TL;DR: Managed service providers are under pressure to govern multiple client SaaS environments, with Josys arguing that centralised visibility, automated provisioning, and continuous monitoring can reduce operational strain and improve compliance reporting. The real issue is that MSP identity governance still depends on tenant-by-tenant control discipline, not just a unified console.
NHIMG editorial — based on content published by Josys: How Josys Helps MSPs Govern Identity and Secure SaaS Operations at Scale
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
Questions worth separating out
Q: How should MSPs govern access across multiple SaaS tenants?
A: MSPs should treat each tenant as a distinct governance boundary, even when one platform manages them all.
Q: When does centralised SaaS management create more risk than it reduces?
A: It creates more risk when the platform concentrates control without preserving separation of duties, tenant boundaries, and client-specific policy.
Q: What breaks when MSP offboarding is not tightly controlled?
A: Stale access remains active, dormant subscriptions continue to consume budget, and former users can retain visibility into client systems longer than intended.
Practitioner guidance
- Standardise tenant lifecycle workflows Define one onboarding, access change, and offboarding workflow template for every managed tenant, then document the exceptions that are allowed by contract or regulation.
- Tie deprovisioning to authoritative events Remove access when the source event occurs, not when a ticket is finally closed, so terminated users and inactive subscriptions do not persist across client environments.
- Review privileges against actual usage Compare assigned access to observed application use and revoke entitlements that have no business justification or no recent activity.
What's in the full article
Josys' full blog post covers the operational detail this post intentionally leaves for the source:
- Walkthroughs of the global SaaS dashboard and multi-tenant navigation model used for day-to-day administration
- Examples of automated provisioning, access reviews, and reporting workflows across managed client environments
- References to the Mach49 case study and the specific operational outcomes described there
- Descriptions of how the platform integrates with existing MSP tooling to reduce duplicate work
👉 Read Josys' analysis of MSP SaaS governance and identity operations →
MSP SaaS governance at scale: is centralised identity control enough?
Explore further
Centralised SaaS governance is now a tenant-risk aggregation problem, not just an efficiency problem. When an MSP consolidates access control across clients, it also consolidates the blast radius of any lifecycle failure, review miss, or misconfiguration. That means governance quality must be measured per tenant and in aggregate, because one weak operating model can contaminate the whole service layer. Practitioners should treat centralisation as a control design choice, not an outcome.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage.
A question worth separating out:
Q: How can teams tell whether SaaS governance is actually working?
A: Look for evidence that discovered applications can be assigned an owner, tied to an access policy, and removed through an enforced workflow. If the platform can only report on SaaS usage but cannot drive deprovisioning or entitlement review, governance is still fragmented.
👉 Read our full editorial: MSP SaaS identity governance at scale: what Josys changes