Skip to content

How SaaS is Changing the Role of the SAM Manager

SaaS moved software buying out of IT and turned the software asset manager from a compliance auditor into an active manager of subscriptions, usage and access. What that shift demands, and what it now takes to keep up with it.

Adapting to a changed environment has become a familiar task for every organisation. The pandemic pushed businesses into remote working and digital delivery far faster than anyone had planned for, and the tooling followed.

That change touched every department, but it is arguably people in software asset management who have faced the most radical version of it. Specifically: how to adapt a discipline built around installed software to an organisation that now buys most of its applications by subscription, per user, on a card, without asking.

This article looks at where SaaS is taking the software asset manager, the challenges that come with it, and how the role has to change to keep up.

The future of SaaS

SaaS is where software buying has gone, and the scale is no longer marginal. The average enterprise portfolio now runs to 305 SaaS applications, and organisations spend an average of $55.7M a year on SaaS. That is not a category to manage on the side of a compliance programme.

SaaS offers flexibility and choice — two things that rise to the top of most organisations’ wish lists — but it does not come without obstacles. As SaaS takes the largest share of the software market, SAM managers have to prepare for a licensing landscape that behaves differently to the one they trained on.

Traditional software asset management was built to give visibility of an on-premises environment: what is installed, where, and whether entitlement covers it. SaaS asks for something more active. It asks you to centralise information about applications nobody told you about, understand how they are actually being used across the business, and hold enough control to act on what you find.

Lessons for a software asset manager

Accept SaaS applications as the new normal

After a period of upheaval, there is an understandable pull towards familiar, reliable management methods. That is no longer an option.

The first lesson is simply accepting the new reality, so you can identify and develop the skills and practices that managing distributed SaaS environments actually requires. The discipline has not been retired. The evidence base has moved.

Understand the decentralisation of IT

IT teams often take the lead on new software investments. That is unlikely to stay true. Departments well outside IT’s purview are comfortable procuring the SaaS applications they need, when they need them, because it lets them improve how they work quickly. The challenge is how software asset managers keep control of that without becoming the department that says no.

This is where a SaaS management capability earns its place. The objective is complete visibility of the applications in use, with the added benefits of better security, better decisions and real cost control.

The practical question is how that visibility is obtained, because asking people is not a method. CerteroX SaaS Management converges three independent signals: identity provider sync from Entra ID and Okta, authoritative user and licence lists pulled through 47 vendor connectors, and a browser extension that detects SaaS domains and attributes time-on-app per user. What each of the three misses, the other two tend to catch. Applications resolve against a catalogue of more than 35,000, so what comes back is a named application with an owner rather than an unrecognised domain.

That is what joins the dots — visibility of SaaS adoption across the business, and a detailed understanding of how those investments are being used, so licensing can be right-sized and costs controlled.

Add value to the business

Once you have full visibility of the SaaS in use, the organisation can act on it.

Like self-hosted software, SaaS subscriptions accumulate waste as the organisation evolves. An application that was central six months ago becomes obsolete or forgotten — a change of focus, a change of team — and the monthly charge carries on regardless. Across the market, 46% of SaaS licences go unused; the average organisation uses 54% of what it pays for.

To manage the cost of subscriptions accurately, a SAM manager needs the full picture: active users, infrequently active users, inactive users, and the per-user subscription cost against each. That is precisely the shape of the data CerteroX SaaS Management holds. Unused licences are flagged at 30 or more days of zero usage. An Active Usage Rate sits next to each application, with power users identified separately. Cost per licensed user is shown against cost per active user, which is usually the number that ends an argument. Upcoming renewals carry days-to-renewal and a utilisation rate, so the negotiation starts from evidence rather than the vendor’s account of your adoption.

Finding the waste is the easy half. Acting on it is what the role is judged on, so the actions are built in — reclaim, reassign, downgrade tier, archive, remind or dismiss — with realised savings and realised avoidance tracked by fiscal quarter. App Rationalization ranks overlapping applications by recoverable saving, which is how you decide between the three project tools three teams each bought independently.

Consider the security risks

Security is a first-order concern in a decentralised software portfolio. Subscriptions that let a team work faster also let data leave, and the decentralised nature of the buying is exactly what makes it hard to see.

The SAM manager’s task is full visibility of every application, so you can assess whether it is being used efficiently, what happens to that access when someone leaves, and where buying power is being fragmented across duplicate contracts.

Offboarding is the sharpest version of this. Someone leaves, their identity provider account is disabled on day one, and their Figma, Notion and Linear seats carry on billing while a third-party OAuth grant they consented to two years ago still holds read access to the company drive. CerteroX SaaS Management keeps an offboarding checklist per user showing every licence they held and the revocation status behind each one — pending, in progress or complete — with the estimated monthly cost of whatever is still open. OAuth grants are discovered and scored from 0 to 100 on data sensitivity, scope breadth, consent age and dormancy, and can be revoked in one click or as a workflow action.

The newest version of the problem is AI. Spend on AI-native applications at large enterprises grew 393%, and almost none of it arrives through procurement. AI tools are classified from application feature tags in the catalogue rather than a fixed list, so the detection set grows without anyone maintaining it, and the Shadow AI dashboard ranks adoption risk by the share of the organisation using each tool — because ten people on a given assistant is a different problem to a thousand.

None of this replaces software asset management. It extends it. The publisher audits have not stopped, the entitlement maths on Oracle, IBM and SAP is unchanged, and CerteroX SAM still computes an effective licence position continuously. What has changed is that the software asset manager is now also accountable for a portfolio nobody installed, and the evidence for it has to come from somewhere other than a scan of the network.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.