TL;DR: Unsanctioned SaaS apps increasingly sit outside SSO, IAM, and standard deprovisioning, leaving sensitive data, wasted licenses, and compliance gaps behind, according to 1Password. The core problem is not just discovery, but the fact that traditional identity controls were designed for managed apps, not continuously changing shadow IT.
At a glance
What this is: This is an analysis of how unsanctioned SaaS creates governance gaps when apps sit outside SSO, IAM, and standard joiner-leaver processes.
Why it matters: It matters because IAM, IGA, and SaaS governance teams need visibility and offboarding coverage for apps that employees adopt outside approved control paths.
Context
Unsanctioned SaaS becomes a governance problem when software is purchased and used outside IT visibility, because the identity controls that protect managed applications never see the new app in the first place. In practical terms, that means discovery, access review, and offboarding all start from incomplete inventory.
The article’s core point is that shadow SaaS is not a fringe exception. It is a structural mismatch between how fast employees adopt tools and how slowly traditional IAM and deprovisioning processes react.
That mismatch affects NHI governance as much as human access governance when shared tools, API-connected services, and delegated workflows remain active after ownership changes.
Key questions
Q: What breaks when SaaS apps are used outside SSO and central IAM?
A: The main failure is lifecycle control. If an app is not tied to SSO or the identity provider, offboarding, recertification, and access logging may never reach it. That leaves active accounts, orphaned licenses, and audit gaps even when the business believes access was removed.
Q: Why do unsanctioned SaaS apps create both security and cost risk?
A: They create both risks because unmanaged apps can retain sensitive data access while also carrying duplicate or unused licenses. Security teams lose visibility into who can access the app, and finance loses the ability to see whether the software is still needed.
Q: How can teams tell whether SaaS governance is actually working?
A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow. If the platform can only report on SaaS usage but cannot drive deprovisioning or entitlement review, governance is still fragmented.
Q: What happens when departments buy SaaS tools independently?
A: Independent purchasing usually creates duplicate tools, fragmented contract ownership, and inconsistent access controls. Costs rise because no one sees the full picture, and renewals are harder to coordinate. Over time, IT and security teams inherit a messy environment where software sprawl increases both spend and governance burden.
Technical breakdown
Why SSO and IAM miss shadow SaaS
SSO and IAM govern applications that are already known to the organisation and integrated into identity policy. Unsanctioned SaaS often bypasses that model entirely because users can sign up with an email address and a card, without a provisioning event for IT to capture. Once that happens, the application sits outside the access graph, so the organisation cannot rely on normal identity signals to understand who has access or what data is stored there.
Practical implication: treat app discovery as an identity control, not a procurement afterthought.
Why deprovisioning fails when apps are not connected to the IdP
Most deprovisioning depends on HRIS or IdP triggers, which work only when the app is integrated with identity infrastructure. If the app is outside SSO, those triggers never reach it, so licences, sessions, and data access can persist after the employee leaves. This is not a failure of the leaver process in isolation. It is a scope problem in the identity architecture, where the offboarding workflow does not cover the application estate.
Practical implication: map offboarding coverage to actual SaaS usage, not only to integrated applications.
How decentralised SaaS ownership creates governance blind spots
Decentralised ownership means finance, security, and IT each see a different fragment of the problem. Finance sees spend, security sees risk, and IT may see neither the app nor the user relationship that created it. Manual audits then lag behind reality because the environment changes continuously. In governance terms, the control failure is not only weak review cadence. It is the absence of a reliable ownership model for software that can appear and disappear without central approval.
Practical implication: assign ownership and review cadence at the business-unit level for unsanctioned tools.
Threat narrative
Attacker objective: The practical objective is prolonged access to unmanaged SaaS data and accounts that remain reachable after the organisation loses visibility and offboarding control.
- Entry occurs when employees adopt unsanctioned SaaS through self-service sign-up, often using business email and payment methods outside IT control.
- Credential and access state are established outside the identity lifecycle, so the app never enters the normal provisioning and deprovisioning path.
- Persistence follows because access, licences, and stored data remain active after the employee leaves if the app is not tied to identity offboarding.
- Impact is expanded attack surface, unmanaged data retention, wasted licences, and compliance exposure across the shadow SaaS estate.
Breaches seen in the wild
- Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
- Ledger Connect Kit npm compromise 2023: Attackers phished a former Ledger employee with unrevoked npm access and published a wallet-draining Connect Kit, stealing about $600k on 14 Dec 2023.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Shadow SaaS is an identity governance failure, not just a procurement nuisance. When employees can adopt applications outside IT approval, the organisation loses the identity signal that normally ties access to lifecycle control. That means IAM and IGA are governing only the approved edge of the estate, while the real usage pattern keeps expanding elsewhere. The practitioner conclusion is simple: governance has to follow actual application use, not just sanctioned inventory.
Standard deprovisioning is too narrow when the app is not connected to identity infrastructure. HRIS and IdP-driven offboarding only work when the target application is in scope and integrated. Unsanctioned SaaS breaks that assumption, so leavers can remain active long after employment ends. The implication is that offboarding is increasingly an application-discovery problem as much as a lifecycle problem.
Continuous discovery is now a prerequisite for access governance. Point-in-time audits go stale because SaaS adoption changes faster than manual review cycles. That creates a governance gap where risk, spend, and compliance issues all accumulate before anyone notices. NHI Mgmt Group’s position is that continuous inventory is the new baseline for any serious SaaS access programme.
Decentralised software ownership creates an accountability gap that traditional IAM reporting cannot close. Finance, security, and IT each hold part of the picture, but none of them alone can see the full access and licence lifecycle. That fragmentation weakens recertification, renewal decisions, and offboarding execution. Practitioners should treat ownership mapping as a control, not an administrative nicety.
Closed-loop SaaS governance is becoming a core extension of identity lifecycle management. The discipline now spans sanctioned apps, unsanctioned apps, licence recovery, and access revocation in one operating model. For identity teams, that means the boundary between SaaS management and IAM governance is disappearing. The practical conclusion is to manage SaaS as part of the identity estate, not alongside it.
From our research library:
- 1 in 3 organisations encountered suspicious AI agent activity in 2025, and 99.4% experienced a SaaS or AI ecosystem incident.
What this signals
Closed-loop SaaS governance: access control now has to cover discovery, offboarding, and licence recovery together. The old model assumed the application estate was known before governance began; shadow SaaS breaks that assumption and forces identity teams to manage what users actually adopt, not just what IT approves.
Manual review cycles cannot keep up with self-service software adoption. A programme that depends on quarterly reconciliation will miss the point where access first leaves the managed estate, which is why continuous inventory has become the real control boundary for SaaS governance.
For practitioners
- Implement continuous SaaS discovery Build an always-current inventory of apps, users, and licences so shadow tools surface before they become unmanaged access paths.
- Extend offboarding beyond SSO-connected apps Verify that leaver workflows revoke access and reclaim licences in applications that do not use the IdP, not only in managed apps.
- Assign business ownership for shadow tools Require each department to own the apps it introduces so security, finance, and IT can reconcile usage, spend, and access decisions.
- Replace point-in-time reviews with continuous control Use recurring reconciliation of SaaS usage against approved identity records because spreadsheets and audits cannot keep pace with weekly app adoption.
Key takeaways
- Unsanctioned SaaS creates a governance gap when applications sit outside the identity systems that normally control access, review, and offboarding.
- The biggest failure mode is incomplete lifecycle coverage, not lack of intent, because HRIS and IdP triggers do not reach apps that were never integrated.
- Practitioners need continuous discovery and reclaim workflows so shadow tools do not turn into persistent access, wasted spend, and compliance exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Unsanctioned SaaS persists when offboarding never reaches apps outside the IdP. |
| NHI-03 — Vulnerable Third-Party NHI | External SaaS tools create third-party access paths that fall outside normal governance. | |
| NHI-05 — Overprivileged NHI | Unreviewed SaaS accounts and licences can retain access beyond business need. | |
| Recommendation — Map shadow SaaS offboarding gaps to NHI-01 and reclaim access where lifecycle controls do not reach. Assess third-party SaaS access paths under NHI-03 and require ownership for every external application. Review SaaS entitlements for excess access under NHI-05 and remove privileges that outlive use. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about entitlement governance across unmanaged SaaS access. |
| Recommendation — Apply PR.AA-05 to reconcile discovered SaaS access against approved entitlements and remove drift. | ||
| CIS Controls v8 | CIS-5 — Account Management | Shadow SaaS exposes account lifecycle failures when apps are not tied into standard account management. |
| Recommendation — Use CIS-5 to inventory SaaS accounts and revoke orphaned access that escapes normal lifecycle control. | ||
Key terms
- Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
- Unsanctioned App: An unsanctioned app is a software service used without formal approval from IT or security. These tools may solve business needs, but they also bypass standard controls for onboarding, offboarding, monitoring, and compliance. Organisations often lose visibility into where data is stored, who can access it, and whether the service is properly governed.
- SaaS Lifecycle Governance: SaaS lifecycle governance is the set of controls that manage applications from onboarding through access assignment, renewal, and decommissioning. It matters because the security value of SaaS management depends on whether the organisation can prove ownership, revoke access, and retire unused tools on demand.
- Licence Reclamation: Licence reclamation is the removal or downgrade of software entitlements that are no longer justified by usage. In identity governance terms, it is a lifecycle action based on observed need, and it becomes more effective when usage telemetry is reliable enough to trigger automated review or deprovisioning.
Deepen your knowledge
NHI governance, identity lifecycle, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org