TL;DR: SaaS Manager is being used to surface blind spots, reduce unnecessary SaaS spend, and automate provisioning, deprovisioning, and access reviews across the employee lifecycle, according to 1Password. The real issue is not tooling breadth but whether lifecycle governance can keep pace with app sprawl and manual IT overhead.
Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Webinar On Demand What's new? The 1Password quarterly security spotlight and roadmap review - Q2 2026”.
Key questions
Q: How should teams govern SaaS access when apps are discovered informally?
A: Start by treating discovery as a governance control, not just inventory.
Q: Why do lifecycle workflows fail when SaaS sprawl grows faster than IAM processes?
A: Because the controls depend on accurate application ownership, current entitlements, and authoritative identity events.
Practitioner guidance
- Map the full SaaS application estate Create a continuously updated inventory of SaaS applications, connected identities, and ownership so access governance starts from visibility rather than assumption.
- Anchor lifecycle workflows to authoritative identity events Connect joiner, mover, and leaver events to provisioning and deprovisioning logic so access changes follow the source of truth instead of manual tickets.
- Unify access requests and access reviews Use one governed record for request, approval, entitlement, and review so reviewers see the same access state that provisioning systems enforce.
Bottom line: SaaS access governance breaks down when teams cannot see the full application estate or assign ownership consistently.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
SaaS visibility is now a prerequisite for lifecycle governance, not a reporting extra: once the app estate outgrows the access model, recertification and deprovisioning become incomplete by design. The article’s core signal is that organizations cannot govern what they cannot inventory. Practitioners should treat visibility as the control plane that makes employee lifecycle access measurable at all.
A question worth separating out:
Q: How should organisations balance SaaS visibility, automation, and lifecycle controls?
A: Organisations should treat visibility, automation, and lifecycle management as one operating model rather than separate projects. Visibility shows the environment, automation removes manual discovery and repetitive work, and lifecycle controls reduce errors from onboarding through offboarding. Together, they improve security, save time, and give IT a defensible basis for decisions about applications and access.
👉 Read our full editorial: 1Password’s SaaS visibility push changes employee lifecycle access