Adapting to a changed environment has become a familiar task for every
organisation. The pandemic pushed businesses into remote working and digital
delivery far faster than anyone had planned for, and the tooling followed.
That change touched every department, but it is arguably people in software
asset management who have faced the most radical version of it. Specifically:
how to adapt a discipline built around installed software to an organisation
that now buys most of its applications by subscription, per user, on a card,
without asking.
This article looks at where SaaS is taking the software asset manager, the
challenges that come with it, and how the role has to change to keep up.
The future of SaaS
SaaS is where software buying has gone, and the scale is no longer marginal.
The average enterprise portfolio now runs to 305 SaaS applications, and
organisations spend an average of $55.7M a year on SaaS. That is not a category
to manage on the side of a compliance programme.
SaaS offers flexibility and choice — two things that rise to the top of most
organisations’ wish lists — but it does not come without obstacles. As SaaS
takes the largest share of the software market, SAM managers have to prepare
for a licensing landscape that behaves differently to the one they trained on.
Traditional software asset management was built to give visibility of an
on-premises environment: what is installed, where, and whether entitlement
covers it. SaaS asks for something more active. It asks you to centralise
information about applications nobody told you about, understand how they are
actually being used across the business, and hold enough control to act on what
you find.
Lessons for a software asset manager
Accept SaaS applications as the new normal
After a period of upheaval, there is an understandable pull towards familiar,
reliable management methods. That is no longer an option.
The first lesson is simply accepting the new reality, so you can identify and
develop the skills and practices that managing distributed SaaS environments
actually requires. The discipline has not been retired. The evidence base has
moved.
Understand the decentralisation of IT
IT teams often take the lead on new software investments. That is unlikely to
stay true. Departments well outside IT’s purview are comfortable procuring the
SaaS applications they need, when they need them, because it lets them improve
how they work quickly. The challenge is how software asset managers keep
control of that without becoming the department that says no.
This is where a SaaS management capability earns its place. The objective is
complete visibility of the applications in use, with the added benefits of
better security, better decisions and real cost control.
The practical question is how that visibility is obtained, because asking
people is not a method. CerteroX SaaS Management converges three independent
signals: identity provider sync from Entra ID and Okta, authoritative user and
licence lists pulled through 47 vendor connectors, and a browser extension that
detects SaaS domains and attributes time-on-app per user. What each of the
three misses, the other two tend to catch. Applications resolve against a
catalogue of more than 35,000, so what comes back is a named application with an
owner rather than an unrecognised domain.
That is what joins the dots — visibility of SaaS adoption across the business,
and a detailed understanding of how those investments are being used, so
licensing can be right-sized and costs controlled.
Add value to the business
Once you have full visibility of the SaaS in use, the organisation can act on
it.
Like self-hosted software, SaaS subscriptions accumulate waste as the
organisation evolves. An application that was central six months ago becomes
obsolete or forgotten — a change of focus, a change of team — and the monthly
charge carries on regardless. Across the market, 46% of SaaS licences go unused;
the average organisation uses 54% of what it pays for.
To manage the cost of subscriptions accurately, a SAM manager needs the full
picture: active users, infrequently active users, inactive users, and the
per-user subscription cost against each. That is precisely the shape of the
data CerteroX SaaS Management holds. Unused licences are flagged at 30 or more
days of zero usage. An Active Usage Rate sits next to each application, with
power users identified separately. Cost per licensed user is shown against cost
per active user, which is usually the number that ends an argument. Upcoming
renewals carry days-to-renewal and a utilisation rate, so the negotiation starts
from evidence rather than the vendor’s account of your adoption.
Finding the waste is the easy half. Acting on it is what the role is judged on,
so the actions are built in — reclaim, reassign, downgrade tier, archive, remind
or dismiss — with realised savings and realised avoidance tracked by fiscal
quarter. App Rationalization ranks overlapping applications by recoverable
saving, which is how you decide between the three project tools three teams
each bought independently.
Consider the security risks
Security is a first-order concern in a decentralised software portfolio.
Subscriptions that let a team work faster also let data leave, and the
decentralised nature of the buying is exactly what makes it hard to see.
The SAM manager’s task is full visibility of every application, so you can
assess whether it is being used efficiently, what happens to that access when
someone leaves, and where buying power is being fragmented across duplicate
contracts.
Offboarding is the sharpest version of this. Someone leaves, their identity
provider account is disabled on day one, and their Figma, Notion and Linear
seats carry on billing while a third-party OAuth grant they consented to two
years ago still holds read access to the company drive. CerteroX SaaS
Management keeps an offboarding checklist per user showing every licence they
held and the revocation status behind each one — pending, in progress or
complete — with the estimated monthly cost of whatever is still open. OAuth
grants are discovered and scored from 0 to 100 on data sensitivity, scope
breadth, consent age and dormancy, and can be revoked in one click or as a
workflow action.
The newest version of the problem is AI. Spend on AI-native applications at
large enterprises grew 393%, and almost none of it arrives through procurement.
AI tools are classified from application feature tags in the catalogue rather
than a fixed list, so the detection set grows without anyone maintaining it, and
the Shadow AI dashboard ranks adoption risk by the share of the organisation
using each tool — because ten people on a given assistant is a different problem
to a thousand.
None of this replaces software asset management. It extends it. The publisher
audits have not stopped, the entitlement maths on Oracle, IBM and SAP is
unchanged, and CerteroX SAM still computes an effective licence position
continuously. What has changed is that the software asset manager is now also
accountable for a portfolio nobody installed, and the evidence for it has to
come from somewhere other than a scan of the network.