By NHI Mgmt Group Editorial TeamBased on Zluri: “Top 20 SaaS Management Platforms [2026]” (May 20, 2026)

TL;DR: SaaS management platforms are shifting from inventory and license tracking to continuous governance, with Zluri highlighting discovery across managed, unmanaged, and shadow AI apps, plus automated deprovisioning and access review triggers. The real change is that SaaS oversight now depends on identity context, not just app counts.


At a glance

What this is: This article argues that SaaS management platforms now need to govern who uses apps, how they are used, and whether access should still exist, not just track software inventory.

Why it matters: For IAM, IGA, and NHI teams, the practical implication is that SaaS management is becoming an access governance layer tied to deprovisioning, shadow app control, and usage-based decisions.


Context

SaaS management is no longer just an inventory problem. Once organisations need to know who is using each application, at what permission level, and whether that access should still exist, the control plane shifts from asset tracking into identity governance.

This is especially relevant where unmanaged SaaS, shadow IT, and shadow AI create access paths outside normal onboarding and offboarding flows. In that environment, the governance gap is not discovery alone, but the ability to act on usage signals before access becomes stale or risky.


Key questions

Q: How should security teams govern SaaS access when identities span many apps?

A: Security teams should govern SaaS access as a relationship problem, not a list problem. The practical approach is to map users, tokens, integrations, roles, and resources into one entitlement model, then use that model for reviews, offboarding, and exception handling. Without that connective tissue, teams will miss inherited privileges and downstream exposure.

Q: Why do unmanaged SaaS apps create identity governance risk?

A: Unmanaged SaaS apps create risk because they sit outside central visibility, which means IT cannot consistently enforce SSO, review entitlements, or offboard access. The longer an app remains invisible, the more likely it is to accumulate stale permissions, duplicate functions, and unmanaged data exposure.

Q: What are the signs that SaaS license governance is failing in a large organisation?

A: Common warning signs include employees waiting on approvals to host basic meetings, licenses sitting unused for long periods, and administrators constantly reassigning the same entitlements. If teams cannot tell which users truly need a paid license, or cannot remove access when it is no longer used, the process is too manual and likely wasting budget while increasing access sprawl.

Q: How should security teams govern Shadow AI in SaaS applications?

A: Security teams should govern Shadow AI by classifying AI-capable SaaS tools, deciding what data each tool may process, and enforcing those decisions centrally. Discovery is necessary but not sufficient. The control layer must cover model training, retention, sharing, and exceptions so users cannot create hidden data-use risk through ordinary application activity.


Technical breakdown

Why SaaS discovery is now an identity problem

Modern SaaS management platforms are aggregating data from API integrations, SSO, browser activity, and financial systems to build a usage-aware app catalog. That matters because the security question is not simply which apps exist, but which identities are active in them, what permission level they hold, and whether those entitlements align with current business need. Discovery without identity context produces an inventory. Discovery with identity context creates governance signals that can drive reviews, access removal, and spend decisions.

Practical implication: treat SaaS discovery as an input to access governance, not as a standalone asset register.

How shadow AI changes SaaS governance

Shadow AI extends the same governance problem into a new class of SaaS usage. Employees can adopt generative AI applications outside approved workflows, which creates visibility gaps over who is using them and what data may be flowing through them. When a platform can monitor AI app adoption and trigger policy enforcement in real time, the issue is no longer retrospective reporting. The control question becomes whether the organisation can spot unsanctioned access quickly enough to stop data exposure or policy drift.

Practical implication: add AI app usage to SaaS governance scope and review it with the same access-policy discipline as other unsanctioned applications.

Why automated deprovisioning changes the SMP control model

Traditional SaaS management often stops at reporting underused licenses. The stronger model is automated action based on usage thresholds, where a platform can reclaim or downgrade access continuously. That turns license optimisation into a governance control because inactive usage can now trigger identity changes across the app stack. The technical difference is important: a dashboard is informational, but an integrated governance workflow can remove entitlement without waiting for a quarterly review cycle.

Practical implication: connect SaaS usage thresholds to deprovisioning logic so stale access is removed as a control outcome, not a manual task.


Threat narrative

Attacker objective: The objective is to exploit unmanaged application access and identity drift to increase exposure, persistence, and policy bypass within the SaaS environment.

  1. Entry occurs through unmanaged SaaS adoption, where employees bring in sanctioned or unsanctioned applications outside central visibility.
  2. Credential and access sprawl then develops as identities accumulate permissions, often without corresponding review of necessity or usage.
  3. Impact follows when stale access, shadow apps, or ungoverned AI usage create unnecessary exposure, wasted spend, or policy violations across the SaaS estate.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

SaaS management is converging with identity governance because visibility alone no longer answers the real risk question. Once teams know who is using a SaaS app, the next control problem is whether that access should still exist. That moves SMPs into IGA territory, especially where offboarding, access reviews, and entitlement hygiene have to follow actual usage rather than renewal dates.

Shadow AI turns SaaS governance into a continuous policy problem, not a periodic inventory exercise. Unapproved AI apps create the same governance failure pattern as shadow IT, but with faster data movement and more ambiguous user intent. The practical implication is that SaaS control now has to include policy enforcement at the point of access, not just after the fact.

Identity context is becoming the decisive differentiator between SaaS management and mere software administration. A platform that can map managed, unmanaged, and shadow apps to active identities and permissions is no longer only tracking spend. It is creating the evidence base for access review, deprovisioning, and risk-based application governance across the SaaS estate.

Integrated SaaS and IGA workflows reduce the gap between finding a risk and removing it. When discovery, access review, and deprovisioning live in separate systems, the governance loop is slow and brittle. When they are linked, the organisation can act on inactive accounts, unapproved applications, and risky AI adoption with less manual stitching, which is where modern SaaS oversight is heading.

App usage has become a governance signal, not just a cost metric. The article reflects a broader market shift in which license utilisation, access level, and compliance posture are all treated as inputs to identity decision-making. Practitioners should expect SaaS management tools to be judged less on counts and more on how directly they influence entitlement decisions.

From our research library:

What this signals

Identity context is now the missing layer in many SaaS management programmes. Inventory alone does not tell you whether access is legitimate, stale, or overextended. The next maturity step is linking usage signals to identity governance so discovery can drive removal, review, or restriction without manual interpretation.

Shadow AI will increasingly force SaaS teams and IAM teams into the same control conversation. Once generative AI apps are part of everyday software use, the question is no longer whether they exist but whether access, data handling, and policy enforcement are governed consistently across the full SaaS estate.


For practitioners

  • Map SaaS discovery to identity records Connect app inventory, SSO data, and browser activity to named users and permission levels so each application can be evaluated in identity terms, not just asset terms.
  • Trigger access reviews from shadow app detections Route unmanaged or unapproved app discoveries into the same review flow used for risky entitlements so governance action follows the finding immediately.
  • Automate deprovisioning for inactive usage Use configurable usage thresholds to remove or downgrade access when accounts stop showing meaningful activity across the SaaS stack.
  • Add shadow AI to application governance scope Track generative AI app adoption alongside other SaaS usage so policy, visibility, and user authorisation cover the same control boundary.
  • Tie renewal decisions to real usage data Use utilisation, access, and spend data together before contracts renew so procurement decisions reflect actual consumption rather than estimates.

Key takeaways

  • SaaS management is shifting from software counting to access governance, which changes the control objective for IAM and IGA teams.
  • The article shows that discovery, usage, and permission context now matter more than simple app inventory for deciding what should stay enabled.
  • Practitioners should connect SaaS detection to review, deprovisioning, and policy enforcement so visibility turns into action.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingInactive SaaS accounts and automated deprovisioning are central to the article.
NHI-05 — Overprivileged NHIThe article focuses on who has what level of access inside SaaS apps.
Recommendation — Use NHI-01 controls to revoke stale SaaS access when usage drops below governance thresholds. Apply NHI-05 to identify and reduce SaaS permissions that exceed current business need.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about entitlement governance across SaaS apps.
Recommendation — Align SaaS governance workflows to PR.AA-05 so entitlements are reviewed and adjusted continuously.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementShadow SaaS and stale access can expand credential exposure and movement opportunities.
Recommendation — Map unmanaged SaaS access to TA0006 and TA0008 to prioritise identity paths that widen attacker reach.

Key terms

  • SaaS Management Platform: A SaaS management platform is a visibility and optimisation layer for cloud software use. It helps teams discover applications, track utilisation, and understand spend patterns, but it does not by itself enforce access policy, revoke permissions, or manage identity lifecycle state.
  • Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
  • Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
  • Access review trigger: An access review trigger is the event that starts a certification or attestation workflow. In mature programmes, the trigger should reflect a real governance change such as a role move or leaver event, not just a fixed calendar date, so review timing aligns with risk.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org