By NHI Mgmt Group Editorial TeamBased on Zluri: “How CFOs can Leverage SMPs to Optimize SaaS Spending?” (June 26, 2025)

TL;DR: Rising SaaS spend and unmanaged app usage create hidden costs and governance gaps as organisations lose visibility into licenses, renewals, duplicate tools, and abandoned access, according to Zluri and Gartner. The identity problem is not just overspend: app lifecycle control across people, subscriptions, and access ownership is now a security requirement.


At a glance

What this is: This article argues that SaaS spend problems also expose an identity governance gap, because unused licenses, duplicate apps, auto-renewals, and abandoned apps reflect weak lifecycle control.

Why it matters: It matters because IAM, IGA, and SaaS governance teams need visibility into app ownership, licensing, and offboarding if they want to reduce both waste and residual access risk.

By the numbers:

  • Cloud services spiked by 20.4% in 2022 compared to 2021, according to Gartner research cited by Zluri.
  • In 2021 the end-users spent $410.9 billion, and in 2022 the numbers reached $494.7 billion, according to Gartner research cited by Zluri.
  • The users are expected to spend nearly $600 billion by 2023, according to Gartner research cited by Zluri.
  • CFOs may pay for 130 unused licenses when they buy 200 licenses but only 70 are used, according to Zluri.

Context

SaaS spend management is not only a finance problem. When organisations cannot reconcile who owns an application, which licenses are active, and which subscriptions renew automatically, the same blind spot that inflates software spend also leaves access paths unmanaged.

For IAM and IGA teams, that is the important governance gap in this article. App sprawl, duplicate tools, and abandoned subscriptions show that SaaS lifecycle control now sits at the intersection of cost management, offboarding, and entitlement visibility.

The source frames CFO accountability, but the operational lesson is broader: software procurement without lifecycle ownership creates a standing access and spending tail. That pattern is common in decentralized SaaS adoption, which is why the article maps directly to identity governance rather than finance alone.


Key questions

Q: How should security teams handle SaaS applications that are bought outside IT?

A: They should bring those apps into a managed inventory, assign business ownership, and require renewal review before the contract continues. The goal is not only cost control. It is also making sure unsanctioned tools do not become unmanaged access paths that bypass lifecycle governance and create shadow IT risk.

Q: Why do duplicate SaaS apps create identity governance risk?

A: Duplicate apps split ownership, permissions, and data flows across multiple systems that perform the same job. That makes access certification less reliable, offboarding harder, and audit evidence weaker because reviewers cannot clearly identify the authoritative control point for a given business function.

Q: What breaks when SaaS offboarding is not tied to identity revocation?

A: The organisation keeps paying for applications after the business no longer needs them, and access can remain active even after the relationship should end. That creates budget leakage, audit exposure, and unnecessary access persistence. The failure is not just operational waste, but the loss of a reliable end state for application lifecycle management.

Q: How can organisations tell whether SaaS budget controls are working?

A: Look for fewer orphaned subscriptions, lower duplicate app counts, and clean ownership records tied to each renewal. If finance can explain spend but IAM cannot explain who still has access, the control set is incomplete. Effective governance shows up as aligned inventory, ownership, and access removal.


Technical breakdown

Why SaaS renewals become a lifecycle control problem

Auto-renewal turns temporary usage into persistent spend and persistent access unless someone owns the offboarding step. In SaaS environments, subscriptions are often bought by teams, adopted by individual users, and then forgotten when the project ends or the employee leaves. That creates a governance gap between procurement, access ownership, and deprovisioning. The technical issue is not the renewal itself, but the absence of a controlled lifecycle state that can be inspected, revoked, or reassigned before the next billing cycle.

Practical implication: Treat renewal review as a lifecycle checkpoint, not a finance task, and tie it to ownership and offboarding records.

How duplicate apps complicate access governance

Duplicate SaaS apps are usually a symptom of fragmented identity ownership. If multiple departments independently adopt tools with overlapping functions, the organisation loses a clean inventory of where user access lives, who administers it, and which app should be authoritative. That weakens recertification and makes entitlement reviews noisy, because the same business function may be spread across several applications with different owners and inconsistent access controls. The governance problem is therefore not just redundant spend, but fragmented control over who can access what across similar services.

Practical implication: Build a single inventory of overlapping SaaS apps and link each one to an accountable business and identity owner.

Why abandoned apps outlive the user who created them

Abandoned apps emerge when the person who signed up for a service leaves, but the subscription and associated access continue. That creates both waste and a residual identity risk, because no one is left actively managing the app, its licenses, or its administrative permissions. In practice, this is a lifecycle failure: the access path remains live after the human owner has gone, which is exactly where shadow subscriptions and orphaned app access start to accumulate. The article’s key point is that no-owner apps are not benign; they are unmanaged identity assets.

Practical implication: Require offboarding to cover application ownership, subscription cancellation, and admin reassignment together.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Abandoned SaaS subscriptions are a lifecycle failure, not only a spend problem. When an app continues after the employee or team that created it no longer needs it, the organisation has lost control of both cost and accountability. That is the same governance gap that lets orphaned access linger in identity programmes, and it is why app ownership has to be treated as a control objective, not an administrative detail.

Duplicate SaaS tools create entitlement ambiguity that weakens governance. If Trello, Asana, and Monday are all being used for similar work, the organisation no longer has a single answer to who owns the business process or which app should carry the authoritative access model. That ambiguity complicates reviews, renewals, and offboarding because control decisions are distributed across overlapping platforms. Practitioners should treat tool sprawl as a signal that identity ownership is fragmented.

Standing SaaS access after offboarding is the hidden risk behind cost leakage. The article’s abandoned-app examples show how subscriptions can continue after the user departs, leaving no active owner to revoke access or cancel the service. This is the same structural problem that identity programmes face with orphaned accounts: lifecycle closure did not happen at the right boundary. The implication is that SaaS governance must include deprovisioning of the service itself, not just the user.

App lifecycle governance: The central issue is not whether SaaS spend is high, but whether every subscription has an owner, an expiry condition, and an offboarding path. That is the control model missing in many decentralised environments. Without it, renewals, duplicate tools, and abandoned access all persist past their useful life, and the organisation pays for drift twice, once in money and once in control loss.

From our research library:

What this signals

Application lifecycle governance has become a cross-functional control problem, not a procurement hygiene task. When renewals, duplicate apps, and abandoned subscriptions are allowed to drift, the organisation loses the ability to connect spend, access, and ownership in one governance model.

The practical signal for IAM and IGA teams is simple: SaaS inventory quality now determines whether offboarding, recertification, and renewal decisions can be trusted. If the organisation cannot name the owner of an application, it cannot confidently say who is responsible for the access and cost that follow it.


For practitioners

  • Map every SaaS app to an accountable owner Assign a business and identity owner to each subscription so renewals, access reviews, and offboarding are not handled as ad hoc exceptions.
  • Reconcile active users against paid licenses Compare purchased seats to active accounts on a regular cadence and downsize subscriptions that remain materially underused.
  • Eliminate overlapping SaaS tools Inventory apps with the same business function, decide which one is authoritative, and retire the others before duplicate access spreads further.
  • Make offboarding include subscription cancellation When a user leaves, remove their app access, transfer ownership where needed, and confirm that the subscription will not silently renew.
  • Review renewal calendars before contract rollover Use renewal checkpoints to verify current usage, business need, and administrative ownership before the next billing event.

Key takeaways

  • SaaS overspend and SaaS governance failures often come from the same source: poor visibility into ownership, licensing, and application lifecycle.
  • The article shows that unused licenses, duplicate tools, auto-renewals, and abandoned apps all point to fragmented control over subscriptions and access.
  • Organisations need a lifecycle model for SaaS apps, because cost optimisation only works when ownership, offboarding, and renewal decisions are managed together.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingAbandoned SaaS apps in the article are classic offboarding failures.
NHI-05 — Overprivileged NHIUnused licenses and duplicate apps often indicate excess access and unused entitlement.
NHI-07 — Long-Lived SecretsAuto-renewed subscriptions and lingering app access create long-lived exposure windows.
Recommendation — Tie SaaS deprovisioning to NHI-01 and revoke service ownership when users leave. Review SaaS entitlements for overprovisioned access and remove unused privileges. Shorten the lifetime of SaaS access paths and retire stale subscriptions on schedule.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on tracking licenses, access ownership, and abandoned app permissions.
Recommendation — Align SaaS inventory and entitlement reviews to PR.AA-05 so permissions stay attributable.
CIS Controls v8CIS-5 — Account ManagementManaging SaaS users, licenses, and offboarding maps directly to account lifecycle control.
Recommendation — Use CIS-5 to ensure SaaS accounts are removed or reassigned during offboarding.

Key terms

  • SaaS Lifecycle Governance: SaaS lifecycle governance is the set of controls that manage applications from onboarding through access assignment, renewal, and decommissioning. It matters because the security value of SaaS management depends on whether the organisation can prove ownership, revoke access, and retire unused tools on demand.
  • Abandoned application: A SaaS application that remains subscribed or accessible after the original business need has ended. In governance terms, it is an orphaned service that may still hold data, retain users, or auto-renew, creating cost leakage and residual access risk until someone formally terminates it.
  • Redundant SaaS App: A redundant SaaS app is a tool that duplicates the function of another application already in use by the organisation. The governance issue is not only cost duplication, but the extra identities, permissions, and integrations that have to be reviewed, retired, and secured across both systems.
  • Licence Right-Sizing: Licence right-sizing is the process of matching user entitlement to real business need so organisations do not pay for access they do not use. In governance terms, it also exposes over-provisioning that can widen risk and complicate audit evidence.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org