TL;DR: SaaS spend management becomes a control problem, not just a finance problem, because unused licenses, auto-renewals, and orphaned accounts are all tied to identity lifecycle gaps, according to Josys. The operational fix is continuous discovery, access review, and offboarding-linked deprovisioning, because spend waste and access risk usually share the same root cause.
At a glance
What this is: This article argues that SaaS spend waste is driven by visibility gaps, auto-renewals, and orphaned user access, with identity data providing the most reliable way to find and remove waste.
Why it matters: It matters to IAM and NHI practitioners because the same controls that reclaim licenses also reduce access exposure, making spend governance and identity governance inseparable.
By the numbers:
- 72%, anizations that experienced or suspected a non-human identity breach reached 72%, with 46% confirming one and 26% suspecting one.
👉 Read Josys's analysis of SaaS spend waste and identity-led control
Context
SaaS spend management is the discipline of tracking, controlling, and optimizing subscription software costs, but the deeper issue is governance drift. In practice, software spend rises when applications are added outside central oversight, renewals auto-extend, and accounts remain active after people leave. For IAM teams, the article's central point is that the license ledger and the identity ledger are the same problem viewed from different angles.
The article also makes a useful operational distinction between finance-led review and identity-led discovery. Invoice data can show what was purchased, but it cannot reliably show whether a seat is still justified or whether the associated account is orphaned. That is the identity bridge: access visibility, offboarding, and entitlement review are what turn SaaS cost control into a repeatable governance process.
The starting position described here is typical for enterprise SaaS estates, not exceptional. Most organisations accumulate tool sprawl through ordinary business decisions, which is why the waste persists until someone connects procurement, usage, and identity lifecycle data.
Key questions
Q: How should security teams connect SaaS spend management with IAM governance?
A: Security teams should treat SaaS spend data as an identity signal. Discovery, licence usage, and renewal reports should feed access reviews, offboarding, and app ownership workflows so shadow apps and idle licences are governed as entitlement problems, not only budget problems.
Q: Why do orphaned SaaS apps create more risk than unused licences?
A: Orphaned SaaS apps can still hold data, tokens, and integrations after the original business need has ended. That means the exposure is operational, not just financial. If no owner exists to revoke access, rotate credentials, or decommission the service, the app remains a live entry point.
Q: What should teams do first when SaaS spend starts to drift upward?
A: Start with identity-led discovery, not a budget freeze. Pull SSO logs, OAuth grants, invoices, and AP records into one inventory, then compare purchased seats with meaningful activity in the last 90 days. That sequence finds both hidden applications and the easiest seats to reclaim.
Q: How can organisations tell whether SaaS budget controls are working?
A: Look for fewer orphaned subscriptions, lower duplicate app counts, and clean ownership records tied to each renewal. If finance can explain spend but IAM cannot explain who still has access, the control set is incomplete. Effective governance shows up as aligned inventory, ownership, and access removal.
Technical breakdown
Why invoice data alone misses SaaS waste
Invoice and AP records are useful for confirming spend, but they are blind to shadow IT, free-tier apps, personal-card purchases, and departmental buying. The real control problem is that a purchase record does not tell you who is using the service, whether the account still belongs to an active worker, or whether the license is tied to a dormant identity. That makes identity-centric discovery, including SSO logs and OAuth grants, essential for accurate inventory.
Practical implication: build SaaS inventory from identity signals, not finance records alone.
Why orphaned accounts and unused licenses are the same issue
A license becomes waste when the identity attached to it no longer needs access, and that same condition also creates an exposure window. Offboarding often covers core systems first, while departmental SaaS tools lag behind and continue billing. In identity terms, this is an entitlement lifecycle failure: access persists beyond employment, project need, or operational relevance, so cost leakage and security exposure converge.
Practical implication: wire license revocation to offboarding so access removal and cost recovery happen together.
How renewal automation changes the control model
Auto-renewal shifts the default from deliberate purchasing to passive continuation, which is why renewal date management is a control, not an admin task. A renewal calendar, usage review, and approval path create a decision point before spend becomes locked in for another term. The article's key governance insight is that SaaS cost control works best when renewal, access review, and deprovisioning are treated as one lifecycle rather than separate workflows.
Practical implication: create pre-renewal review gates that depend on usage and owner approval before contracts roll over.
Threat narrative
Attacker objective: The operational objective is not direct intrusion but prolonged unauthorized access and persistent cost leakage through unmanaged subscriptions and accounts.
- Entry occurs when employees, departments, or contractors add SaaS apps outside procurement or keep access after role changes, creating unmanaged accounts and subscriptions.
- Escalation happens when orphaned identities, over-tiered seats, and missed offboarding keep permissions and billing active long after the original business need has ended.
- Impact is recurring financial waste plus expanded attack surface, because unmanaged SaaS accounts and apps sit outside normal governance and access controls.
NHI Mgmt Group analysis
Identity-led SaaS governance is now the more accurate control model. The article is strongest when it shows that software waste is not just procurement drift but entitlement drift. If every paid seat maps to an identity, then inventory, renewal, and offboarding belong in the same governance loop. That is where IAM teams can add measurable value by treating SaaS spend as a lifecycle issue rather than a budget-only exercise.
Orphaned SaaS access is both a cost leak and an access-control failure. The article's key insight is that departed users and abandoned tools are not separate problems. They are the same governance gap expressed in different ledgers, which means access review discipline directly affects both risk and spend. Practitioners should read this as a case for closing entitlement persistence windows, not just reclaiming seats.
Shadow SaaS creates an identity visibility gap that finance cannot close. The article notes that browser signals, SSO logs, and OAuth grants are necessary to find apps people actually use. That aligns with broader identity governance practice: if an application is invisible to identity controls, it is also invisible to lifecycle enforcement. Teams need one inventory that spans procurement, authentication, and offboarding.
SaaS renewal control is a form of privilege control. Auto-renewal makes continuation the default, which means a contract can keep granting access and consuming budget without an explicit decision. The stronger governance pattern is to require an owner, a review date, and a usage check before renewal. In practical terms, this is the same discipline as least privilege, applied to subscriptions.
Continuous governance beats periodic cleanup. Annual audits will always lag the pace at which employees, tools, and contracts change. A named owner, quarterly review cadence, and automated deprovisioning create a control loop that can keep pace with normal business churn. For identity and SaaS teams, that is the difference between one-time reclamation and durable control.
What this signals
SaaS spend control is converging with identity governance. As organisations move toward identity-led discovery, the operational boundary between financial control and access control keeps shrinking. That matters because the same data that identifies waste also exposes orphaned access, and the strongest programmes will treat those as one governance workflow rather than two disconnected reviews.
Persistent entitlements are the hidden tax inside subscription software. If an identity retains access after its business need ends, the organisation pays twice: once in recurring subscription fees and again in residual access exposure. The practical response is to make offboarding, renewal review, and access certification part of the same operating rhythm.
License reclamation is becoming a measurable identity security signal. When teams can show shrinking gaps between active identities and paid seats, they have evidence that governance is working. That is the kind of operational metric that can be reported alongside access review coverage, because it demonstrates control over both spend and exposure.
For practitioners
- Map SaaS seats to identity records Build your inventory from SSO logs, OAuth grants, and browser-level discovery so each app and seat is linked to an accountable identity and owner.
- Tie offboarding to license revocation Automate deprovisioning so that access removal also reclaims the associated subscription seat the same day an employee, contractor, or project ends.
- Set a 90-day usage threshold Compare purchased seats against meaningful activity in the last 90 days, then reclaim zero-activity licenses and review low-activity seats with managers.
- Create a pre-renewal approval gate Require an owner review, usage evidence, and an explicit decision before any SaaS contract renews automatically, especially for tools outside central procurement.
- Consolidate overlapping tools by function Group applications by what they do, not by vendor name, so you can remove redundant platforms and reduce duplicate access review paths.
Key takeaways
- SaaS waste is fundamentally an identity lifecycle problem, not just a finance problem.
- Orphaned accounts and unused licenses represent both recurring cost leakage and avoidable access exposure.
- Continuous identity-led discovery, offboarding, and renewal control are what keep SaaS governance stable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST SP 800-63 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorisations | SaaS seats are governed through access permissions and lifecycle control. |
| Recommendation — Map SaaS entitlements to PR.AC-4 and enforce review before renewal or offboarding. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Over-tiered licenses and lingering access both reflect excess privilege. |
| Recommendation — Apply AC-6 to remove unnecessary SaaS access and downgrade users to the least capable tier. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article centres on inventory, ownership, and account removal across SaaS tools. |
| Recommendation — Use CIS Control 5 to inventory SaaS accounts and revoke stale access on offboarding. | ||
| ISO/IEC 27001:2022 | A.8.2 — Privileged Access Rights | Higher SaaS tiers and lingering access both require tighter rights management. |
| Recommendation — Review privileged SaaS roles under A.8.2 and remove access that no longer matches job need. | ||
| NIST SP 800-63 | SP 800-63C — Federation | Identity-led SaaS discovery depends on federated login and connected application signals. |
| Recommendation — Use SP 800-63C federation data to discover SaaS usage and connect applications to identities. | ||
Key terms
- Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
- Orphaned license: A software subscription seat that remains active after the original user no longer needs it. Orphaned licenses create direct cost leakage and can also preserve access paths or data ownership links that should have been retired during offboarding.
- Identity-led investigation: An investigation approach that treats identity activity as a primary source of compromise evidence rather than a supporting signal. It correlates IdP, SaaS, cloud, and endpoint data to determine whether access was expected, abused, or delegated in a risky way.
- Renewal Gate: A renewal gate is a required review point before a SaaS contract can auto-renew. It forces an explicit decision based on usage, ownership, and business need, turning renewal from a passive default into a managed control in the software lifecycle.
What's in the full article
Josys's full article covers the operational detail this post intentionally leaves for the source:
- A practical audit sequence for building a SaaS inventory from finance records, SSO logs, and OAuth grants.
- Step-by-step guidance for splitting unused licenses into zero-activity, low-activity, and over-tiered groups.
- Contract-renewal tactics for owners who need to negotiate using usage data rather than generic discount requests.
- A working model for wiring offboarding into automatic deprovisioning so seats are reclaimed without manual follow-up.
Deepen your knowledge
NHI Mgmt Group's NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle discipline. It is designed for practitioners who need to connect access control, lifecycle governance, and operational risk across their programmes.
Published by the NHIMG editorial team on September 16, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org