Manual tracking fails because it records perception, not authoritative access state. Dashboards, surveys, and expense reports can miss dormant accounts, shadow IT, and hidden integrations, so they cannot reliably support least privilege or offboarding. Identity teams need governed inventory and entitlement evidence instead of self-reported usage data.
Why manual SaaS tracking breaks down as an identity control
Manual SaaS tracking is a snapshot of what people think exists, not a live record of who or what can actually access the service. That matters because identity control depends on current authority, not reported usage. Once permissions are spread across admins, purchased seats, OAuth grants, shared accounts, and forgotten connectors, manual lists quickly drift away from the real access state.
Where the tracking model loses authoritative access state
The core failure is that SaaS usage data and identity evidence are not the same thing. An expense report may show a subscription, a manager may confirm use, and a survey may name an owner, but none of those sources proves whether the account still exists, whether access was removed after role change, or whether a token still authorizes a background integration. For that reason, manual tracking cannot reliably support offboarding or least privilege.
This is also why governed inventory matters more than self-reported adoption. The identity control question is not “who says they use the app?”, it is “which identities, sessions, and delegations can still reach it right now?” When that answer lives in spreadsheets, the organization depends on stale human memory and partial reporting instead of evidence from the control plane.
Manual tracking also struggles with hidden relationships. A SaaS app may look unused from a user survey while still receiving automated API traffic, service-to-service calls, or delegated access through another platform. Those indirect paths are exactly where dormant access and shadow integration risk tends to survive, because the visible seat list no longer reflects the true trust chain.
Why offboarding and least privilege need governed evidence
Offboarding fails when the record of access is assembled after the fact. If the inventory cannot show the complete set of users, service accounts, tokens, and integrations attached to the application, teams cannot prove that access was removed everywhere it mattered. The same limitation undermines least privilege, because privilege reviews based on reported use usually miss the permissions nobody remembered to report.
For identity teams, the practical fix is a governed inventory that is tied to entitlement evidence, owner accountability, and lifecycle events. That means linking SaaS applications to authoritative sources of truth, then tracking changes in access state as part of joiner-mover-leaver workflows rather than as a quarterly admin exercise. NHIMG’s NHI Lifecycle Management Guide and Identity Security Programme Guide both reinforce the same operational point: lifecycle control only works when ownership, discovery, and revocation are part of the process, not an afterthought.
Manual tracking is especially weak when the SaaS estate includes machine-facing access. A service may have no active human users at all and still hold valuable privileges through API keys, OAuth grants, or delegated admin access. That is why identity control has to include non-human access paths, not just named employee accounts. The broad NHI issue set in Top 10 NHI Issues is relevant here because stale access, excessive privilege, and ownership gaps are often the first things manual tracking misses.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Manual SaaS tracking fails because access state and account lifecycle are not authoritative. |
| IA-5 — Authenticator Management | Manual tracking misses the credentials and tokens that still authorize SaaS access. | |
| AC-6 — Least Privilege | Self-reported usage cannot show whether SaaS permissions remain excessive. | |
| Recommendation — Use AC-2 to maintain authoritative SaaS account inventories and remove stale access promptly. Use IA-5 to govern secret, token, and credential lifecycle for SaaS access. Use AC-6 to recertify SaaS entitlements against actual job need and revoke excess access. | ||
| CIS Controls v8 | CIS-5 — Account Management | The issue is incomplete account visibility and stale SaaS access records. |
| Recommendation — Centralise SaaS account inventory and disable stale accounts as part of account management. | ||
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems within the organization are inventoried | A governed SaaS inventory is the underlying control gap manual tracking leaves unresolved. |
| Recommendation — Maintain a current SaaS inventory that is tied to access owners and entitlement evidence. | ||
Practitioner Guidance
What to prioritise: Start by replacing application self-reporting with evidence of actual entitlements, active accounts, and active delegations. If a SaaS app cannot produce an authoritative access record, treat its inventory data as incomplete until proven otherwise.
What to verify: For each SaaS application, verify the owner, the current user set, the admin set, the connected integrations, and the revocation path. If any one of those is missing, the control is not ready for offboarding decisions.
Common mistake: Teams often equate “unused” with “safe to ignore.” In practice, low-visibility apps are where dormant accounts, orphaned tokens, and cross-system permissions persist longest.
Practitioner takeaway: Manual SaaS tracking is useful for discovery, but not for control. Treat it as a lead generator, then anchor access decisions in governed entitlement evidence and lifecycle enforcement.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org