TL;DR: SaaS portfolio management is presented as a way to control app sprawl, reduce redundant subscriptions, and improve compliance by centralising assessment, categorisation, licensing, and access oversight, according to Zluri. The identity issue is that portfolio management only helps when app ownership, user access, and offboarding are enforced across the full SaaS lifecycle.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “SaaS Portfolio Management: A Comprehensive Guide | 2026”.
Key questions
Q: What breaks when SaaS portfolio management does not include access governance?
A: The programme can still reduce cost and improve visibility, but it will not reliably control who can use each application or whether access ends when the app is retired.
Q: Why does SaaS sprawl increase non-human identity risk?
A: SaaS sprawl increases NHI risk because every new integration can create tokens, service accounts, OAuth grants, and delegated permissions that persist outside normal review cycles.
Q: What are the signs that SaaS app permission governance is failing?
A: Common warning signs include users approving apps outside policy, security teams lacking visibility into permission changes, and integrations with broad access that no one can explain.
Practitioner guidance
- Inventory the full SaaS estate Compile a continuously updated inventory of approved and unapproved SaaS applications, including owners, user populations, and renewal dates so identity governance starts from a complete system boundary.
- Bind renewal to access review Require ownership validation, active-user checks, and entitlement recertification before any SaaS contract is renewed, especially where applications carry sensitive data or delegated access.
- Offboard access at retirement Remove accounts, tokens, and embedded permissions as part of every application retirement process so old SaaS services do not leave behind residual access paths.
Bottom line: SaaS portfolio sprawl creates identity governance blind spots because discovery, ownership, and access control are often managed separately.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
SaaS portfolio management is now an identity governance function, not just an IT inventory exercise. The article frames portfolio oversight around assessment, categorisation, and renewals, but each of those steps determines whether access remains governable. Once application sprawl outpaces ownership assignment, the IAM programme no longer has a complete system boundary to govern. Practitioners should treat the SaaS portfolio as part of the identity estate.
A few things that frame the scale:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
A question worth separating out:
Q: Should teams prioritise SaaS discovery or offboarding first?
A: Discovery comes first when the estate is incomplete, because you cannot govern what you cannot see. Offboarding should follow immediately for any apps that are redundant, unowned, or no longer required. The practical sequence is discover, assign ownership, then remove unnecessary access and retire the app cleanly.
👉 Read our full editorial: SaaS portfolio sprawl exposes identity governance blind spots