Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

SaaS spend management and orphaned access: what IAM teams miss


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: SaaS spend management becomes a control problem, not just a finance problem, because unused licenses, auto-renewals, and orphaned accounts are all tied to identity lifecycle gaps, according to Josys. The operational fix is continuous discovery, access review, and offboarding-linked deprovisioning, because spend waste and access risk usually share the same root cause.

NHIMG editorial — based on content published by Josys: SaaS Spend Management: Find and Cut Software Waste

By the numbers:

  • 72%, anizations that experienced or suspected a non-human identity breach reached 72%, with 46% confirming one and 26% suspecting one.

Questions worth separating out

Q: How should security teams connect SaaS spend management with IAM governance?

A: Security teams should treat SaaS spend data as an identity signal.

Q: Why do orphaned SaaS apps create more risk than unused licences?

A: Orphaned SaaS apps can still hold data, tokens, and integrations after the original business need has ended.

Q: What should teams do first when SaaS spend starts to drift upward?

A: Start with identity-led discovery, not a budget freeze.

Practitioner guidance

  • Map SaaS seats to identity records Build your inventory from SSO logs, OAuth grants, and browser-level discovery so each app and seat is linked to an accountable identity and owner.
  • Tie offboarding to license revocation Automate deprovisioning so that access removal also reclaims the associated subscription seat the same day an employee, contractor, or project ends.
  • Set a 90-day usage threshold Compare purchased seats against meaningful activity in the last 90 days, then reclaim zero-activity licenses and review low-activity seats with managers.

What's in the full article

Josys's full article covers the operational detail this post intentionally leaves for the source:

  • A practical audit sequence for building a SaaS inventory from finance records, SSO logs, and OAuth grants.
  • Step-by-step guidance for splitting unused licenses into zero-activity, low-activity, and over-tiered groups.
  • Contract-renewal tactics for owners who need to negotiate using usage data rather than generic discount requests.
  • A working model for wiring offboarding into automatic deprovisioning so seats are reclaimed without manual follow-up.

👉 Read Josys's analysis of SaaS spend waste and identity-led control →

SaaS spend management and orphaned access: what IAM teams miss?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

Identity-led SaaS governance is now the more accurate control model. The article is strongest when it shows that software waste is not just procurement drift but entitlement drift. If every paid seat maps to an identity, then inventory, renewal, and offboarding belong in the same governance loop. That is where IAM teams can add measurable value by treating SaaS spend as a lifecycle issue rather than a budget-only exercise.

A question worth separating out:

Q: How can organisations tell whether SaaS budget controls are working?

A: Look for fewer orphaned subscriptions, lower duplicate app counts, and clean ownership records tied to each renewal. If finance can explain spend but IAM cannot explain who still has access, the control set is incomplete. Effective governance shows up as aligned inventory, ownership, and access removal.

👉 Read our full editorial: SaaS spend management is really an identity governance problem



   
ReplyQuote
Share: