By NHI Mgmt Group Editorial TeamBased on Zluri: “Top 10 Software Asset Management Service Providers in 2026” (March 12, 2026)

TL;DR: Software asset management service providers now sit across discovery, licence optimisation, monitoring, procurement and retirement for sprawling SaaS estates, according to Zluri, but the governance lesson is that usage, contractual ownership and access ownership are increasingly misaligned. That makes software lifecycle control an identity problem as much as a cost problem: ungoverned apps, stale licences and shadow IT all expand access surface and weaken accountability.


At a glance

What this is: This article surveys ten software asset management service providers and shows that lifecycle, compliance, and cost controls are becoming inseparable from software discovery and retirement.

Why it matters: For IAM, NHI, and governance teams, the important shift is that software ownership, application access, and SaaS sprawl now need to be managed as one lifecycle problem.


Context

Software asset management is the discipline of discovering, governing, optimising, and retiring software across its lifecycle. In this article, that lifecycle is presented as a service layer around SaaS estate control, not just a procurement function, and that matters because software sprawl now affects who can use what as much as what an organisation pays for.

The identity governance connection is direct: software sprawl creates unmanaged application access, shadow IT, and weak ownership between procurement, usage, and account lifecycle. When organisations outsource SAM, they are often outsourcing part of the access surface too, which is why the control problem spans software inventory, user entitlement visibility, and offboarding discipline.


Key questions

Q: How should teams govern SaaS access when the application estate keeps changing?

A: Start with discovery, not policy. Teams need a trusted inventory of SaaS applications, owners, users, and entitlements before they can govern access consistently. Once that data exists, connect onboarding, offboarding, and access reviews to the same source so changes in employment or role translate into changes in access without manual rework.

Q: Why do software asset management tools matter to IAM and IGA programmes?

A: They matter because software inventory only becomes usable when it informs entitlement decisions. IAM and IGA teams need to know which apps are live, who owns them, which users still need them, and when access should be removed. Without that linkage, software asset management becomes reporting, not governance.

Q: What breaks when software retirement is not tied to access offboarding?

A: The application may disappear while its credentials, integrations, or delegated access remain live. That leaves dormant identity paths in place after the asset is supposedly gone, which is a common governance failure in both SaaS and NHI environments.

Q: Should organisations prioritise software discovery or licence optimisation first?

A: Discovery should come first because licence optimisation depends on knowing what is actually present. If the inventory is incomplete, cost saving efforts will miss shadow IT, duplicate applications, and hidden entitlements, which means the organisation optimises the wrong estate.


Technical breakdown

Why software discovery now overlaps with identity governance

Software discovery is no longer just an inventory exercise. In SaaS-heavy environments, the systems that reveal installed software, subscriptions, and usage also expose where identity data sits, who is actively using an application, and where shadow IT has bypassed formal governance. That makes discovery a prerequisite for access governance because you cannot review entitlements you cannot see. The article’s service models combine SSO, API integrations, expense data, and endpoint signals for that reason: they create a more complete picture of application ownership and consumption.

Practical implication: treat software discovery outputs as an entitlement inventory input, not only a procurement report.

How licence optimisation becomes entitlement rationalisation

Licence optimisation is often described as cost control, but in practice it is also access rationalisation. If a platform shows who uses an application, how many licences are owned, and where usage is low, it can expose dormant accounts, over-assigned tiers, and mismatched entitlement models. That is an identity governance problem because unused software still carries access pathways, contract obligations, and support exposure. Optimisation therefore becomes a control on both spending and privilege accumulation across the SaaS estate.

Practical implication: pair licence optimisation reviews with entitlement cleanup and application owner validation.

Why software retirement is an offboarding problem

Retiring software is not the same as deleting a subscription. Retirement requires the removal of active users, contractual obligations, and residual access paths that may persist in SSO, vendor portals, and adjacent integrations. The article repeatedly ties SAM services to retirement, renewal, and vendor management because software exits are where ownership often breaks down. For identity teams, this is the same governance failure seen in other lifecycle controls: access survives after the business no longer needs the application. That is where SaaS sprawl becomes a control gap rather than just a spending problem.

Practical implication: build software retirement into access offboarding and recertification workflows.


Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Software asset management is now part of identity governance, not a separate cost function. The article shows that discovery, licence use, renewal, and retirement all depend on knowing which users and workflows actually touch an application. That means SAM is increasingly a control plane for access visibility, not merely a procurement support function. IAM leaders should treat SaaS ownership as part of the identity estate.

Software sprawl creates governance debt by hiding who is responsible for what. Once application ownership, contract ownership, and access ownership diverge, no single team can reliably certify need or remove access. The result is stale applications, redundant licences, and shadow IT that survives because the business cannot prove what should be removed. Practitioners should view this as lifecycle fragmentation, not just inefficiency.

Lifecycle control is the named concept that ties this market together. The article’s ten providers all orbit the same problem: software does not become governable at purchase time, it becomes governable only when discovery, usage, renewal, and retirement are linked to accountable owners. That is the point where software asset management becomes an identity lifecycle discipline. Teams should align SAM with joiner-mover-leaver governance and application ownership.

Shadow IT is an identity issue when it enters the SaaS estate. The article’s repeated emphasis on discovery, usage monitoring, and self-service requests shows that unmanaged app adoption is not only a licensing concern. It also creates unmanaged access pathways outside normal approval and review cycles. Security teams should treat unauthorised software as unauthorised access in waiting.

The market is moving toward lifecycle governance over point-in-time visibility. Several service models described here combine monitoring, renewal, procurement, and vendor management because isolated reports do not fix the control gap. The direction of travel is toward continuous software governance tied to entitlement and contractual state. Practitioners should expect higher pressure to unify SAM with identity governance and compliance reporting.

What this signals

Lifecycle control is the useful lens here: software asset management only becomes governable when discovery, renewals, entitlement review, and retirement operate as one process. For IAM teams, that means SaaS ownership should be folded into the same control model used for other access-bearing assets.

Shadow IT becomes more dangerous when it has live identity bindings: an unapproved application is not just an expense line, it is an unmanaged access path with its own accounts, roles, and offboarding requirements. Practitioners should expect pressure to bring SaaS discovery into access governance reporting.

Software asset management and identity governance are converging around the same question: who is accountable for application access over time? When that answer is unclear, licence optimisation, audit readiness, and offboarding all weaken together.


For practitioners

  • Map software ownership to application ownership Assign a named business and technical owner for each SaaS application, then require that owner to participate in access review and retirement decisions. Without that ownership link, licence data and access data will continue to drift apart.
  • Use discovery data to find hidden access paths Combine SSO, expense, API, and endpoint discovery signals to identify software that exists outside approved procurement or IAM workflows. Treat any unapproved application as a potential governance gap until ownership and access are confirmed.
  • Tie renewals to entitlement recertification Review user assignments, licence tiers, and renewal dates together so that dormant subscriptions are removed before contract renewal and over-assigned entitlements are corrected at the same time.
  • Fold software retirement into offboarding When an application is retired, revoke access in SSO, remove vendor logins, and validate that any linked integrations or service accounts are also removed from the surrounding estate.
  • Track shadow IT as an access-control signal Escalate unapproved SaaS discovery findings to IAM and security teams, not only procurement, so that unsanctioned applications are reviewed for access, data exposure, and ownership before they spread.

Key takeaways

  • Software asset management now sits inside the identity governance problem because software discovery, access visibility, and application ownership are inseparable in SaaS-heavy estates.
  • The core control gap is lifecycle fragmentation: organisations can know what they bought without knowing who still uses it or who is accountable for removing it.
  • IAM teams should link discovery, renewal, recertification, and retirement so that application access cannot outlive business need.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while CSA Cloud Controls Matrix, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity and Access ManagementSaaS asset management here is fundamentally about who can access which applications and when.
Recommendation — Use IAM controls to align application ownership, access review, and retirement across the SaaS estate.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on entitlement visibility and lifecycle control for software access.
Recommendation — Review and tighten access permissions as part of every software discovery and renewal cycle.
CIS Controls v8CIS-5 — Account ManagementSoftware retirement and unused licences often mask stale accounts and unmanaged access paths.
Recommendation — Reconcile accounts tied to SaaS applications and remove access that no longer has a business owner.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article repeatedly points to software retirement and vendor lifecycle gaps that mirror offboarding failures.
Recommendation — Offboard SaaS applications and related access together so residual credentials do not outlive the business need.

Key terms

  • Software Asset Management: Software asset management is the process of tracking, optimising, and governing software usage, licences, and contracts across an organisation. In modern SaaS environments, it increasingly depends on identity data because software value and software risk are both defined by who or what can use the application.
  • SaaS Sprawl: SaaS sprawl is the uncontrolled spread of software-as-a-service applications across teams and business units. It creates fragmented ownership, duplicated functionality, and weak visibility into who can access what. For IAM and NHI teams, the main risk is not only cost but persistent entitlements that outlive business need.
  • Application Ownership: Application ownership is the assignment of accountability for approving, funding, governing, and retiring a software application. Effective ownership links budget responsibility to access responsibility, which is essential when renewals, offboarding, and access reviews need a clear decision-maker.
  • Lifecycle Governance: Lifecycle governance is the set of controls that cover creation, assignment, review, rotation, and retirement of identities and credentials. For NHIs, it is the difference between a temporary automation asset and a persistent access risk. Strong lifecycle governance keeps ownership and expiry tied to actual business use.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org