TL;DR: SaaS spend management tools promise better visibility into subscriptions, licences, renewals, and shadow IT, with Zluri’s article emphasising discovery methods, automated tracking, and access control across a broad SaaS estate. The real governance issue is that spend optimisation and identity control now overlap, so unmanaged app access becomes both a cost problem and an identity problem.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Top 10 SaaS Spend Management Tools in 2026”.
Key questions
Q: What breaks when SaaS spend management is treated separately from identity governance?
A: The organisation can remove licences without removing accounts, or keep accounts active without any clear business need.
Q: Why do unsanctioned SaaS apps create both security and cost risk?
A: They create both risks because unmanaged apps can retain sensitive data access while also carrying duplicate or unused licenses.
Q: How do you know if SaaS license optimization is working?
A: You should see fewer duplicate applications, lower spend on unused seats, clearer application ownership, and cleaner recertification outcomes.
Practitioner guidance
- Reconcile SaaS discovery with identity ownership Map every discovered application to an accountable owner, an authentication method and a lifecycle path so shadow IT cannot remain outside governance.
- Tie licence recovery to access review decisions Use licence usage reports and access certification outcomes together so idle subscriptions and stale accounts are removed in the same cycle.
- Classify unmanaged apps as control exceptions Route any newly discovered unsanctioned SaaS app into a security and governance review before renewal, re-provisioning or broader rollout.
Bottom line: SaaS spend tools now expose a governance gap where cost control and access control overlap in the same application estate.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
SaaS spend management is now an identity governance problem, not just a procurement problem. The article shows that discovery, renewal management and licence optimisation all depend on knowing who has access to what. Once application inventory is used for both cost and access decisions, identity governance becomes the control plane that determines whether savings are real or cosmetic.
A few things that frame the scale:
- The average enterprise SaaS platform connects to 42 or more third-party applications through OAuth tokens, API keys, webhooks and automation platforms.
A question worth separating out:
Q: How should organisations discover and govern shadow IT apps?
A: Start with discovery, but do not stop there. Build a process that assigns ownership, classifies the data the app touches, checks whether approved authentication and logging are available, and records whether the tool will be sanctioned, constrained, or removed. Discovery without a disposition workflow only creates more inventory, not better control.
👉 Read our full editorial: SaaS spend management tools expose the identity control gap