Salesforce is one of the most widely deployed applications in the world. It is
also one of the easiest to overspend on, because almost everything that drives
the cost of it happens without anyone deciding to spend more money.
Seats are not reclaimed when people leave. Admins install packages from the
AppExchange that nobody reviews afterwards. Storage consumption creeps. And the
renewal arrives with a number on it that nobody forecast, because the number was
never being tracked.
The average enterprise portfolio runs to 305 applications, and 46% of SaaS
licences go unused — the average organisation is actively using just 54% of
what it pays for. On the infrastructure side, wasted cloud spend runs at
29%, up for the first time in five years.
In almost every case the root cause is the same: nobody has visibility of which
cloud applications have been deployed, what they are used for, who owns them and
what they cost.
Shadow IT, cloud sprawl and bill shock
Three distinct failures compound into one invoice.
Shadow IT is any system running inside the organisation without explicit
approval — an application specified and paid for by a department other than IT.
IT does not know it exists, cannot support it, and has not assessed it. It is
the largest single source of both unmanaged security exposure and unmanaged
spend.
Cloud sprawl is what happens when an organisation stops monitoring what it
has already bought. It covers unmanaged infrastructure instances, and it covers
applications like Salesforce, Microsoft 365 and Google Workspace where user
accounts are paid for month after month and never used.
Bill shock is the culmination of the first two. Someone signs up at a
heavily discounted introductory rate outside procurement, and the renewal
reprices at list. A user base grows a few seats at a time until it crosses a
tier boundary. Consumption inside an application quietly rises until the
subscription is upgraded. Each individual movement is too small to trigger a
conversation. The aggregate is not.
Why Salesforce in particular
Salesforce has the characteristics that make all three worse.
Seats outlive people. Employees join and leave continuously. Unless
deprovisioning is enforced, licences accumulate in an unallocated or dormant
state and are renewed automatically because nobody has a report showing which
ones nobody has opened.
Admins can extend the platform. AppExchange packages get installed over
time, often for a project that finished years ago, and are rarely removed. The
instance fills with legacy packages that carry their own data models, permission
sets and integration users.
Salesforce enforces org-level limits. API requests, custom fields, objects
and storage are all capped. Adding packages consumes headroom against those caps
without anyone tracking it. The API limit is the one that bites hardest:
Salesforce enforces a rolling 24-hour allowance per org, and once you exceed it
further API calls are refused until earlier requests age out of the window.
Integrations fail, marketing automation stops triggering, and data integrity
suffers — for reasons that have nothing to do with the integration that broke.
None of these are Salesforce failing. They are an unmanaged instance behaving
exactly as designed.
Governance is necessary and insufficient
The instinctive response is policy. Define who may buy, who may install, and
what must happen when someone leaves.
Do it — but do not expect it to hold on its own. Policy administration is
manual, and manual controls degrade. Somebody will always install a package.
Somebody will always exceed a licence limit. A leaver’s seat will always be
missed, usually the week the person handling offboarding is on annual leave.
What closes the gap is making the current position continuously visible, and
making the corrective action a single step rather than a project.
What CerteroX SaaS Management does about it
This is the part of the original article that most needed rewriting. In 2019 the
honest answer was that a SaaS management tool could pull data from your cloud
applications into one place, and the rest was down to you. That is no longer the
answer.
Discovery from three converging signals. An identity provider sync from
Entra ID or Okta, connector syncs that pull the authoritative user and licence
list from the vendor’s own API, and a browser extension that detects SaaS
domains, time-on-app and per-user attribution. Salesforce is covered by a
connector, and the browser signal is what catches the applications no connector
would ever be pointed at, because nobody in IT knows they are in use. Forty-seven
connectors ship today, resolving against a catalogue of over 35,000
applications.
Unused licence detection. Seats with 30 or more days of zero usage are
surfaced automatically, with cost per licensed user shown against cost per
active user — the pair of numbers that turns “we have 900 Salesforce seats” into
a decision.
Offboarding you can prove finished. Every departing user gets a checklist
showing each licence they hold, the connector status behind it, and whether
revocation is pending, in progress or complete — plus the estimated monthly cost
of anything still open. A wasted-spend metric tracks licences still held by
people who have left. A bulk deprovision wizard handles multi-select
offboarding after a restructure or a divestment.
App rationalisation. Overlap between applications is detected and ranked by
recoverable saving, which is the form of that analysis a finance director will
act on. Upcoming renewals are listed with days-to-renewal against utilisation
rate, so the seat count is reviewed before the renewal rather than after it.
OAuth grants. The third-party applications your users have consented to are
discovered and risk-scored from 0 to 100 on data sensitivity, scope breadth,
consent type and dormancy. Grants can be revoked in one click, or automatically
as a workflow action. This is the part of Salesforce and Microsoft 365 sprawl
that is a security problem rather than a cost problem, and it is invisible to
spend analysis.
Automation instead of administration. The workflow engine gives you eight
triggers, eleven conditions and thirteen actions on one canvas — so “when a user
has not opened Salesforce in 45 days, notify their manager, then reclaim the
seat if there is no response” is a rule that runs, not a process somebody
remembers.
Every provisioning and deprovisioning step is written to an audit log, and a
dedicated Auditor role exists in the six-tier permission model so the evidence
can be handed over without granting change rights.
Where Salesforce licensing itself needs interrogating rather than just counting,
CerteroX SAM carries a dedicated Salesforce licence engine alongside those for
Microsoft, Oracle, IBM, SAP and Adobe.
The version of this problem that did not exist in 2019
Everything above was written about SaaS. It now applies at least as sharply to
AI tools, and it is moving faster: +393% growth in AI-native application spend
at large enterprises.
Those tools arrive the way Salesforce AppExchange packages arrived: adopted by
individuals, expensed rather than procured, and frequently granted access to
company data through an OAuth consent nobody reviewed.
CerteroX SaaS Management classifies AI tools from application feature tags in
the catalogue rather than a hardcoded list, so the detection set grows on its
own as new tools appear. The Shadow AI dashboard ranks adoption risk by the
share of the organisation using each tool, because ten people using an
unsanctioned model is a different problem from a thousand, and each detected
tool carries a status of managed, blocked or ignored.
The lesson from Salesforce transfers directly. Costs do not spiral because of a
decision somebody made. They spiral because of a series of decisions nobody
recorded.