By NHI Mgmt Group Editorial TeamBased on Zluri: “SaaS Portfolio Management: A Comprehensive Guide | 2026” (December 24, 2025)

TL;DR: SaaS portfolio management is presented as a way to control app sprawl, reduce redundant subscriptions, and improve compliance by centralising assessment, categorisation, licensing, and access oversight, according to Zluri. The identity issue is that portfolio management only helps when app ownership, user access, and offboarding are enforced across the full SaaS lifecycle.


At a glance

What this is: This guide explains SaaS portfolio management as a way to assess, rationalise, and govern cloud applications, while showing that unmanaged app sprawl creates visibility and access blind spots.

Why it matters: It matters because IAM teams cannot govern SaaS access, renewals, and offboarding reliably if the application estate itself is incomplete or outdated.


Context

SaaS portfolio management is the discipline of inventorying, categorising, and governing cloud applications so IT can decide what stays, what goes, and who should have access. In practice, the control challenge is not just cost optimisation. It is knowing which applications exist, how they are used, and whether access, ownership, and renewal decisions are still aligned to business need.

Zluri’s guide treats portfolio oversight as a way to reduce redundancy and improve compliance, but the governance gap is broader than application rationalisation. When SaaS adoption spreads faster than ownership and offboarding processes, shadow IT and stale entitlements accumulate in the spaces between procurement, usage, and retirement. That is where identity governance becomes a portfolio problem, not just an access review problem.


Key questions

Q: What breaks when SaaS portfolio management does not include access governance?

A: The programme can still reduce cost and improve visibility, but it will not reliably control who can use each application or whether access ends when the app is retired. That leaves shadow IT, stale entitlements, and orphaned accounts outside the normal IAM lifecycle, which is where audit and compliance gaps appear.

Q: Why does SaaS sprawl increase non-human identity risk?

A: SaaS sprawl increases NHI risk because every new integration can create tokens, service accounts, OAuth grants, and delegated permissions that persist outside normal review cycles. Those identities often have more reach than human users and fewer lifecycle checks. The result is wider attack surface and harder-to-audit access paths.

Q: What are the signs that SaaS app permission governance is failing?

A: Common warning signs include users approving apps outside policy, security teams lacking visibility into permission changes, and integrations with broad access that no one can explain. If administrators cannot see app security settings or changes are not reviewed promptly, the organisation is operating with blind spots that attackers can exploit through consent phishing or existing integrations.

Q: Should teams prioritise SaaS discovery or offboarding first?

A: Discovery comes first when the estate is incomplete, because you cannot govern what you cannot see. Offboarding should follow immediately for any apps that are redundant, unowned, or no longer required. The practical sequence is discover, assign ownership, then remove unnecessary access and retire the app cleanly.


Technical breakdown

Why SaaS portfolio sprawl undermines identity governance

SaaS portfolio sprawl occurs when application adoption outpaces the organisation’s ability to maintain an accurate inventory, assign owners, and govern access. The technical issue is not only discovery. It is that every SaaS app introduces its own user store, permissions model, renewal path, and lifecycle edge cases. Without a current portfolio, IAM teams cannot tell whether access belongs to an active business workflow, a forgotten subscription, or a shadow IT deployment. That makes certification, revocation, and compliance monitoring materially less reliable.

Practical implication: tie SaaS discovery to identity governance workflows so every app enters an ownership and access control process.

How license renewal and app retirement create access leakage

Renewal management and retirement are identity events as much as procurement events. If an app is renewed without verifying ownership, active users, and business relevance, stale accounts and unnecessary entitlements can persist for another term. If an app is retired without a clean offboarding process, accounts, tokens, and embedded permissions can outlive the service itself. The article’s lifecycle framing matters because renew, retain, and retire decisions all carry identity consequences that are easy to miss when SaaS is managed only as spend.

Practical implication: include access review and entitlement revocation in every renewal and retirement decision.

Where shadow IT turns into unmanaged identity risk

Shadow IT is often discussed as an inventory problem, but in SaaS environments it becomes an identity governance problem the moment users authenticate to unmanaged applications. Once employees adopt tools outside approved procurement, IT loses visibility into who can access data, where records are stored, and whether the app meets baseline controls. The risk is not abstract. Unrecorded apps create unmanaged access paths that bypass standard joiner, mover, and leaver processes and weaken auditability across the SaaS stack.

Practical implication: connect discovery tooling to access governance so hidden apps cannot escape lifecycle controls.


Threat narrative

Attacker objective: The objective is to exploit unmanaged SaaS access and governance gaps to reach data or workflows that the organisation cannot easily control or audit.

  1. Entry occurs when users or departments adopt SaaS applications outside the approved application inventory, creating unmanaged access paths.
  2. Privilege accumulation follows when licenses, accounts, and permissions are left in place without a clean renewal or retirement decision.
  3. Impact emerges as shadow IT and redundant apps increase the chance of unauthorised access, poor auditability, and compliance gaps.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

SaaS portfolio management is now an identity governance function, not just an IT inventory exercise. The article frames portfolio oversight around assessment, categorisation, and renewals, but each of those steps determines whether access remains governable. Once application sprawl outpaces ownership assignment, the IAM programme no longer has a complete system boundary to govern. Practitioners should treat the SaaS portfolio as part of the identity estate.

Visibility without lifecycle enforcement creates a false sense of control. Central dashboards can show usage, cost, and compliance status, but those views do not revoke orphaned access or retire stale credentials by themselves. The governance failure is assuming that discovery equals control. In practice, discovery only becomes meaningful when it drives ownership, recertification, and offboarding across every application.

Application renewal is an access decision disguised as procurement. Every renewal extends the period in which existing accounts, delegated permissions, and data paths remain valid. That means renewal workflows need identity checks, not just commercial approval. The practitioner lesson is to treat renewal governance as part of the access lifecycle, especially where SaaS applications are widely integrated into business processes.

Shadow SaaS blind spot: The article shows that hidden applications undermine the organisation’s ability to know who has access to what, where data is stored, and whether controls are consistent. That blind spot matters because IAM and IGA controls are only as complete as the application estate they can see. The implication is to measure governance coverage against the true SaaS footprint, not the approved catalogue only.

From our research library:

What this signals

SaaS portfolio sprawl is a governance boundary problem. Once the application estate becomes fragmented across departments and procurement paths, IAM teams lose the clean inventory needed for meaningful recertification and offboarding. The control question is no longer whether a dashboard exists, but whether the organisation can prove ownership and access for every live SaaS app.

Portfolio rationalisation should be measured by access closure, not just spend reduction. A shorter application list is useful only if the retired services no longer hold accounts, tokens, or delegated permissions. Otherwise, the organisation has reduced tooling count without reducing the identity surface.

SaaS ecosystem breadth matters because the average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms. That kind of connectivity means portfolio oversight has to extend beyond application counting into lifecycle governance for the connected identities and integrations.


For practitioners

  • Inventory the full SaaS estate Compile a continuously updated inventory of approved and unapproved SaaS applications, including owners, user populations, and renewal dates so identity governance starts from a complete system boundary.
  • Bind renewal to access review Require ownership validation, active-user checks, and entitlement recertification before any SaaS contract is renewed, especially where applications carry sensitive data or delegated access.
  • Offboard access at retirement Remove accounts, tokens, and embedded permissions as part of every application retirement process so old SaaS services do not leave behind residual access paths.
  • Trace shadow IT back to governance Map discovered unsanctioned applications into the same joiner, mover, and leaver controls used for approved apps so hidden adoption cannot bypass lifecycle governance.

Key takeaways

  • SaaS portfolio sprawl creates identity governance blind spots because discovery, ownership, and access control are often managed separately.
  • The article’s value is in showing that renewals and retirements are lifecycle events with direct access implications, not just procurement decisions.
  • The practical response is to connect SaaS inventory to recertification, offboarding, and ownership validation so hidden apps cannot escape governance.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingSaaS retirement without access cleanup leaves residual identities behind.
NHI-05 — Overprivileged NHIShared SaaS apps often accumulate excessive permissions and stale access paths.
Recommendation — Map SaaS retirement to NHI-01 and remove residual accounts, tokens, and permissions before decommissioning. Review SaaS entitlements against NHI-05 and shrink access to the minimum required for active use.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementSaaS accounts, tokens, and subscriptions need lifecycle management and revocation controls.
Recommendation — Apply IA-5 to govern SaaS authenticator issuance, renewal, and revocation across the application estate.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementHidden SaaS access paths can support credential misuse and movement across connected apps.
Recommendation — Map hidden SaaS access paths to TA0006 and TA0008 to prioritise detection and containment.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on whether app portfolios and entitlements are governed together.
Recommendation — Use PR.AA-05 to align SaaS access permissions with current business need and ownership.

Key terms

  • SaaS Portfolio Management: The process of assessing, classifying, and governing an organisation's cloud application stack so it aligns with business need and security expectations. In practice, it combines cost control, access oversight, renewal decisions, and retirement hygiene into one continuous management loop.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Application lifecycle control: Application lifecycle control is the practice of managing an application from adoption through review and retirement. In SaaS environments, it ensures ownership, user access, data handling, and decommissioning stay aligned with business need rather than lingering as informal or forgotten entitlements.
  • Access Governance: Access governance is the policy and workflow layer that manages how access is requested, approved, certified, and revoked. In SaaS environments it helps standardise control across many applications, reducing inconsistency between teams. It is most effective when it covers both human accounts and non-human identities.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org