TL;DR: Choosing a SAM tool still comes down to visibility, license optimisation, integration, vendor management, and risk controls, with KuppingerCole cited in the source as backing Zluri’s SaaS discovery claims. The deeper issue is that software governance now overlaps with identity governance, because app inventory without user and access context leaves security and compliance decisions incomplete.
At a glance
What this is: This article explains five questions to ask when selecting a SAM tool and argues that SaaS visibility, licensing, integrations, vendor management, and risk controls only work when paired with identity and access context.
Why it matters: IAM and SaaS governance teams need more than inventory, because app discovery without user, entitlement, and risk context leaves recertification, offboarding, and compliance decisions partially blind.
By the numbers:
- Zluri says it supports over 300 applications and grows monthly.
- The article says one example of SaaS license underuse is 100 licenses purchased and 75 used.
Context
Software asset management for SaaS is no longer just a procurement and licensing exercise. In practice, the control problem is whether an organisation can see its software estate, understand who is using each application, and connect that use back to risk, compliance, and access governance.
This article frames SAM tool selection around inventory, licence management, integrations, vendor management, and risk scoring. Those are necessary functions, but they become incomplete when the programme cannot answer the identity questions that matter to IAM, IGA, and SaaS governance teams.
The strongest signal in the piece is that SaaS management and identity governance are converging. That makes the selection criteria broader than tooling features and narrower than general IT asset management.
Key questions
Q: How should teams govern SaaS access when the application estate keeps changing?
A: Start with discovery, not policy. Teams need a trusted inventory of SaaS applications, owners, users, and entitlements before they can govern access consistently. Once that data exists, connect onboarding, offboarding, and access reviews to the same source so changes in employment or role translate into changes in access without manual rework.
Q: Why do SaaS licences and usage counts not tell the full governance story?
A: Because a seat count shows consumption, not whether access is still justified, approved, or properly offboarded. An underused licence may be a cost issue, but an external user or dormant account can also be a lifecycle and compliance issue. Teams need both licence management and entitlement review to make a sound decision.
Q: What breaks when SaaS management tools do not include user context?
A: Access reviews, offboarding, and risk decisions become partial because the organisation can see the application but not the identities behind it. That creates a visibility illusion: the estate looks controlled, yet admins still lack the link between apps, users, and business justification. The result is weaker compliance and slower remediation.
A: Prioritise inventory enough to know what exists, but move quickly to access review once the app list is credible. Licence optimisation saves money, yet access review tells you whether the right identities still need the access they hold. In practice, review and offboarding matter more than seat efficiency when risk is the concern.
Technical breakdown
Why SaaS discovery is only the first control layer
SaaS discovery builds the inventory, but inventory alone does not establish governance. A complete view needs to connect applications to users, licences, contracts, and authorised access paths, otherwise teams only know that a service exists, not whether it is appropriately used. Zluri’s article highlights discovery methods and app catalogue scale, which reflects the operational reality that SaaS estates are fragmented across SSO, admin panels, and shadow usage. The technical issue is not just finding apps, but normalising their identity and usage signals into a control plane that can support compliance and optimisation.
Practical implication: Treat SaaS discovery as an input to governance, not the governance decision itself.
How licence management differs from entitlement governance
Licence management tracks how many seats exist, how many are consumed, and when renewals occur. Entitlement governance asks whether the right identities hold the right access for the right reason, which includes employees and external users such as freelancers or consultants. The article shows why this distinction matters by discussing licences per user, licence type, payment method, and external users. In practice, a seat can be optimised financially while still being mis-governed from an access perspective if no one checks the linked identity lifecycle or business justification.
Practical implication: Use licence data to inform access governance, but do not mistake usage counts for entitlement review.
Why integrations and risk scoring matter to identity governance
Integrations with ITSM, CMDB, SSO, and directory data turn SAM from a static catalogue into an operational control surface. That matters because SaaS risk is created by the combination of app exposure, user permissions, shared data, and vendor posture. The article’s risk scoring approach combines events, data shared, compliance, and external security checks, which is a useful reminder that governance must blend operational telemetry with access context. Without that linkage, teams can detect that an app is risky but still lack the authority model needed to act on it consistently.
Practical implication: Connect SAM outputs to identity sources so risk decisions can drive access and offboarding actions.
Threat narrative
Attacker objective: Exploit gaps in SaaS visibility and identity linkage to leave access, compliance, and risk controls operating on incomplete information.
- Entry occurs when SaaS applications are discovered through multiple sources, including SSO, directory data, and app libraries, but the identity context behind each connection remains incomplete.
- Escalation happens when licence and app usage data are treated as sufficient proof of control, even though external users, shared access, and hidden app connections can remain outside the governance view.
- Impact follows when compliance and risk decisions are made on partial inventory data, leaving organisations with blind spots in access reviews, vendor oversight, and SaaS risk prioritisation.
Breaches seen in the wild
- SalesBleed Salesforce Agentforce 2026: Three fixed Agentforce flaws let poisoned web leads make AI agents leak CRM data with zero clicks and send phishing under the agent's identity.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
SaaS management has become an identity governance problem: A tool that inventories applications but cannot tie them back to users, external accounts, and entitlements leaves the programme with only partial control. The article correctly points toward visibility, but the deeper shift is that software governance now depends on identity context to explain risk, ownership, and access intent. Practitioners should judge SAM tools by whether they can support governance decisions, not just asset counts.
License optimisation is not the same as access governance: Counting consumed seats and tracking renewals reduces waste, but it does not prove that access is appropriate, current, or revocable. The article’s examples show why external users matter here, because a consultant with a valid seat can still be a governance problem if lifecycle and approval logic are absent. Teams should separate financial efficiency from entitlement assurance.
Inventory without lifecycle linkage creates a visibility illusion: The governance assumption that software inventory equals software control breaks once SaaS access spans SSO, local admin panels, and unmanaged sharing. That assumption fails because applications can remain discoverable while the identities using them change faster than the inventory does. The implication is that teams need a control model that tracks ownership and offboarding alongside discovery.
Risk scoring only works when it includes identity and usage signals: Zluri’s article treats events, data sharing, compliance, and security probes as risk inputs, which is directionally correct but still incomplete without identity authority. A risk score that ignores who can act inside the application can understate exposure, especially where privileged or external users are involved. Practitioners should expect SaaS risk scoring to feed access review and offboarding workflows, not sit beside them as a separate dashboard.
One named concept emerges here: SaaS visibility gap: This is the gap between knowing an app exists and knowing who controls it, who uses it, and whether that access is still justified. It is the central reason SAM and IAM are converging in the same operating model. Teams that close this gap gain a better basis for compliance, vendor oversight, and identity lifecycle decisions.
From our research library:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
- Read next: IAM and IGA Basics
What this signals
SaaS visibility gap: The real governance problem is not whether a platform can find applications, but whether it can preserve the identity context needed to decide if access is still justified. Once SaaS discovery is disconnected from identity lifecycle and approval history, the programme starts optimising assets while losing control over who can act inside them.
For IAM and IGA teams, that means SaaS management should be treated as an upstream signal in the access governance workflow, not a parallel IT operations dashboard. The practical shift is to use discovery outputs to drive review, offboarding, and risk remediation rather than stopping at catalogue completeness.
For practitioners
- Map SaaS inventory to identity sources Connect discovery, SSO, directory data, and app catalogue outputs so each application can be tied to accountable users and administrators.
- Separate licence efficiency from entitlement review Use seat counts and renewal dates for cost control, then run access reviews on the identities actually holding those licences.
- Include external users in governance scope Track freelancers, consultants, and other non-employees in the same control process as employees so shared SaaS access is not missed.
- Tie risk scores to operational response Route high-risk SaaS findings into offboarding, vendor review, and access recertification workflows instead of leaving them in a standalone dashboard.
Key takeaways
- SaaS management becomes a governance issue when inventory data is disconnected from identity and access context.
- The article shows that licence counts, app discovery, and vendor records are useful, but they do not replace entitlement assurance.
- Teams should connect SAM outputs to IAM and IGA processes so access reviews, offboarding, and risk scoring happen on the same evidence base.
Key terms
- SaaS Visibility: SaaS visibility is the ability to identify which software services, tenants, and accounts exist in an environment and who controls them. In identity governance, it is the prerequisite for review, offboarding, and cost control because hidden applications cannot be certified or revoked reliably.
- License Optimisation: License optimisation is the process of matching software entitlements to actual use so organisations do not pay for access they no longer need. In identity terms, it is a governance function because entitlement reduction often requires review, downgrade, or deprovisioning decisions.
- Entitlement review: A governance process that checks whether users, service accounts or systems still need their access. For modern identity programmes, the limitation is timing: if reviews happen too late or too rarely, access may already have been misused before the review occurs.
- Delegated SaaS access: Delegated SaaS access is permission granted to one application, connector, or service account to act on behalf of another identity or data owner. It is often necessary for automation, but it becomes a governance risk when the grant is broad, stale, or poorly owned.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org