spans human users, non-human identities, and automated workflows, making it a core control layer for SaaS, cloud infrastructure, and lifecycle management.
- Access Recertification: Access recertification is the periodic review of user or account permissions to confirm that access is still justified. It is useful, but it is not enough on its own because it reacts after entitlements already exist, which is why lifecycle governance must reduce the volume of exceptions before review time.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org