TL;DR: SaaS sprawl starts with fast self-service adoption and ends with hidden access, unused licenses, and audit gaps, according to 1Password. The governance problem is not discovery alone, but the lack of repeatable lifecycle controls for onboarding, offboarding, access reviews, and renewals across unmanaged apps.
Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Five things successful IT teams get right about SaaS management”.
Key questions
Q: What breaks when SaaS sprawl is treated as a discovery problem instead of a governance problem?
A: Discovery alone cannot answer who owns an app, who still has access, or what happens to licenses and data when people move on.
Q: Why do unmanaged SaaS apps create access risk even when SSO is in place?
A: Because SSO only governs the apps it covers.
Q: How do teams know whether SaaS access reviews are actually working?
A: Look for reduction in orphaned accounts, faster revocation after role change, and fewer exceptions repeated across successive review cycles.
Practitioner guidance
- Build a shadow SaaS intake workflow Route every newly discovered app into a review queue that captures owner, user population, access method, business purpose, and retirement date before it becomes normalised.
- Extend offboarding beyond the IdP Revoke app-native accounts, OAuth grants, licenses, and shared resource ownership in the same offboarding motion so departed users do not leave behind active access.
- Centralise access reviews across managed and unmanaged apps Run review cycles with role, department, and risk context, and require reviewers to act on in-line remediation rather than exporting lists into spreadsheets.
Bottom line: SaaS sprawl is what happens when adoption is easy but lifecycle governance is fragmented across tools, teams, and data sources.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
SaaS sprawl is an identity governance failure before it is a software management problem. The article shows that apps proliferate when business speed outruns lifecycle control, and that is an IGA issue as much as a procurement issue. Discovery without ownership, review, and retirement simply creates a larger inventory of unmanaged entitlements. Practitioners should treat SaaS sprawl as evidence that identity governance has not been extended far enough into the application perimeter.
A few things that frame the scale:
- 1 in 3 organisations encountered suspicious AI agent activity in 2025, and 99.4% experienced a SaaS or AI ecosystem incident.
A question worth separating out:
Q: What is the difference between SaaS management and SaaS discovery?
A: SaaS discovery finds applications. SaaS management adds ownership, access context, offboarding, review, and renewal control. In practice, discovery is an input to governance, while management is the repeatable process that keeps the app, the entitlement, and the spend aligned.
👉 Read our full editorial: SaaS sprawl is really an identity governance problem