Join our Newsletter — 33% off our NHI Course

SaaS Manager and access reviews: what this means for IAM teams

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: SaaS oversight is becoming an identity lifecycle problem, not just an inventory problem, as 1Password’s quarterly security spotlight says SaaS Manager is being used to control SaaS spend, automate provisioning and deprovisioning, and streamline access reviews across the employee lifecycle, according to 1Password.

Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Webinar On Demand EMEA - What's new? The 1Password quarterly security spotlight and roadmap review - Q2 2026”.

Key questions

Q: What breaks when SaaS change management is separated from IAM processes?

A: When SaaS change management is separated from IAM, teams lose visibility into who should still have access after a change, which accounts or integrations are obsolete, and whether approvals match current state.

Q: Why do SaaS environments create so much access review friction?

A: Because entitlement data is often fragmented across app consoles, directories, and shadow tools.

Practitioner guidance

  • Map SaaS ownership to lifecycle control points Define which team owns provisioning, recertification, and deprovisioning for each SaaS application category, then record those ownership points in your IAM operating model.
  • Unify access requests and access reviews Make sure request approvals and certification campaigns draw from the same entitlement source of truth so reviewers see current access, not stale snapshots.
  • Use SaaS spend anomalies as governance signals Investigate unused licences, duplicate subscriptions, and unexpected spend as possible signs of orphaned access or missing deprovisioning steps.

Bottom line: The article frames SaaS management as an IAM problem because visibility, access requests, and lifecycle changes now sit in the same control path.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 10 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21539
 

SaaS governance is now an identity lifecycle discipline, not a shadow inventory exercise. The article shows the operating centre of gravity moving from simple discovery to provisioning, deprovisioning, and access review. That shift matters because the control question is no longer whether an app exists, but whether the entitlement lifecycle is governed end to end. Practitioners should treat SaaS management as part of IAM and IGA design, not as a parallel admin function.

A question worth separating out:

Q: What should IAM teams do first when they cannot see all SaaS applications in use?

A: Start by building a complete discovery picture from browser activity, SSO logs, and direct connectors. The first goal is not remediation but inventory quality, because access decisions cannot be trusted until you know which apps, accounts, and OAuth grants actually exist across the environment.

👉 Read our full editorial: 1Password roadmap review shows SaaS governance moving into IAM


This post was modified 10 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.