TL;DR: Unsanctioned SaaS apps increasingly sit outside SSO, IAM, and standard deprovisioning, leaving sensitive data, wasted licenses, and compliance gaps behind, according to 1Password. The core problem is not just discovery, but the fact that traditional identity controls were designed for managed apps, not continuously changing shadow IT.
Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Solving the unsanctioned SaaS problem”.
Key questions
Q: What breaks when SaaS apps are used outside SSO and central IAM?
A: The main failure is lifecycle control.
Q: Why do unsanctioned SaaS apps create both security and cost risk?
A: They create both risks because unmanaged apps can retain sensitive data access while also carrying duplicate or unused licenses.
Q: How can teams tell whether SaaS governance is actually working?
A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow.
Practitioner guidance
- Implement continuous SaaS discovery Build an always-current inventory of apps, users, and licences so shadow tools surface before they become unmanaged access paths.
- Extend offboarding beyond SSO-connected apps Verify that leaver workflows revoke access and reclaim licences in applications that do not use the IdP, not only in managed apps.
- Assign business ownership for shadow tools Require each department to own the apps it introduces so security, finance, and IT can reconcile usage, spend, and access decisions.
Bottom line: Unsanctioned SaaS creates a governance gap when applications sit outside the identity systems that normally control access, review, and offboarding.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Shadow SaaS is an identity governance failure, not just a procurement nuisance. When employees can adopt applications outside IT approval, the organisation loses the identity signal that normally ties access to lifecycle control. That means IAM and IGA are governing only the approved edge of the estate, while the real usage pattern keeps expanding elsewhere. The practitioner conclusion is simple: governance has to follow actual application use, not just sanctioned inventory.
A few things that frame the scale:
- 1 in 3 organisations encountered suspicious AI agent activity in 2025, and 99.4% experienced a SaaS or AI ecosystem incident.
A question worth separating out:
Q: What happens when departments buy SaaS tools independently?
A: Independent purchasing usually creates duplicate tools, fragmented contract ownership, and inconsistent access controls. Costs rise because no one sees the full picture, and renewals are harder to coordinate. Over time, IT and security teams inherit a messy environment where software sprawl increases both spend and governance burden.
👉 Read our full editorial: Unsanctioned SaaS access exposes a governance gap in IAM controls