Because a seat count shows consumption, not whether access is still justified, approved, or properly offboarded. An underused licence may be a cost issue, but an external user or dormant account can also be a lifecycle and compliance issue. Teams need both licence management and entitlement review to make a sound decision.
Why licence counts are a governance signal, not the governance answer
A SaaS licence count tells you what was purchased and consumed, but not whether each active seat still has a legitimate business reason to exist. Governance has to answer who approved the access, whether the assignment still matches role and purpose, and whether the account is still reachable after a change in employment, vendor status, or project scope.
That distinction matters because a low utilisation report can hide stale access, while a high utilisation report can still include users whose access should have been removed. The operational question is not “how many seats are used?” but “which users, devices, or accounts are still authorised to use them, and under what control?”
What licence usage misses about entitlement and lifecycle
Usage data is a snapshot of consumption, so it is useful for cost optimisation and renewals, but it does not prove entitlement. A user may log in rarely and still be fully approved, or may be active every day despite no longer needing access. That is why seat analytics need to be joined to joiner-mover-leaver processes, approval history, and periodic access review.
The same gap shows up with external users, contractors, and shared service access. A licence can remain technically assigned after the business relationship ends, especially when offboarding is delayed or delegated across teams. For governance, the control question is whether the account can still act in the tenant, not whether the licence meter shows value received.
When teams treat licence dashboards as the full control, they miss the difference between commercial efficiency and access assurance. A dormant account may justify reclaiming a seat, but an account with retained entitlement may also represent an unresolved authorization, ownership, or retention problem that deserves separate treatment.
How to read SaaS reports without confusing spend with control
The useful view is a layered one: licence assignment, effective entitlement, and actual activity should all be compared. This is especially important in SaaS environments where admin portals, self-service provisioning, and third-party integrations can create access paths that are invisible in billing reports. For a broader control lens, teams often anchor the discussion in NIST Cybersecurity Framework 2.0, because the governance question spans inventory, access protection, detection, and recovery rather than only procurement.
From an access-control perspective, the key is to separate economic waste from control failure. The strongest checks are entitlement recertification, offboarding verification, and exception handling for accounts that remain active for operational reasons. Where organisations need a formal control catalogue, NIST SP 800-53 Rev 5 Security and Privacy Controls provides the access-control and accountability structure needed to make that distinction auditable.
For SaaS specifically, software licence reporting should be treated as evidence, not as proof. If the report cannot show owner, purpose, and review date, then it is missing the governance dimension that decides whether the account should stay, be reapproved, or be removed.
Risk and Threat Considerations
Licence overhang creates more than waste. It can preserve dormant access paths, allow former staff or contractors to retain usable accounts, and make it harder to spot accounts that were never properly offboarded. In regulated or high-trust environments, that is an access-control and auditability problem, not just a finance issue.
Failure mechanism: Organisations rely on consumption metrics, so accounts that still authenticate successfully are left in place even after the underlying entitlement rationale has expired.
Impact: That gap can lead to unauthorised access, failed leaver controls, audit findings, and a wider blast radius if a stale account is later abused.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | SaaS licences need business-purpose context beyond raw seat counts. |
| ID.AM-03 — Hardware Assets are Inventoried | Seat tracking depends on an accurate inventory of active accounts and service access. | |
| Recommendation — Define who owns each SaaS application and why the access exists. Maintain an authoritative inventory of active SaaS users and linked accounts. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Licence assignment must be governed as account lifecycle and access control, not only usage. |
| AU-6 — Audit Record Review, Analysis, and Reporting | Usage logs and admin evidence are needed to validate whether access is still justified. | |
| Recommendation — Review, disable, and remove SaaS accounts when entitlement no longer exists. Correlate usage, approval, and offboarding evidence during access reviews. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Licence counts must be reconciled with current access rights and revocation decisions. |
| Recommendation — Recertify SaaS access rights on a defined schedule and remove stale entitlement. | ||
Practitioner Guidance
What to verify: For each high-value SaaS application, verify the owner, approval source, last access, and current business justification separately. If the licence cannot be tied to a current entitlement, treat it as a governance exception rather than a simple optimisation candidate.
Decision rule: If the account is unused but still approved, reclaim the seat while preserving the entitlement record for review. If the account is used but not clearly approved, prioritise access review and offboarding validation before any cost discussion.
Practitioner takeaway: Seat counts are useful for spend management, but governance only becomes sound when licence data is joined to entitlement, lifecycle, and offboarding evidence.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org