Treat install counts as discovery only and require usage evidence before renewals, tier changes, or budget approvals. Governance works better when licence decisions are based on what people actually open in the foreground, because installed software can remain idle while still consuming cost. That shifts SaaS management from inventory tracking to measurable entitlement control.
Why install counts are only the starting point
Installation data tells you what is present, not what is being used. For SaaS governance, that distinction matters because dormant installs can distort renewal forecasts, inflate seat counts, and hide where access is no longer justified. Teams need a usage-backed view of entitlement consumption before they treat a licence as active.
Foreground activity is the more reliable signal because it shows whether a person is actually opening and interacting with the service rather than simply retaining a provisioned account. That makes licence review a control problem, not just a procurement check.
What “real use” should mean in licence governance
Real use should be defined in terms of observable interaction with the application, not device presence or software deployment. The practical question is whether the user opened the SaaS product, performed a meaningful action, or generated a recent activity trail that justifies keeping the entitlement.
That definition helps separate discovery from justification. Discovery data is still useful for inventory, shadow IT identification, and adoption analysis, but it should not by itself validate renewals, higher-tier assignments, or exception approvals. A licence that is installed but inactive should be treated as a candidate for removal, downgrade, or revalidation.
For NIST Cybersecurity Framework 2.0 style governance, the point is to align ownership, oversight, and monitoring with the actual service relationship rather than the presence of software on an endpoint.
How to run usage-based SaaS licence decisions
Effective governance usually starts with a simple rule set: define the usage threshold, define the observation window, and define who can approve exceptions. Teams then compare installation data, sign-in evidence, and application activity to decide whether a licence remains justified, should be downgraded, or should be reclaimed.
This is strongest when procurement, IT, and security work from the same evidence set. If renewal decisions rely on a vendor report while operations relies on endpoint installs, the organisation will overcount active demand and miss reclaim opportunities. Where access or entitlement controls are part of the decision, NIST SP 800-53 Rev 5 Security and Privacy Controls provides a useful control language for baselining access reviews and continuous monitoring.
Teams should also distinguish between occasional and essential usage. A seat used once in a quarter may still be valid, but it should not be processed the same way as a daily operational licence. That difference prevents a blunt “install equals keep” rule from locking in waste.
Risk and Threat Considerations
When install data is mistaken for real use, organisations can carry unused entitlements, miss overprovisioned access, and lose sight of accounts that should be reclaimed. That creates cost exposure first, but it can also become an access-control problem if stale licences remain available long after the business need has disappeared.
Failure mechanism: The control fails when inventory data is treated as proof of business activity, so renewal and tiering decisions are made without checking whether the service is actually being opened and used.
Impact: Organisations overpay for inactive seats, preserve unnecessary access paths, and weaken the evidence base for licence reclamation, budget approval, and entitlement governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-03 — Mission and Stakeholder Expectations | Licence governance must reflect actual business use and ownership expectations. |
| ID.AM-01 — Physical Devices and Systems Inventoried | Install counts are discovery data, so inventory discipline underpins the subject. | |
| Recommendation — Align SaaS licence decisions to documented business use and accountable ownership. Use inventory as discovery input, not as proof of active licence use. | ||
| NIST SP 800-53 Rev 5 | AU-2 — Audit Events | Usage-based governance depends on retained activity evidence for entitlement review. |
| AC-2 — Account Management | Unused SaaS seats are an account and entitlement management issue. | |
| Recommendation — Log application activity needed to justify renewals and reclaim decisions. Review, disable, or reclaim inactive accounts and licences on a defined cadence. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Licence governance here is really about controlling who retains access. |
| Recommendation — Revoke or reduce access when usage evidence no longer supports the entitlement. | ||
Practitioner Guidance
What to prioritise: Set a decision rule that requires recent usage evidence before a renewal or upgrade is approved. If the product is installed but has no meaningful activity in the review window, route it to reclaim, downgrade, or business-owner exception review.
What to verify: Confirm that your reporting can distinguish install status, authentication events, and true application activity. A useful licence dashboard should answer whether the seat was used, how recently it was used, and whether the user can still justify the entitlement.
Common mistake: Treating endpoint presence as adoption. That shortcut is convenient for reporting, but it produces inflated active-seat counts and makes licence governance look healthier than it is.
Practitioner takeaway: The right control objective is not to count installed software, but to prove that the entitlement is being exercised in a way that justifies keeping it.
Related resources from NHI Mgmt Group
- How should security teams govern data access when data catalogs alone do not show who can use sensitive information?
- How should security teams govern non-human identities at scale?
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities in Salesforce?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org