TL;DR: More than 30% of SaaS spend is wasted each year, according to Zluri research, while the post argues that unused, duplicate, and abandoned subscriptions also create security and compliance drag as SaaS adoption accelerates. The practical issue is not just cost control. It is governance over app access, lifecycle, and entitlement cleanup before shadow subscriptions become shadow identities.
At a glance
What this is: This is a SaaS management perspective arguing that forgotten, unused, and duplicate subscriptions create both waste and identity governance risk.
Why it matters: IAM and IGA teams should care because SaaS sprawl expands the number of app entitlements that must be inventoried, reviewed, and removed before they become unmanaged access paths.
By the numbers:
- More than 30% of SaaS spend is wasted every year, according to Zluri research.
Context
SaaS sprawl is the uncontrolled growth of subscriptions across teams, often with duplicate tools, forgotten renewals, and accounts that remain active after the business need has ended. In identity terms, the risk is not just cost leakage. It is ungoverned access to business applications that still carry data, permissions, and workflow reach.
The article's core point is that subscription hygiene and identity governance are now connected problems in SaaS-heavy environments. When app ownership, renewal, and offboarding are handled inconsistently, organisations accumulate shadow subscriptions that behave like shadow identities, because nobody is clearly accountable for their lifecycle or access removal.
Key questions
Q: How should teams govern SaaS subscriptions that no one actively uses?
A: Treat them as lifecycle objects, not just cost items. Every dormant subscription should still have an owner, a renewal decision, and a removal path. If a subscription has no current business purpose, the associated app accounts, roles, and integrations should be retired through the same governance process used for other access cleanup.
Q: Why does SaaS sprawl increase non-human identity risk?
A: SaaS sprawl increases NHI risk because every new integration can create tokens, service accounts, OAuth grants, and delegated permissions that persist outside normal review cycles. Those identities often have more reach than human users and fewer lifecycle checks. The result is wider attack surface and harder-to-audit access paths.
Q: What breaks when subscription ownership is not assigned?
A: Review and offboarding break first. Without a named owner, nobody can confidently approve renewal, remove stale licences, or confirm whether the application still supports a current business process. The result is entitlement residue that remains in place long after the subscription should have been retired.
Q: How do organisations reduce shadow subscriptions without creating more manual work?
A: Use a repeatable review process that combines app inventory, usage data, and ownership checks. The goal is to make subscription retirement a standard governance step, not a spreadsheet exercise. That gives IAM and procurement one shared view of which tools are still justified.
Technical breakdown
Why SaaS sprawl becomes an identity problem
SaaS subscriptions are not just line items on a finance ledger. Each subscription typically creates one or more accounts, roles, token-based integrations, and delegated access paths that must be governed across their full lifecycle. When subscriptions are duplicated or forgotten, the identity layer becomes fragmented: app owners lose track of who should retain access, which accounts are active, and whether dormant licences still map to live permissions. In an IAM or IGA programme, that creates a blind spot because the service catalogue and the access estate drift apart.
Practical implication: Treat SaaS inventory as an identity inventory, not just a procurement list.
Shadow subscriptions and entitlement cleanup
A shadow subscription is a paid application instance that persists without active use or clear ownership. From a governance perspective, the problem is that access often survives longer than intent. This creates entitlement residue: accounts, roles, and integrations remain valid even when the original business justification has disappeared. Once that happens at scale, recertification becomes less effective because reviewers are looking at stale records rather than current business need.
Practical implication: Tie subscription review to entitlement review so dormant apps cannot keep dormant access alive.
SaaS management as lifecycle control
The article frames SaaS management as a control layer for a much broader lifecycle issue. That is the right framing. Joiner, mover, and leaver workflows do not stop at human onboarding and offboarding. They also apply to the app itself: who requested it, who owns it, who approves renewal, and who removes it when it is no longer needed. Without that lifecycle, organisations may reduce spend in one quarter while quietly preserving unnecessary access paths for years.
Practical implication: Build subscription offboarding into lifecycle governance instead of handling it as an ad hoc cost-saving exercise.
NHI Mgmt Group analysis
Subscription sprawl is an identity governance failure before it is a finance problem: once SaaS procurement outpaces ownership, the organisation loses track of which applications still have valid users, integrations, and business justification. That creates a governance gap that sits between procurement, IAM, and security operations. The practitioner conclusion is simple: if you cannot inventory the app, you cannot govern the access it creates.
Shadow subscriptions create entitlement residue: unused licences rarely stay harmless, because the accounts and permissions attached to them often outlive the reason they were issued. That residue distorts recertification, weakens offboarding, and leaves stale access available in systems nobody is actively watching. The practical implication is that subscription cleanup has to be treated as access cleanup.
Shadow subscriptions are a precursor to shadow identities: when no one owns renewal, offboarding, or access review, the subscription itself becomes the forgotten object and the attached identity becomes the unmanaged one. This is the named concept that matters here: shadow subscription drift. It captures the point where procurement drift turns into identity drift, and practitioner control must move upstream.
The SaaS lifecycle must be governed like any other identity lifecycle: joiner, mover, and leaver discipline does not apply only to people. It also applies to the applications, entitlements, and integrations they rely on. That means the control objective is not merely reducing app count, but ensuring every subscription has a clear owner, a defined review cycle, and a removal path. The practitioner conclusion is to govern app lifecycle with the same seriousness as user lifecycle.
What this signals
Shadow subscription drift: the important governance signal is not merely unused software but the point where no one can explain why the subscription still exists, who owns it, or which access paths it still maintains. Once that state appears, IAM and procurement stop seeing the same asset, and lifecycle control fragments.
SaaS programmes should be designed so that renewal, review, and retirement are all tied back to the same ownership record. Otherwise, entitlement cleanup becomes an afterthought and dormant applications continue to behave like live access surfaces.
For practitioners
- Map subscriptions to business owners Create a live inventory that ties each SaaS app to a named owner, renewal date, user population, and downstream integrations. Without ownership, dormant tools will survive renewal cycles and remain outside normal access governance.
- Review dormant subscriptions with access attached Identify licences that have not been used for a defined period and check whether accounts, roles, and API connections are still active. Remove the app if the business need has ended, not just the licence.
- Fold SaaS cleanup into offboarding Add subscription removal to leaver and project-end workflows so app access does not persist after the team or use case disappears. Treat app retirement as part of the same governance motion as account deprovisioning.
- Track duplicate tools by function Group subscriptions by business function, then compare usage and ownership to find overlapping tools that create unnecessary access paths and spend. Replace spreadsheet tracking with a repeatable review process that security and procurement can both audit.
Key takeaways
- SaaS sprawl becomes an identity issue when subscriptions carry accounts, permissions, and integrations that outlast their business purpose.
- The article's evidence is that more than 30% of SaaS spend is wasted each year, which aligns cost leakage with governance leakage.
- The practical control is not just licence cleanup but subscription lifecycle governance that links ownership, review, and offboarding.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Forgotten subscriptions persist because app and account offboarding is not completed. |
| NHI-05 — Overprivileged NHI | Unused apps often keep permissions and integrations that no longer match business need. | |
| NHI-09 — NHI Reuse | Duplicate subscriptions and repeated tools create repeated identity and access sprawl. | |
| Recommendation — Add SaaS retirement to offboarding so abandoned subscriptions cannot retain active access. Review subscription entitlements for excess access and remove privileges tied to dormant apps. Consolidate duplicate SaaS services and map repeated access paths back to one governed owner. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The issue is entitlement governance across SaaS apps, not only cost control. |
| Recommendation — Apply entitlement review controls to SaaS apps so unused access is removed on a defined cadence. | ||
| CIS Controls v8 | CIS-5 — Account Management | SaaS sprawl creates unmanaged accounts that outlive their purpose. |
| Recommendation — Inventory SaaS accounts and remove dormant access as part of routine account management. | ||
Key terms
- SaaS Sprawl: SaaS sprawl is the uncontrolled spread of software-as-a-service applications across teams and business units. It creates fragmented ownership, duplicated functionality, and weak visibility into who can access what. For IAM and NHI teams, the main risk is not only cost but persistent entitlements that outlive business need.
- Shadow Subscription: A shadow subscription is a paid application instance that continues running without clear ownership, usage, or renewal justification. It becomes a governance problem when the subscription still carries active accounts, permissions, or integrations that no one is actively reviewing.
- Entitlement Residue: Entitlement residue is the leftover access, integrations, or credentials that remain after an application is no longer actively needed. It is a lifecycle failure condition where business value has dropped away, but technical access and contractual status have not been cleaned up.
- Subscription Lifecycle: The subscription lifecycle is the ongoing state management of a recurring billing commitment that continues until it is actively cancelled. In practice, it covers start date, renewal behaviour, active or cancelled status, and how quantity and cost are kept aligned with real vendor billing over time.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org