TL;DR: SaaS sprawl creates security, compliance, and cost risk when employees adopt apps outside IT visibility, according to Zluri. Automation helps discovery and inventory management, but it also exposes the deeper identity governance problem: access, lifecycle, and renewal control still fail when app usage is fragmented.
At a glance
What this is: This article argues that SaaS sprawl is not just an inventory problem, but an identity governance problem where unmanaged app adoption, renewal drift, and weak lifecycle control create security and compliance exposure.
Why it matters: IAM and IGA teams need to treat SaaS discovery as the starting point, because app visibility without access governance, offboarding, and renewal control leaves the real risk untouched.
By the numbers:
- Zluri can discover 100% of SaaS apps used within an organization through its extensive library of 225,000+ apps.
- Zluri directly integrates with around 300 SaaS applications to surface access levels, permission data, and audit logs.
Context
SaaS sprawl is the accumulation of too many overlapping applications across an organisation’s environment, often because users adopt tools without central approval. In identity terms, the problem is not only discovery. It is whether app access, user provisioning, license ownership, and deprovisioning are governed as one lifecycle.
The article connects sprawl to security breaches, compliance violations, and overspending, but its practical point is narrower than the marketing language suggests. The identity gap appears when IT can see apps but still cannot reliably control who gets access, who owns renewal decisions, and who removes access when the app is abandoned.
For IAM and IGA teams, the issue is a governance model built for sanctioned systems trying to absorb a fragmented SaaS estate created by Shadow IT. That is typical of modern SaaS environments, not an edge case.
Key questions
Q: What breaks when employees adopt apps outside IT control?
A: Governance breaks when app adoption outpaces discovery, approval, and offboarding. Security teams lose a reliable view of who has access, which accounts exist, and which tools support critical work. The result is not just policy noncompliance. It is identity drift, where the organisation governs one stack while employees operate another.
Q: Why does SaaS sprawl make governance and compliance harder?
A: SaaS sprawl creates multiple independent storage and access decisions across departments, which breaks visibility and weakens auditability. Compliance gets harder because teams can no longer prove where regulated data lives or who can access it. The control problem is not volume alone. It is the lack of a single governance boundary for data and identity.
Q: How can teams tell whether SaaS governance is actually working?
A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow. If the platform can only report on SaaS usage but cannot drive deprovisioning or entitlement review, governance is still fragmented.
Q: Should organisations prioritise app discovery or lifecycle controls first?
A: Discovery comes first only if the organisation cannot see its current SaaS estate at all. But discovery by itself does not reduce risk, because the real exposure comes from unmanaged access, duplicate tools, and renewal drift. As soon as visibility exists, lifecycle controls should be prioritised so governance can act on what discovery finds.
Technical breakdown
Why SaaS discovery is not the same as governance
Discovery tells you which applications exist, but governance answers who can use them, under what approval path, and for how long. In SaaS sprawl, employees can create accounts directly with a provider, bypassing procurement and central identity controls. That produces an inventory problem first, then an entitlement problem, then a lifecycle problem. If the organisation only discovers apps after purchase or after user adoption, the identity function is always reacting to a live estate rather than shaping it. The result is fragmented control over access, renewals, and offboarding across a large application surface.
Practical implication: Treat discovery as an input to governance, not as the governance control itself.
How fragmented SaaS usage breaks access and deprovisioning
When app adoption is decentralised, access is often granted through local accounts, ad hoc SSO connections, or direct vendor signup flows rather than through a standard identity workflow. That makes provisioning inconsistent and deprovisioning unreliable, because the organisation may not even know which account should be removed. The article’s mention of automated provisioning and de-provisioning points to this exact gap: the app stack has to be connected to identity lifecycle processes or access persists beyond business need. In practice, sprawl turns offboarding into a partial exercise unless app ownership and account ownership are linked.
Practical implication: Map every SaaS app to an accountable owner and a revocation path before the next access review cycle.
Why renewals and duplicate apps are identity signals, not just finance signals
Renewal management and duplicate app cleanup are often treated as cost optimisation, but in SaaS governance they are also identity controls. Duplicate tools create parallel access paths, which increase the number of identities, tokens, and permissions that must be managed. Auto-renewal of unused apps extends that exposure window and preserves accounts that no one actively governs. The article’s DUAAS framing, duplicate apps, unused apps, abandoned apps, auto-renewal, and suitable license, is really a lifecycle diagnostic: it identifies where access, usage, and ownership have drifted apart. That is why licence review and app rationalisation belong in the identity programme, not only in procurement.
Practical implication: Use renewal and duplicate-app review to surface orphaned access and reduce unmanaged identity sprawl.
Threat narrative
Attacker objective: Exploit unmanaged SaaS adoption and weak lifecycle control to gain access, hide usage, and increase the chance of data exposure or operational waste.
- Entry happens when employees sign up for SaaS applications without consulting IT, creating shadow IT accounts outside the sanctioned onboarding path.
- Credential and access sprawl follow when those apps are integrated inconsistently, leaving permissions, licence state, and audit visibility fragmented across systems.
- Impact appears as security breaches, compliance violations, and overspending when the organisation cannot reliably track, revoke, or rationalise the SaaS estate.
Breaches seen in the wild
- Millions of Misconfigured Git Servers Leaking Secrets: Nearly 5 million misconfigured Git servers expose sensitive secrets and credentials online.
- Massive Docker Hub Secrets Leak: 10,000+ Docker Hub container images expose hardcoded secrets and authentication keys.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
SaaS sprawl is an identity governance problem before it is an application inventory problem. The article is right to frame discovery and automation as helpful, but those controls only expose the scale of the estate. The real failure is that access, ownership, renewal, and offboarding are no longer governed as one lifecycle. Practitioners should treat uncontrolled app adoption as a governance design flaw, not a visibility gap.
Centralised procurement is necessary, but it is not sufficient without lifecycle enforcement. The article points to procurement discipline, employee training, and automation models, which is directionally correct. Yet the identity issue persists if app approval is centralised but account creation and deprovisioning remain local or manual. The programme implication is that SaaS governance must bind procurement to identity workflows, or Shadow IT simply reappears through unmanaged accounts.
Renewal control is an access-control problem in disguise. Auto-renewal of unused apps does more than waste budget. It preserves dormant access paths, duplicate entitlements, and unresolved ownership. That means licence review should sit alongside access review in the identity operating model, because the same fragmentation that wastes money also expands attack surface.
Shadow IT creates a governance gap that traditional IAM cadence does not fully close. Standard access reviews assume the organisation already knows the app, the owner, and the user population. SaaS sprawl undermines all three assumptions at once. The practical conclusion is that identity teams need continuous SaaS inventory hygiene before recertification can be meaningful.
App rationalisation is a control strategy, not a cleanliness exercise. Removing duplicate or overlapping SaaS tools reduces the number of identity relationships that must be maintained and monitored. That lowers the chance that stale accounts, abandoned apps, or duplicate permissions persist unnoticed. Teams should measure SaaS rationalisation as part of identity risk reduction, not as a one-time consolidation project.
From our research library:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
What this signals
SaaS discovery only becomes useful when it feeds identity governance. Many teams still stop at inventory because that is the easiest metric to report. The stronger control point is whether every discovered app can be tied to an owner, an approval path, and a revocation path before it is allowed to persist in the environment.
Duplicate apps are a governance signal, not just an efficiency issue. When multiple tools provide overlapping functionality, identity teams inherit more accounts, more access paths, and more renewal decisions. Rationalisation therefore belongs in the same programme that manages access reviews and offboarding, because fragmented tooling creates fragmented control.
Renewal automation changes the shape of SaaS risk only if it is linked to access lifecycle management. If auto-renewal is controlled but accounts remain unreviewed, the organisation can still carry dormant access and abandoned apps forward indefinitely. Practitioners should watch for that mismatch in their next SaaS control review.
For practitioners
- Implement centralised SaaS procurement gates Require business justification, owner assignment, and identity integration before any new SaaS purchase or direct signup is approved.
- Automate SaaS inventory and ownership mapping Use discovery feeds from SSO, IDP, finance systems, browser telemetry, and API integrations to keep a current inventory of apps, owners, and active users.
- Tie provisioning to revocation workflows Ensure every SaaS account is created through a tracked workflow and removed through the same identity process when the app is no longer needed.
- Review renewals as part of access governance Use renewal dates, usage data, and license assignment to find abandoned apps, duplicate tools, and accounts that should be offboarded.
- Train employees on Shadow IT risk Explain why unsanctioned SaaS adoption creates fragmented access, audit blind spots, and compliance exposure even when the app seems harmless.
Key takeaways
- SaaS sprawl turns app adoption into an identity governance problem because access, ownership, and offboarding no longer follow one controlled lifecycle.
- The article points to hundreds of SaaS apps in mid-size environments and 100% discovery claims, which shows why manual tracking no longer scales.
- The practical response is to connect discovery, provisioning, renewal, and revocation so Shadow IT does not become permanent access drift.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Shadow IT leaves SaaS accounts active after apps are no longer needed. |
| NHI-05 — Overprivileged NHI | Unmanaged SaaS accounts often carry more access than the business can justify. | |
| Recommendation — Map SaaS offboarding to NHI-01 and revoke abandoned app access through the identity lifecycle. Review SaaS entitlements against NHI-05 and remove excess permissions from shadow apps. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centres on controlling who can access which SaaS apps and for how long. |
| Recommendation — Apply PR.AA-05 to keep SaaS permissions, entitlements, and authorisations tied to governance workflows. | ||
| CIS Controls v8 | CIS-5 — Account Management | SaaS sprawl creates unmanaged accounts that must be inventoried and controlled. |
| Recommendation — Use CIS-5 to inventory SaaS accounts and remove unmanaged access paths as part of account governance. | ||
| MITRE ATT&CK | TA0006; TA0040 — Credential Access; Impact | Shadow IT and unmanaged SaaS accounts increase exposure to credential abuse and downstream impact. |
| Recommendation — Track unmanaged SaaS accounts against TA0006 and TA0040 to prioritise identity exposure reduction. | ||
Key terms
- SaaS Sprawl: SaaS sprawl is the uncontrolled spread of software-as-a-service applications across teams and business units. It creates fragmented ownership, duplicated functionality, and weak visibility into who can access what. For IAM and NHI teams, the main risk is not only cost but persistent entitlements that outlive business need.
- Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
- Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.
- Application rationalisation: The process of reducing overlapping tools, subscriptions, and integrations so the organisation keeps only what it actually needs. For identity teams, it is also a privilege reduction exercise because every removed app should eliminate accounts, tokens, and trust relationships.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org