TL;DR: Cost control, license visibility, and access governance are converging as one operational problem in SaaS spend management tools, especially where shadow apps, unused subscriptions, and risky access create both waste and exposure, according to Zluri’s 2026 review. The real lesson is that spend optimisation now depends on identity control, not procurement alone.
At a glance
What this is: This is a review of SaaS spend management tools that finds cost optimisation and identity governance are converging around the same control surface.
Why it matters: It matters because IAM and IGA teams can no longer treat SaaS cost control as a procurement-only problem when unused licences, shadow apps, and access permissions all sit in the same operational path.
Context
SaaS spend management is the discipline of tracking software subscriptions, usage, and licence allocation so organisations can reduce waste and improve control. In Zluri's review, the practical issue is not just overspend but the identity layer underneath it, because access rights, application inventory, and entitlement usage all shape what gets paid for and what remains exposed.
That makes the topic relevant to IAM and IGA as well as finance operations. When a tool claims to discover shadow apps, surface unused licences, and manage user access, it is really describing the same governance problem from three angles: ownership, entitlement, and cost. The article's core message is that SaaS optimisation now depends on identity visibility, not on spend tracking alone.
Key questions
Q: What breaks when SaaS spend management is treated separately from identity governance?
A: The organisation can remove licences without removing accounts, or keep accounts active without any clear business need. That split leaves shadow access in place, weakens ownership, and produces a false sense of control because the finance view and the identity view never meet.
Q: Why do unused SaaS licences create identity risk as well as cost waste?
A: Unused licences often indicate that apps are still licensed after the people or teams that justified them have changed. That usually means access review, account removal, and contract ownership are not aligned. The result is unnecessary spend plus a larger surface for stale access and administrative confusion.
Q: How do you know if SaaS license optimization is working?
A: You should see fewer duplicate applications, lower spend on unused seats, clearer application ownership, and cleaner recertification outcomes. If renewals are still approved without usage evidence, the programme is not working. The strongest signal is that access and spend decisions are now tied to measurable business use.
Q: Should organisations treat SaaS spend tools as part of IGA or finance operations?
A: They should treat them as part of both, but with identity governance taking priority whenever access, ownership, or lifecycle decisions are involved. Finance teams care about cost efficiency, while IAM and IGA teams control who can still use the application and when that access should end. The strongest programmes connect those functions instead of running them as separate workstreams.
Technical breakdown
How SaaS discovery, licence usage, and access control intersect
SaaS spend management platforms combine application discovery, usage telemetry, and licence assignment data to reveal where money is being wasted. Discovery shows which apps exist, usage shows whether the licence is active, and access control shows who can still reach the application. The technical issue is that these signals often live in different systems, so a team may know an app is unused without knowing whether dormant access still exists. That creates a governance blind spot where cost optimisation and access reduction need to be evaluated together.
Practical implication: align SaaS inventory, licence data, and access entitlement reviews in one operating rhythm.
Why shadow apps and redundant subscriptions are an identity problem
Shadow IT becomes a spend problem only after it is first an identity problem. An unvetted SaaS app usually enters through a user, team, or workflow with some form of authorised access, then persists outside central visibility. The article's emphasis on discovery methods, including SSO, directories, finance systems, and browser extensions, shows that app inventory is assembled from identity and usage signals rather than procurement records alone. Once those signals are incomplete, redundant subscriptions and risky access can survive in parallel.
Practical implication: treat app discovery as an access-governance control, not just a finance reconciliation exercise.
Why renewals and licence rationalisation depend on lifecycle governance
Licence management is not just about counting seats. In practice, it depends on joiner-mover-leaver logic for application access, because a subscription that outlives the user who needs it becomes pure waste and possible exposure. The article repeatedly ties renewals, underused licences, and access permissions together, which is a sign that lifecycle governance is the hidden control plane. If offboarding, reassignment, and periodic review do not happen reliably, spend optimisation cannot be sustained.
Practical implication: build SaaS licence rationalisation into identity lifecycle and access review processes.
Threat narrative
Attacker objective: The objective is to exploit unmanaged SaaS sprawl and lingering access to expand exposure, evade oversight, and persist inside the application estate.
- Entry occurs when users, departments, or workflows add SaaS applications outside central governance, creating shadow app adoption and fragmented ownership.
- Credential or entitlement exposure follows when unused licences and lingering access permissions remain active after the app or user should have been retired.
- Escalation happens when duplicate tools and unmanaged subscriptions expand the attack surface while cost controls and access controls operate separately.
- Impact is wasted spend, weaker visibility, and higher risk from unauthorised or risky applications that remain inside the estate.
Breaches seen in the wild
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Spend management has become an identity governance problem wearing a finance label: once SaaS discovery, licence optimisation, and access control share the same workflow, procurement alone cannot explain or fix the control gap. The article reflects a broader market shift where app inventory, entitlement data, and lifecycle decisions all shape whether an organisation pays for software it should have already removed. Practitioners should treat SaaS cost control as a governance discipline, not a budgeting side task.
Shadow SaaS is the operational expression of incomplete identity visibility: the article's discovery methods matter because no single source of truth captures every application, licence, and access path. SSO, directories, finance systems, and browser telemetry each reveal different parts of the same control problem, and gaps between them create both waste and risk. The practitioner conclusion is straightforward: if the inventory is partial, the spend picture will be partial too.
Identity lifecycle discipline is what turns licence optimisation from a one-time clean-up into a durable control: underused subscriptions do not disappear on their own, and renewal alerts are only useful when offboarding, reassignment, and access review are actually enforced. This is the same lifecycle logic applied to SaaS access that identity teams already expect for human and non-human accounts. Teams should map SaaS rationalisation to joiner-mover-leaver governance rather than run it as an isolated cost exercise.
SaaS spend management tools now sit on the boundary between IGA and operational security: once a platform can flag risky applications, track permission use, and support compliance reporting, it is influencing decisions that extend beyond finance. That makes the category relevant to access governance, audit readiness, and exposure reduction at the same time. Practitioners should evaluate these tools by how well they connect inventory, entitlement, and accountability rather than by savings claims alone.
Identity blast radius is the right concept for this category: every unmanaged application, duplicate subscription, or stale licence expands the number of places where access can persist without ownership. The article points to a market direction where SaaS governance is becoming a continuous visibility problem rather than a periodic procurement review. Teams should measure whether their controls reduce that blast radius, not just whether they lower the monthly bill.
From our research library:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
What this signals
Identity visibility is now the prerequisite for SaaS cost control: the article shows that discovery, licence management, and access permissions are converging into one operational question. Teams that still separate procurement oversight from access governance will miss the control point that actually reduces waste.
Lifecycle control is what keeps SaaS optimisation from backsliding: once a subscription is reclaimed, the access path has to be removed or reassigned, otherwise the same waste returns at the next renewal cycle. That is why SaaS rationalisation belongs inside identity operations, not beside them.
App sprawl creates an identity blast radius: every unmanaged SaaS service increases the number of entitlements, owners, and review decisions an organisation has to track. The programme implication is simple: shrink the application set, or the governance burden keeps growing faster than the savings.
For practitioners
- Map SaaS inventory to entitlement ownership Correlate discovery data from SSO, directories, finance systems, and app integrations so every application has a named owner and an access path you can review.
- Tie licence reviews to joiner-mover-leaver processes Use offboarding and mover events to reclaim unused seats, remove dormant access, and prevent licences from surviving the business need that justified them.
- Separate duplicate apps from required apps by business function Rationalise overlapping tools by mapping each one to a business outcome, then retire the redundant licence where two products cover the same workflow.
- Set renewal decisions on verified usage, not contract timing Require current utilisation data before any renewal, so licences are renewed only when the access and workflow evidence still supports them.
- Bring risky SaaS discovery into security review Flag unmanaged or unvetted applications for security assessment before they are allowed to remain in the estate or expand their permissions.
Key takeaways
- SaaS spend management is no longer just a procurement exercise because access governance now determines whether software is actually in use.
- Discovery and licence optimisation only work when inventory, entitlement ownership, and offboarding are tied together.
- The practical goal is to reduce SaaS waste by removing duplicate apps, reclaiming unused licences, and enforcing lifecycle control over access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 — Vulnerable Third-Party NHI | Third-party SaaS apps create unmanaged identity and access exposure across the estate. |
| NHI-05 — Overprivileged NHI | Unused licences and broad app permissions indicate excess access beyond current business need. | |
| Recommendation — Inventory third-party SaaS identities and remove any app access that lacks a clear owner or lifecycle path. Review SaaS entitlements for excess access and reduce permissions to the minimum required for current use. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centres on controlling who can use SaaS applications and whether access is still warranted. |
| Recommendation — Align SaaS licence decisions to entitlement reviews so access stays tied to business need. | ||
| CIS Controls v8 | CIS-5 — Account Management | Lifecycle control of SaaS access depends on timely account removal and entitlement hygiene. |
| Recommendation — Reconcile SaaS accounts regularly and remove dormant or orphaned access without waiting for renewal. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Licence and access management depend on lifecycle control of credentials and authenticators behind SaaS use. |
| Recommendation — Enforce authenticator lifecycle controls so dormant SaaS access is revoked when no longer needed. | ||
Key terms
- SaaS Spend Management: SaaS spend management is the practice of tracking, analysing, and reducing software subscription costs across an organisation. It combines usage data, renewal timing, and ownership information so teams can remove waste, renegotiate contracts, and align applications with business need.
- Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
- License Rationalisation: License rationalisation is the practice of matching paid software entitlements to actual business use so organisations stop paying for excess capacity. In identity terms, it also helps reveal which accounts or integrations still have access even after the need has ended.
- Joiner-Mover-Leaver Lifecycle: The joiner-mover-leaver lifecycle describes the access changes that should happen when a person or account is created, changes role, or exits the organisation. It is the basic operating model for keeping entitlements aligned to current need, and it becomes critical when automation replaces manual ticket handling.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org