TL;DR: SaaS renewals often become reactive because usage data is fragmented, ownership is unclear, and offboarding gaps leave former employees and unused licenses on the books, according to 1Password. The governance problem is not negotiation skill but identity visibility, because renewal decisions are only as accurate as the access data behind them.
NHIMG editorial — based on content published by 1Password: SaaS renewal management and access visibility
By the numbers:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
Questions worth separating out
Q: How should teams manage SaaS renewals when usage data is incomplete?
A: Start by treating renewals as a governance review, not a purchasing task.
Q: Why do SaaS renewals expose access governance gaps?
A: Renewals expose governance gaps because they force teams to prove who still needs access, who owns the tool, and whether the contract matches reality.
Q: What breaks when former employees are still counted in SaaS renewals?
A: What breaks is both spend accuracy and access governance.
Practitioner guidance
- Create a renewal ownership register Map every renewing SaaS application to a named business owner, technical owner, and finance contact so no contract reaches auto-renewal without an accountable reviewer.
- Reconcile licenses against active usage before notice windows open Pull usage data early enough to identify shelfware, duplicate tools, and dormant accounts before the renewal notice forces a rushed decision.
- Fold leaver cleanup into renewal reviews Use each renewal checkpoint to remove access for former employees, reclaim unused seats, and verify that inherited accounts still have a valid business need.
What's in the full article
1Password's full article covers the operational detail this post intentionally leaves for the source:
- How 1Password SaaS Manager discovers apps and tracks usage patterns across the estate
- The 30-60-90 day alerting model for upcoming renewals and review workflows
- How Slack, Teams, and email notifications support cross-functional renewal decisions
- The operational steps for reclaiming licenses and reducing unmanaged app risk
👉 Read 1Password's analysis of SaaS renewal management and access visibility →
SaaS renewals and license sprawl: what IAM teams miss?
Explore further
SaaS renewals are a lifecycle governance test, not a procurement event. The article is describing what happens when identity and entitlement data are too fragmented to support a decision. If teams cannot answer who is using an app, they cannot know whether access and spend remain justified. Practitioners should treat every renewal as a control checkpoint for access validity, ownership, and removal.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to Ultimate Guide to NHIs.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
A question worth separating out:
Q: Who should be accountable for SaaS renewal decisions?
A: Accountability should sit with the business owner of the application, supported by IT for access data and finance for contract control. If any one of those groups owns the process alone, the organisation loses either usage context, entitlement accuracy, or cost discipline. Shared review is the only reliable way to make renewal decisions that stand up operationally.
👉 Read our full editorial: SaaS renewal management is really an access governance problem