Every few years someone announces that SaaS has killed Software Asset Management. The reasoning is superficially sound: you no longer own the software, so you can no longer be under-licensed, so what is left to manage?
Quite a lot, as it turns out. The risk has not disappeared. It has moved.
Recognise the differences
On-premises SAM and SaaS SAM are not interchangeable, and the first mistake is treating them as one job.
SaaS applications can be bought in a couple of clicks. They need no infrastructure, no change window and no IT involvement — which means they are routinely bought without IT’s knowledge, sometimes on a personal credit card and reclaimed on expenses.
That is a visibility problem before it is anything else. How do I know what is actually in use across the organisation? Without that answer, cost and security exposure are both unbounded.
The scale is not small. The average enterprise portfolio runs to 305 SaaS applications. Very few IT functions could name 305 applications unprompted.
In the SaaS world, SAM is less about preparing for a compliance audit and more about utilisation. The question changes from am I licensed? to am I using what I am paying for?
That change is easy to understand. You are not buying ownership of anything; you are renting named access. The risk of being found under-licensed largely disappears by default.
What does not disappear is cost risk — and it gets worse, not better. Because licences are so easy to consume, SaaS platforms drift into routine over-licensing. And the administrative burden inverts: instead of managing one volume agreement covering thousands of users, you are now managing entitlement user by user, by name, across dozens of vendors with dozens of different metrics.
The waste rate runs at 46% of SaaS licences going unused, with the average organisation using just 54% of what it buys. That is the number the discipline exists to attack.
Security
Traditional on-premises software needed routine patching and maintenance. With SaaS that burden sits with the provider — which is not the same as it going away.
Due diligence still applies at procurement, and especially at integration. If business data flows between systems, ask the questions before signing rather than after an incident:
- Where is my data stored?
- How does the data flow between these systems?
- Is the data encrypted, in transit and at rest?
If those questions are never asked because the application was never procured through a process, you are one vendor breach away from finding out the answers publicly.
You also need a central record of every SaaS application in use. When a provider is compromised, the first question is always whether you use them. That should take seconds to answer, not a week of emails.
Knowing who has access matters just as much. On-premises, software was installed on a corporate device; when someone left, the device went back and access went with it. In SaaS, access lives in each vendor’s portal. Unless a licence is explicitly revoked, a departed employee can still log in.
So: if someone in marketing leaves on Friday, can you list every SaaS application they had access to, and remove it, before Monday?
That used to be a rhetorical question. It is now a product feature. CerteroX SaaS Management builds an offboarding checklist per user showing every licence they hold, the connector status behind each one, and whether revocation is pending, in progress or complete — with the estimated monthly cost of whatever is still open. It also surfaces OAuth grants the user consented to on the organisation’s behalf, scored from 0 to 100 on data sensitivity, scope, consent type and dormancy, and revocable in one click or as a workflow action.
The awkward truth about offboarding is that most platforms will tell you a user was offboarded. Far fewer will show you the evidence that every seat actually closed.
Governance still comes first
Governance remains the focal point, because it is what makes monitoring and management possible in the first place. Check that you have SaaS procurement and access policies, then check you have the tooling to enforce and evidence them.
A SaaS access policy also needs balance. Too lax and you lose control. Too strict and people quietly route around you — which recreates exactly the shadow layer the policy was written to prevent.
Avoiding automatic overspend
Moving to SaaS has real operational advantages. It also carries a specific financial failure mode.
You accumulate seats. You keep paying for inactive users. Contracts auto-renew regardless of how heavily — or how rarely — they were used. Costs surge quietly rather than dramatically, which is why they survive so long.
The counter is unglamorous: know the utilisation, know the renewal date, and act before the renewal rather than during it.
Getting in control
SaaS cannot be managed without tooling that sees it. Here is the order of work.
Step 1: Get visibility
You cannot govern an application you do not know exists, so discovery has to come from more than one direction. CerteroX SaaS Management converges three signals:
- A browser extension that detects SaaS domains, time-on-app and per-user attribution — this is what catches the credit-card purchase nobody declared.
- Identity provider sync from Entra ID and Okta, including MFA enrolment state.
- Vendor connectors — 47 shipping today — that pull the authoritative user and licence list straight from the vendor.
Each signal alone has blind spots. Together they close most of them. Discovered applications resolve against a catalogue of more than 35,000 applications, which is also what drives feature-tag classification and overlap detection.
The same catalogue makes Shadow AI a first-class capability rather than a keyword list: AI tools are classified from application feature tags, so the detection set grows as the market does, and adoption risk is ranked by the share of the organisation using each tool. Ten people using an AI assistant is a different problem from a thousand.
Step 2: Gather utilisation data
You need to know what is used, by whom, and how much of it.
Unused licence detection triggers at 30 or more days of zero usage. Alongside it sit Active Usage Rate, power-user identification, cost per licensed user set against cost per active user, and upcoming renewals ranked with days-to-renewal and current utilisation — which is the report you actually want in your hand three months before a renewal, not three days.
App Rationalization goes further and detects functional overlap between applications, ranked by recoverable saving. Two collaboration tools and three design tools is a procurement conversation, not a discovery one, but you need the evidence to open it.
The data is also worth more when it is enriched. Combining SaaS usage with device inventory, Active Directory information and the rest of the asset record gives you the whole picture rather than one piece of it — which is the argument for holding SaaS in the same platform as everything else rather than in a standalone tracker.
Step 3: Turn it into decisions
Data that nobody acts on is overhead. Turn it into rules.
Reclaim, reassign, downgrade tier, archive, remind and dismiss are all actions you can take from the finding itself, and all available to the workflow engine — eight triggers, eleven conditions and thirteen actions on one canvas. Provisioning and deprovisioning run across Entra, Okta, Google Workspace, Microsoft 365 and more, and there is a bulk deprovision wizard for multi-select offboarding.
Deprovisioning respects each vendor’s reality, which sounds like a detail until it is your problem. HubSpot has no suspend API, so there is a soft mode that strips roles and a hard mode that deletes. Box transfers file ownership before deactivating an account. ServiceNow locks the account and strips every role and group membership. A generic connector cannot do any of that.
Every step is written to an audit log, so what you have at the end is not just a saving but a defensible record of how it was made.
The point
SaaS is not the end of SAM. It is the reason SAM had to grow up.
The decentralised nature of SaaS data makes a normalised, central record more valuable than it ever was on-premises — one place that holds SaaS, cloud, hardware and on-premises software together, so licences can be right-sized against actual use and decisions can be made from evidence rather than an invoice.
That is what CerteroX SAM and CerteroX SaaS Management are built to do, and they run on the same data model as the rest of the platform rather than beside it.