Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do organisations lose control of SaaS renewals…
Governance, Ownership & Risk

Why do organisations lose control of SaaS renewals and license waste in decentralized environments?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Governance, Ownership & Risk

Control breaks down when software buying is distributed across teams without a single inventory, renewal process, or ownership model. Licenses auto renew, shadow tools accumulate, and former users may retain access after departure. Finance then discovers the cost late, which makes the problem harder and more expensive to fix.

Why This Matters for Security Teams

Decentralised buying turns SaaS renewals into an identity and governance problem, not just a procurement problem. When each team can adopt tools independently, there is no reliable inventory of who owns the contract, which users still need access, or whether a license is tied to an active business need. That is how renewal waste, orphaned seats, and unnoticed access drift accumulate.

This also creates a security gap. SaaS access often persists long after a project ends, an employee moves teams, or a vendor relationship changes. NHI Mgmt Group notes that only 5.7% of organisations have full visibility into their service accounts in the Ultimate Guide to NHIs, which is a useful warning signal for broader identity sprawl. The same pattern appears in SaaS estate management: if you cannot see the full set of accounts and owners, you cannot reliably remove waste or enforce least privilege.

Security teams also miss the timing problem. Renewal notices arrive late, usage data is fragmented, and finance only sees the cost after auto-renewal has already locked it in. In practice, many security teams encounter license waste only after renewal invoices have landed, rather than through intentional ownership and review controls.

How It Works in Practice

The practical fix is to treat SaaS renewals as a controlled lifecycle with named ownership, usage evidence, and revocation steps. A usable process starts with a single inventory of applications, contract dates, admin accounts, and business owners. From there, each service needs an access review cadence, a renewal decision point, and a defined offboarding path for users and privileged roles.

Security and IT should also separate active use from nominal assignment. A seat that exists in the directory is not proof of value. Usage telemetry, login frequency, feature adoption, and department sponsorship all matter. Where tools support it, short-lived access and role review should replace standing entitlements, especially for admin consoles and integration accounts. This aligns with the broader control themes in the NHI Lifecycle Management Guide and the Guide to the Secret Sprawl Challenge, because unused access and stale credentials often travel together.

Operationally, teams should:

  • Require a business owner for every SaaS app and every renewal.
  • Review seat usage before renewal windows, not after invoices arrive.
  • Remove dormant users, former employees, and duplicate accounts on a fixed schedule.
  • Track admin, API, and integration accounts separately from human licenses.
  • Trigger cancellation or downsizing when utilisation falls below an agreed threshold.

For security leaders, this is also where identity hygiene and spend control overlap. OWASP’s OWASP Non-Human Identity Top 10 reinforces the point that unmanaged service accounts and keys are not just technical debt; they are ongoing exposure. These controls tend to break down when procurement is decentralised across subsidiaries or fast-moving teams because no single owner can reconcile contracts, access, and actual usage.

Common Variations and Edge Cases

Tighter renewal control often increases administrative overhead, requiring organisations to balance spend reduction against speed for teams that need software quickly. That tradeoff is real, especially in startups, research groups, and global business units where local autonomy is part of how work gets done.

Best practice is evolving for environments with heavy self-service procurement. Some organisations use chargeback or showback to make waste visible, while others use approval gates only for high-risk tools or contract values. There is no universal standard for this yet, but the direction is clear: without ownership and telemetry, renewal decisions are guesswork. The Guide to NHI Rotation Challenges is relevant here because stale access behaves like stale credentials: it lingers, becomes normalised, and is hard to clean up once embedded.

Edge cases matter. Shared departmental licenses, usage-based SaaS, and platform bundles can hide waste because one renewal covers many services. In those cases, a simple seat-count model is not enough. Teams need service-by-service ownership, audit trails for admin access, and a way to distinguish temporary project demand from baseline consumption. For high-risk environments, the lessons from incidents like the Salesloft OAuth token breach and the BeyondTrust API key breach are clear: once access is left standing without review, the cost is not only financial.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Unmanaged SaaS access and stale service accounts mirror non-human identity sprawl.
NIST CSF 2.0ID.AMAsset management is needed to see all SaaS tools, owners, and renewal dates.
NIST AI RMFGOVERNGovernance is needed to assign accountability for decentralized software decisions.
NIST Zero Trust (SP 800-207)PR.AC-1Least-privilege access is undermined when SaaS entitlements persist after need ends.
CSA MAESTROGOV-02Distributed SaaS control needs lifecycle governance across teams and cloud services.

Assign decision rights for SaaS acquisition, renewal, and deprovisioning under a formal governance model.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org