By NHI Mgmt Group Editorial TeamBased on Zluri: “13 Best Software Asset Management Tools in 2026” (March 20, 2026)

TL;DR: Software asset management tools are positioned to help organisations discover applications, track renewals, optimise license spend, and support onboarding and offboarding, according to Zluri’s review of 13 tools. The deeper issue is that SaaS governance is now an identity problem as much as a procurement problem, because unmanaged app sprawl creates access, compliance, and lifecycle risk.


At a glance

What this is: This is a review of 13 software asset management tools that shows discovery and licence control are necessary, but not sufficient, for SaaS governance.

Why it matters: IAM, IGA, and security teams need to treat SaaS sprawl as an identity lifecycle problem because application ownership, request flow, and revocation determine real control.


Context

Software asset management is the practice of discovering, tracking, optimising, and retiring software across an organisation. In SaaS-heavy environments, that task quickly crosses into identity governance because every application also represents an access path that must be requested, approved, assigned, reviewed, and removed.

The article’s core point is that app inventory by itself is not governance. Once software sprawl grows beyond spreadsheets, the practical questions become who can request apps, who can approve them, how unused licences are reclaimed, and whether offboarding actually revokes access rather than just closing a procurement record.


Key questions

Q: How should IAM and SaaS teams share responsibility for app offboarding?

A: IAM should own the lifecycle logic for access removal, while SaaS operations should supply the usage and contract context that proves whether access is still needed. When those functions stay separate, offboarding becomes inconsistent and accounts survive because no single team sees the full picture.

Q: Why does application discovery alone not solve software governance?

A: Discovery tells you what exists, but it does not tell you who approved it, who owns it, or whether access was ever removed. Governance fails when organisations stop at inventory and renewals. The missing control is lifecycle enforcement, because the real risk sits in the identities attached to the app, not in the list of app names.

Q: Why do SaaS management gaps often turn into access governance problems?

A: Because the same blind spots that hide rogue apps also hide who can use them. If an application enters the environment outside approved discovery paths, the organisation may never review the accounts, tokens, or delegated access that come with it. That turns an inventory gap into a lifecycle and entitlement gap.

Q: How do software asset management and IGA work together in practice?

A: SAM should supply application discovery, usage, and renewal context, while IGA should enforce ownership, approvals, recertification, and removal. Used together, they create a closed loop from request to revocation. Used separately, they leave gaps where applications can be purchased, assigned, and forgotten without a durable governance record.


Technical breakdown

Why SaaS discovery is the foundation of app governance

Modern software asset management depends on discovery because teams cannot govern what they cannot see. In SaaS environments, discovery has to combine signals from SSO, finance and expense systems, APIs, browser extensions, and optional desktop agents to build a usable picture of application use. That visibility is not just about inventory hygiene. It establishes the baseline for licence reconciliation, shadow IT detection, and lifecycle decisions that connect app ownership to identity control.

Practical implication: map every discovery source you rely on and test whether it actually captures unsanctioned SaaS use, not just approved applications.

How onboarding and offboarding become identity controls

The article makes clear that SAM tools increasingly automate request, approval, assignment, and revocation workflows. That matters because onboarding and offboarding are not merely HR events when applications are involved. They are the points where access is granted, reused, removed, or accidentally left behind. In governance terms, software management becomes an extension of IGA: the asset may be a licence, but the control plane is still identity and entitlement lifecycle.

Practical implication: verify that application provisioning and revocation are tied to identity lifecycle events, not handled as separate manual admin tasks.

Why licence optimisation does not equal access governance

Licence optimisation reduces wasted spend, but it does not automatically resolve who should have access, when, or under what approval path. The article repeatedly links savings to usage data, renewal monitoring, and removing unused apps, yet those controls operate on demand and cost, not on authorisation design. That distinction matters because an underused application can still be a high-risk access path, and an overprovisioned one can still look efficient on paper. Governance teams need both financial and entitlement views to understand exposure.

Practical implication: use spend data as a prioritisation signal, but validate access decisions with entitlement and ownership evidence before you retire or renew an app.


NHI Mgmt Group analysis

Software asset management has become a proxy layer for identity governance in SaaS estates. The article shows that the operational value of SAM now depends on whether it can connect discovery, requests, approvals, assignment, and revocation. That is an identity lifecycle problem wearing an asset-management label. Practitioners should stop treating SAM and IGA as separate domains when the control failure emerges in the same application path.

Discovery without lifecycle control creates governance theater. Knowing that an application exists, who pays for it, and when the contract renews does not tell you whether the right identities still have access. The article’s strongest signal is that unmanaged app sprawl creates control gaps at the point of onboarding and offboarding. The practical question is not how many apps you can list, but whether access can be removed as reliably as it is granted.

Shadow IT is now an access problem before it is a procurement problem. The article correctly frames unused or duplicate apps as budget waste, but the deeper issue is that every unmanaged application widens the organisation’s identity surface. Unapproved apps can still carry data, permissions, and delegated access paths. The implication is that SaaS governance must join procurement, security, and IAM around one operational record of application ownership.

Identity request workflows are the control point that SAM tools expose but do not replace. A request, approval, and assignment flow becomes meaningful only when ownership, policy, and revocation are enforced consistently across the stack. That is why a SAM programme that cannot reconcile app inventory with access lifecycle is only partially governing the environment. The practitioner takeaway is to treat workflow quality as the measure of governance maturity, not tool count.

Access review pressure increases as SaaS sprawl fragments accountability. The more applications an organisation accumulates, the harder it becomes to determine who should attest to access, who owns the app, and which identities are still entitled. This is where IGA discipline and SAM discipline intersect. Teams should use application ownership and usage signals to make recertification meaningful instead of ceremonial.

What this signals

SaaS sprawl is the hidden identity layer of software asset management. Once a business has enough applications to need a SAM platform, the operational question is no longer only what was bought or renewed. It is who can request, approve, assign, and revoke access across that app estate, because governance breaks at the lifecycle boundary rather than at the inventory layer.

App discovery needs to feed entitlement governance, not sit beside it. A complete app list still leaves teams blind if ownership, approval, and offboarding are handled outside the same control model. The strongest programmes use discovery to prioritise review, then connect that data to IGA workflows so dormant applications do not remain active by default.


For practitioners

  • Strengthen SaaS discovery coverage Validate that your discovery stack pulls from SSO, finance, APIs, and optional endpoint signals so unsanctioned apps do not stay invisible.
  • Tie app requests to identity lifecycle Ensure approval, assignment, and revocation are triggered by joiner, mover, and leaver events rather than handled as standalone admin work.
  • Separate spend optimisation from access decisions Use licence usage and renewal data to prioritise review, but confirm entitlement ownership before terminating or retaining an application.
  • Create a single owner for each business application Assign accountability for app approval, renewal, and offboarding so dormant applications do not remain active because no team owns the decision.

Key takeaways

  • SAM tools help organisations see and rationalise software spend, but they do not on their own govern the identities that use those applications.
  • The biggest governance gap in SaaS-heavy environments is often the disconnect between app inventory and access lifecycle control.
  • IAM and IGA teams should treat discovery, approvals, and revocation as one operating model if they want software governance to be durable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingUnremoved SaaS access after offboarding is the central lifecycle risk discussed here.
NHI-05 — Overprivileged NHIDuplicate and unused apps often conceal excess access and entitlement sprawl.
Recommendation — Tie app revocation to leaver workflows so SaaS access cannot outlive identity ownership. Review SaaS entitlements for excess access and remove privileges that no longer match business need.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on governing who gets access to SaaS applications and when.
Recommendation — Use PR.AA-05 to align SaaS approvals, entitlements, and removals with defined authorisation rules.
CIS Controls v8CIS-5 — Account ManagementLifecycle control of app access maps directly to account and access governance.
Recommendation — Apply account management controls to track and remove SaaS access when users change role or leave.

Key terms

  • SaaS Discovery: SaaS discovery is the process of identifying all sanctioned and unsanctioned software-as-a-service applications in use across the organisation. It matters because cloud assurance increasingly depends on seeing where apps share data, what permissions they hold, and which identities can reach them.
  • Identity Lifecycle Governance: Identity lifecycle governance is the set of processes that create, change, review, rotate, and revoke access across human and non-human identities. It matters because access risk usually increases when lifecycle events are slow, incomplete, or disconnected from the systems that rely on them.
  • License Optimisation: License optimisation is the process of matching software entitlements to actual use so organisations do not pay for access they no longer need. In identity terms, it is a governance function because entitlement reduction often requires review, downgrade, or deprovisioning decisions.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org