Join our Newsletter — 33% off our NHI Course

SaaS app sprawl and governance gaps: what IAM teams miss

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: SaaS management platforms are moving from app inventory into access governance because Zluri says modern teams need to know not just which apps exist, but who uses them, at what permission level, and whether that access should exist at all. That shift makes SaaS discovery an identity problem, not only a cost problem.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Top 20 SaaS Management Platforms [2026]”.

Key questions

Q: What breaks when SaaS management stops at app inventory?

A: When SaaS management stops at inventory, teams can see applications but not whether access is justified, active, or connected to unmanaged identities.

Q: How should security teams govern shadow AI in SaaS environments?

A: Security teams should inventory AI-enabled features, classify the data those features can touch, and enforce approved-use rules at the application and identity layers.

Q: How should teams decide whether SaaS access still belongs?

A: Teams should base that decision on real usage, permission level, business role, and application risk, not on whether the app was once approved.

Practitioner guidance

  • Map SaaS discovery to identity records Connect app inventory, SSO, browser activity, and finance data to the user and entitlement records that explain who actually has access.
  • Extend access reviews into SaaS sprawl Trigger recertification when unmanaged apps, inactive accounts, or unusual permission levels appear in the SaaS estate, not only on a calendar schedule.
  • Define policy for shadow AI adoption Decide which AI apps are approved, which data types are prohibited, and what events should block or flag usage for review.

Bottom line: SaaS sprawl becomes an identity problem when organisations can no longer map users, permissions, and business justification to the apps they run.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Visibility without entitlement context is not governance. A SaaS inventory can tell you how many applications exist, but it cannot tell you whether access is still justified, whether an account is dormant, or whether permissions exceed the user's current role. That distinction is central to OWASP-NHI and NIST CSF thinking because unmanaged access is the control failure, not app sprawl alone. The practitioner takeaway is simple: SaaS governance must evaluate entitlement state, not just application presence.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.

A question worth separating out:

Q: What should teams do when unused SaaS licenses keep accumulating?

A: They should automate reclamation based on actual usage, then align those actions to offboarding and recertification events. If a license is inactive, but the account still exists, the problem is not cost alone. It is persistent access that no longer has a business need.

👉 Read our full editorial: SaaS management platforms expose the IAM gap behind app sprawl



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

SaaS app sprawl is now an identity governance problem, not a tooling problem: Once organisations cannot map users to applications and entitlements, the real issue is governance drift. Inventory alone cannot answer whether access is still justified, which means the control gap sits inside IAM and IGA, not just procurement. Practitioners should evaluate SaaS management through the lens of entitlement control, not software catalogue depth.

A few things that frame the scale:

A question worth separating out:

Q: When should SaaS governance trigger deprovisioning instead of review?

A: Deprovisioning should be triggered when the platform has reliable usage evidence that an account is inactive, over-permissioned, or associated with an unmanaged application. Review still has value, but it should not delay action when the governance signal already shows the access no longer fits the identity lifecycle.

👉 Read our full editorial: SaaS management platforms expose the IAM gap behind app sprawl


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.