TL;DR: SaaS sprawl creates a shared visibility failure for finance and identity teams because applications are often discovered only after signup, purchase, or SSO integration, according to Zluri. That late discovery leaves access reviews incomplete, offboarding partial, and software spend reactive instead of governed.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “The Problem of SaaS Sprawl: Where SaaS Management and Identity Governance Meet (And Both Fail)”.
Key questions
Q: What breaks when SaaS applications are discovered too late?
A: Access reviews, offboarding, and spend control all become partial controls because they only operate on applications already known to IT.
Q: Why do SaaS sprawl and identity governance fail in the same place?
A: They both depend on discovery happening before control.
Q: How do you know if access reviews are actually covering your SaaS environment?
A: Compare the number of applications in review workflows with the number of applications employees actually use.
Practitioner guidance
- Implement stage-one SaaS discovery Add browser, endpoint, CASB, and finance signals so new applications are visible before they become embedded in team workflows.
- Unify finance and identity inventories Reconcile procurement records, expense data, and IdP inventories into one application register that both Finance and IGA teams can use.
- Expand access reviews beyond SSO-connected tools Measure review coverage against the total application estate, not only the systems already integrated into Okta or another identity provider.
Bottom line: SaaS sprawl creates a single visibility gap that damages both cost control and identity governance.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Late discovery is the shared failure mode behind SaaS cost waste and identity blind spots. This article shows that finance and security are reacting to the same upstream inventory gap, just at different points in the lifecycle. Traditional SaaS management sees charges too late, while IGA sees applications only after SSO integration. The practitioner conclusion is that discovery timing, not just catalogue quality, determines whether either programme can govern reality.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: Who should own SaaS discovery when cost control and IGA both depend on it?
A: Ownership usually sits with IT, but both Finance and Security are stakeholders because they consume the same inventory for different outcomes. The key is shared governance: one discovery process, one register, and one set of escalation paths for unmanaged applications.
👉 Read our full editorial: SaaS sprawl is breaking both identity governance and cost control