Join our Newsletter — 33% off our NHI Course

SaaS management platforms and identity governance: what changes now?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: SaaS management platforms are shifting from inventory and license tracking to continuous governance, with Zluri highlighting discovery across managed, unmanaged, and shadow AI apps, plus automated deprovisioning and access review triggers. The real change is that SaaS oversight now depends on identity context, not just app counts.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Top 20 SaaS Management Platforms [2026]”.

Key questions

Q: How should security teams govern SaaS access when identities span many apps?

A: Security teams should govern SaaS access as a relationship problem, not a list problem.

Q: Why do unmanaged SaaS apps create identity governance risk?

A: Unmanaged SaaS apps create risk because they sit outside central visibility, which means IT cannot consistently enforce SSO, review entitlements, or offboard access.

Q: What are the signs that SaaS license governance is failing in a large organisation?

A: Common warning signs include employees waiting on approvals to host basic meetings, licenses sitting unused for long periods, and administrators constantly reassigning the same entitlements.

Practitioner guidance

  • Map SaaS discovery to identity records Connect app inventory, SSO data, and browser activity to named users and permission levels so each application can be evaluated in identity terms, not just asset terms.
  • Trigger access reviews from shadow app detections Route unmanaged or unapproved app discoveries into the same review flow used for risky entitlements so governance action follows the finding immediately.
  • Automate deprovisioning for inactive usage Use configurable usage thresholds to remove or downgrade access when accounts stop showing meaningful activity across the SaaS stack.

Bottom line: SaaS management is shifting from software counting to access governance, which changes the control objective for IAM and IGA teams.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Identity-aware SaaS management is now part of the governance stack, not a sidecar to it. The article shows the category moving beyond renewal tracking into access context, shadow app detection, and automated actions. That matters because the security question is no longer whether an app exists, but whether the identities inside it are still authorised, reviewable, and revocable. Practitioners should treat SMP output as governance input, not just procurement data.

A few things that frame the scale:

  • Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, with 77% of these incidents resulting in tangible damage. That is the baseline risk behind unmanaged SaaS integrations and delegated access paths.

A question worth separating out:

Q: How do SaaS management platforms differ from identity governance tools?

A: SaaS management focuses on discovering, classifying, and optimising the app estate, while identity governance focuses on who should have access and whether that access should persist. In practice, the two are converging because SaaS control is incomplete unless discovery, review, and deprovisioning are linked.

👉 Read our full editorial: SaaS management platforms now govern identity, usage, and risk



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

SaaS management is converging with identity governance because visibility alone no longer answers the real risk question. Once teams know who is using a SaaS app, the next control problem is whether that access should still exist. That moves SMPs into IGA territory, especially where offboarding, access reviews, and entitlement hygiene have to follow actual usage rather than renewal dates.

A few things that frame the scale:

A question worth separating out:

Q: How should security teams govern Shadow AI in SaaS applications?

A: Security teams should govern Shadow AI by classifying AI-capable SaaS tools, deciding what data each tool may process, and enforcing those decisions centrally. Discovery is necessary but not sufficient. The control layer must cover model training, retention, sharing, and exceptions so users cannot create hidden data-use risk through ordinary application activity.

👉 Read our full editorial: SaaS management platforms now govern identity, usage, and risk


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.