TL;DR: Choosing a SAM tool still comes down to visibility, license optimisation, integration, vendor management, and risk controls, with KuppingerCole cited in the source as backing Zluri’s SaaS discovery claims. The deeper issue is that software governance now overlaps with identity governance, because app inventory without user and access context leaves security and compliance decisions incomplete.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “5 Questions to Ask For Selecting the Best SAM Tool for Your IT Team”.
By the numbers:
- Zluri says it supports over 300 applications and grows monthly.
- The article says one example of SaaS license underuse is 100 licenses purchased and 75 used.
Key questions
Q: How should teams govern SaaS access when the application estate keeps changing?
A: Start with discovery, not policy.
Q: Why do SaaS licences and usage counts not tell the full governance story?
A: Because a seat count shows consumption, not whether access is still justified, approved, or properly offboarded.
Q: What breaks when SaaS management tools do not include user context?
A: Access reviews, offboarding, and risk decisions become partial because the organisation can see the application but not the identities behind it.
Practitioner guidance
- Map SaaS inventory to identity sources Connect discovery, SSO, directory data, and app catalogue outputs so each application can be tied to accountable users and administrators.
- Separate licence efficiency from entitlement review Use seat counts and renewal dates for cost control, then run access reviews on the identities actually holding those licences.
- Include external users in governance scope Track freelancers, consultants, and other non-employees in the same control process as employees so shared SaaS access is not missed.
Bottom line: SaaS management becomes a governance issue when inventory data is disconnected from identity and access context.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
SaaS management has become an identity governance problem, not a shelfware problem. The article treats SAM as a way to control cost and compliance, but the operational reality is broader: every SaaS app also carries user entitlements, external access, and data-sharing trust. Once a platform is connected to SSO, directories, and third-party apps, it starts participating in identity governance. Practitioners should treat SAM selection as part of their broader access architecture, not a procurement decision in isolation.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
A question worth separating out:
Q: Which frameworks should guide SaaS access and application governance?
A: NIST CSF and OWASP-NHI are the most relevant lenses for SaaS governance because they connect discovery, protection, and access control to the identities using the software. Use those frameworks to check whether inventory feeds ownership, entitlement review, and lifecycle actions rather than staying at reporting level.
👉 Read our full editorial: SAM tool selection exposes the governance gap in SaaS visibility
SaaS management has become an identity governance problem: A tool that inventories applications but cannot tie them back to users, external accounts, and entitlements leaves the programme with only partial control. The article correctly points toward visibility, but the deeper shift is that software governance now depends on identity context to explain risk, ownership, and access intent. Practitioners should judge SAM tools by whether they can support governance decisions, not just asset counts.
A few things that frame the scale:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
A question worth separating out:
A: Prioritise inventory enough to know what exists, but move quickly to access review once the app list is credible. Licence optimisation saves money, yet access review tells you whether the right identities still need the access they hold. In practice, review and offboarding matter more than seat efficiency when risk is the concern.
👉 Read our full editorial: SAM tool selection exposes the governance gap in SaaS visibility