By NHI Mgmt Group Editorial TeamBased on 1Password: “Five things successful IT teams get right about SaaS management” (January 16, 2026)

TL;DR: SaaS sprawl starts with fast self-service adoption and ends with hidden access, unused licenses, and audit gaps, according to 1Password. The governance problem is not discovery alone, but the lack of repeatable lifecycle controls for onboarding, offboarding, access reviews, and renewals across unmanaged apps.


At a glance

What this is: This is an analysis of how SaaS sprawl becomes an identity governance problem when discovery, offboarding, access reviews, and renewals are not tied to repeatable control.

Why it matters: It matters because unmanaged SaaS creates hidden access, stale entitlements, and audit blind spots that identity, IGA, and SaaS operations teams must govern together.


Context

SaaS sprawl is a governance problem because apps are now easy to create and hard to retire. When employees self-serve new tools faster than IT can track them, the identity layer becomes fragmented across SSO, direct logins, OAuth grants, and unmanaged vendor accounts.

In practical terms, the question is no longer whether an app exists. It is whether the organisation can prove who has access, who still needs it, and what happens to the account, license, and stored data when the requester moves on.

For IAM and IGA teams, this pushes SaaS management beyond discovery into lifecycle control. Without that shift, shadow IT becomes shadow access, shadow spend, and eventually shadow audit risk.


Key questions

Q: What breaks when SaaS sprawl is treated as a discovery problem instead of a governance problem?

A: Discovery alone cannot answer who owns an app, who still has access, or what happens to licenses and data when people move on. The failure is that the organisation ends up with inventory without lifecycle control, which creates hidden access, wasted spend, and audit gaps across the SaaS estate.

Q: Why do unmanaged SaaS apps create access risk even when SSO is in place?

A: Because SSO only governs the apps it covers. Employees can still use browser tools, local accounts, and OAuth-linked services outside federation, which leaves access invisible to standard identity reporting. The risk is not the absence of authentication, but the absence of complete lifecycle control over what users can actually reach.

Q: How do teams know whether SaaS access reviews are actually working?

A: Look for reduction in orphaned accounts, faster revocation after role change, and fewer exceptions repeated across successive review cycles. If the same overprivileged access returns every quarter, the review process is documenting risk rather than removing it. Effective reviews change the entitlement baseline, not just the spreadsheet.

Q: What is the difference between SaaS management and SaaS discovery?

A: SaaS discovery finds applications. SaaS management adds ownership, access context, offboarding, review, and renewal control. In practice, discovery is an input to governance, while management is the repeatable process that keeps the app, the entitlement, and the spend aligned.


Technical breakdown

Why SaaS discovery is not the same as governance

Discovery tells you an app exists. Governance tells you who is using it, how access was granted, whether it is redundant, and whether it should remain in the portfolio. In SaaS environments, logs, expense reports, and SSO visibility often provide partial discovery, but they do not establish lifecycle control. A real governance process turns each newly found app into an owned record with context, approval, and a path to manage or retire it. That distinction matters because the security issue is not the app list itself. The issue is the unmanaged identity relationship behind each subscription.

Practical implication: treat discovery as intake to an access and ownership workflow, not as the end state.

How offboarding fails when SSO is the only control

Disabling SSO access only covers applications that actually sit behind the identity provider. Many SaaS apps also have native licenses, OAuth tokens, shared files, calendars, and app-specific admin roles that survive the employee departure unless they are explicitly revoked. That creates a long tail of lingering access and data custody after offboarding should be complete. In governance terms, offboarding is not a single action. It is the coordinated retirement of every access path and every resource relationship attached to the departed user, including those outside the SSO boundary.

Practical implication: verify offboarding at the app layer, not just at the SSO or IdP layer.

Why access reviews and renewals need usage context

Manual access reviews usually fail because they rely on static exports, stale spreadsheets, and deadline-driven sign-off. By the time reviewers see the list, roles have changed, former users may still be present, and usage data is missing from the decision. The same pattern shows up in renewals: without usage and entitlement context, teams pay for inactive licenses or preserve duplicate tools because nobody can compare actual consumption to contract state. The control problem is not visibility alone. It is the lack of repeatable review and renewal decisions tied to real usage.

Practical implication: couple entitlement review with usage and contract data so recertification and renewal actions are evidence-based.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

SaaS sprawl is an identity governance failure before it is a software management problem. The article shows that apps proliferate when business speed outruns lifecycle control, and that is an IGA issue as much as a procurement issue. Discovery without ownership, review, and retirement simply creates a larger inventory of unmanaged entitlements. Practitioners should treat SaaS sprawl as evidence that identity governance has not been extended far enough into the application perimeter.

Shadow IT becomes shadow access when account lifecycle is not tied to application lifecycle. The article’s core point is that SaaS access does not end when SSO access ends. Native app accounts, OAuth grants, and shared assets can outlive the user relationship unless the organisation has repeatable offboarding across the full SaaS estate. The implication is that access governance must be app-aware, not IdP-only, or offboarding will remain incomplete.

Hidden spend is a security signal, not just a finance problem. Unused licenses, duplicate tools, and forgotten subscriptions show that entitlement management is disconnected from actual use. That disconnect matters because the same blind spots that waste budget also hide dormant access paths and stale ownership. Teams that cannot reconcile usage, ownership, and renewal state are already operating with weak control over SaaS identity risk.

Repeatable lifecycle controls matter more than periodic audits. The article makes clear that annual reviews and manual spreadsheets cannot keep up with self-service adoption. SaaS governance needs continuous discovery, continuous review, and continuous renewal decisions because the environment changes too quickly for episodic control. The practical conclusion is straightforward: if the process is not repeatable, it is not governance.

Unified SaaS governance is now part of identity programme design. This topic sits at the intersection of IAM, IGA, and SaaS operations because access, ownership, and spend all move together. NIST CSF access control and governance concepts align here, but the operational reality is even more specific: organisations need one source of truth for entitlement, usage, and offboarding across managed and unmanaged apps. Teams should design SaaS control planes as extensions of identity governance, not as isolated admin workflows.

From our research library:

What this signals

Lifecycle control is the missing layer in most SaaS programmes. Organisations can discover apps through SSO logs, expense reports, and audits, but without repeatable onboarding, offboarding, review, and renewal controls, those apps remain operationally unmanaged. The governance lesson is that visibility only matters when it triggers a decision and a recorded ownership path.

Shadow IT is becoming a lifecycle problem, not just a visibility problem. Once users can create tools faster than IT can absorb them, the control point shifts from enumeration to continuous entitlement management. Teams should design SaaS governance so every app enters a managed state with clear ownership, access context, and retirement criteria.

Renewal governance now belongs in the identity conversation. When contract state, usage state, and access state are isolated, organisations overbuy licenses and preserve inactive access. The practical signal is simple: if procurement and IAM are not working from the same SaaS record, the programme is already losing control of the portfolio.


For practitioners

  • Build a shadow SaaS intake workflow Route every newly discovered app into a review queue that captures owner, user population, access method, business purpose, and retirement date before it becomes normalised.
  • Extend offboarding beyond the IdP Revoke app-native accounts, OAuth grants, licenses, and shared resource ownership in the same offboarding motion so departed users do not leave behind active access.
  • Centralise access reviews across managed and unmanaged apps Run review cycles with role, department, and risk context, and require reviewers to act on in-line remediation rather than exporting lists into spreadsheets.
  • Tie renewal decisions to usage evidence Compare active logins, license tiers, and contract renewals so procurement only extends tools that show current value and remove seats that no longer map to use.

Key takeaways

  • SaaS sprawl is what happens when adoption is easy but lifecycle governance is fragmented across tools, teams, and data sources.
  • The article ties unmanaged apps to hidden access, unused licenses, and audit exposure, which makes the issue operational as well as financial.
  • The strongest control response is repeatable lifecycle management that connects discovery, offboarding, access reviews, and renewals to one governed process.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centres on access and ownership lingering after users leave SaaS apps.
NHI-03 — Vulnerable Third-Party NHIUnmanaged SaaS apps and external services create third-party identity exposure outside SSO.
NHI-05 — Overprivileged NHIThe article highlights lingering access, redundant tools, and permissions that outlive need.
Recommendation — Map SaaS offboarding to NHI-01 and revoke app-native access, licenses, and ownership together. Inventory third-party SaaS identities and track who can still authenticate outside the IdP. Review SaaS entitlements for overprivilege and remove access that no longer maps to business use.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing access across a sprawl of apps and identities.
Recommendation — Apply PR.AA-05 to reconcile SaaS entitlements with current roles and business need.
CIS Controls v8CIS-5 — Account ManagementSaaS sprawl exposes stale accounts and weak lifecycle control across many applications.
Recommendation — Use CIS-5 to centralise account lifecycle control and remove dormant SaaS access.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeUnused SaaS access and role drift indicate privilege is persisting beyond need.
Recommendation — Enforce AC-6 so SaaS users keep only the minimum access required for current work.

Key terms

  • SaaS Sprawl: SaaS sprawl is the uncontrolled spread of software-as-a-service applications across teams and business units. It creates fragmented ownership, duplicated functionality, and weak visibility into who can access what. For IAM and NHI teams, the main risk is not only cost but persistent entitlements that outlive business need.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
  • SaaS offboarding: The process of removing a departing user from software access while also closing the related account, subscription, and data-handling obligations. In mature programmes, it includes license recovery, file transfer, inbox ownership changes, and evidence that the app lifecycle has ended cleanly.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org