TL;DR: Enterprise SaaS is expanding toward 85% of software spend, while shadow IT already accounts for 29% of IT security concerns, according to JumpCloud. The practical shift is that SaaS management now functions as identity governance for apps, accounts, and access, not just license cleanup.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Best SaaS Management Platforms Compared (Aug. 2025)”.
By the numbers:
- Almost 85% of all enterprise software will be SaaS applications, according to JumpCloud.
- Shadow IT accounts for 29% of IT security concerns, according to JumpCloud.
Key questions
Q: What breaks when SaaS spend management is treated separately from identity governance?
A: The organisation can remove licences without removing accounts, or keep accounts active without any clear business need.
Q: Why do shadow IT and SaaS sprawl break access governance?
A: Because governance only works on systems you can see.
Q: What are the signs that SaaS app permission governance is failing?
A: Common warning signs include users approving apps outside policy, security teams lacking visibility into permission changes, and integrations with broad access that no one can explain.
Practitioner guidance
- Map SaaS discovery to identity signals Use browser extensions, native connectors, and directory integrations together so unknown apps are tied back to actual users and accounts.
- Review shadow IT as an access-risk queue Treat personally registered SaaS accounts, OAuth-connected apps, and unapproved logins as governance exceptions that require owner review.
- Tie offboarding to SaaS account removal Ensure leaver workflows revoke SaaS access, remove shared access paths, and check for former-employee accounts that remain active.
Bottom line: SaaS management is no longer just software inventory because the real risk sits in who can access which apps and whether that access is still legitimate.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
SaaS management has crossed the line from portfolio hygiene into identity governance. Once discovery, account matching, access enforcement, and offboarding all become part of the same workflow, the old separation between SaaS administration and IAM stops making operational sense. The programme owner now has to treat SaaS applications as identity-bearing systems, not just software subscriptions. That is the governance shift this market has been heading toward.
A few things that frame the scale:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
A question worth separating out:
Q: How can organisations reduce wasted SaaS spend without weakening access control?
A: They should combine usage telemetry, renewal calendars, and access reviews so underused licences can be reclaimed without delaying legitimate work. The best result is not fewer licences at any cost, but cleaner assignment and faster recovery of dormant entitlements. That approach reduces waste while preserving operational continuity.
👉 Read our full editorial: SaaS management now sits inside identity governance, not beside it