Skip to content

Salesforce: How to Reduce and Control the Rising Cost of Cloud Applications

Salesforce instances grow wild — leavers keep their seats, admins install AppExchange packages nobody reviews, and the renewal arrives larger than anyone forecast. Where the waste actually accumulates, and the controls that stop it recurring.

Salesforce is one of the most widely deployed applications in the world. It is also one of the easiest to overspend on, because almost everything that drives the cost of it happens without anyone deciding to spend more money.

Seats are not reclaimed when people leave. Admins install packages from the AppExchange that nobody reviews afterwards. Storage consumption creeps. And the renewal arrives with a number on it that nobody forecast, because the number was never being tracked.

The average enterprise portfolio runs to 305 applications, and 46% of SaaS licences go unused — the average organisation is actively using just 54% of what it pays for. On the infrastructure side, wasted cloud spend runs at 29%, up for the first time in five years.

In almost every case the root cause is the same: nobody has visibility of which cloud applications have been deployed, what they are used for, who owns them and what they cost.

Shadow IT, cloud sprawl and bill shock

Three distinct failures compound into one invoice.

Shadow IT is any system running inside the organisation without explicit approval — an application specified and paid for by a department other than IT. IT does not know it exists, cannot support it, and has not assessed it. It is the largest single source of both unmanaged security exposure and unmanaged spend.

Cloud sprawl is what happens when an organisation stops monitoring what it has already bought. It covers unmanaged infrastructure instances, and it covers applications like Salesforce, Microsoft 365 and Google Workspace where user accounts are paid for month after month and never used.

Bill shock is the culmination of the first two. Someone signs up at a heavily discounted introductory rate outside procurement, and the renewal reprices at list. A user base grows a few seats at a time until it crosses a tier boundary. Consumption inside an application quietly rises until the subscription is upgraded. Each individual movement is too small to trigger a conversation. The aggregate is not.

Why Salesforce in particular

Salesforce has the characteristics that make all three worse.

Seats outlive people. Employees join and leave continuously. Unless deprovisioning is enforced, licences accumulate in an unallocated or dormant state and are renewed automatically because nobody has a report showing which ones nobody has opened.

Admins can extend the platform. AppExchange packages get installed over time, often for a project that finished years ago, and are rarely removed. The instance fills with legacy packages that carry their own data models, permission sets and integration users.

Salesforce enforces org-level limits. API requests, custom fields, objects and storage are all capped. Adding packages consumes headroom against those caps without anyone tracking it. The API limit is the one that bites hardest: Salesforce enforces a rolling 24-hour allowance per org, and once you exceed it further API calls are refused until earlier requests age out of the window. Integrations fail, marketing automation stops triggering, and data integrity suffers — for reasons that have nothing to do with the integration that broke.

None of these are Salesforce failing. They are an unmanaged instance behaving exactly as designed.

Governance is necessary and insufficient

The instinctive response is policy. Define who may buy, who may install, and what must happen when someone leaves.

Do it — but do not expect it to hold on its own. Policy administration is manual, and manual controls degrade. Somebody will always install a package. Somebody will always exceed a licence limit. A leaver’s seat will always be missed, usually the week the person handling offboarding is on annual leave.

What closes the gap is making the current position continuously visible, and making the corrective action a single step rather than a project.

What CerteroX SaaS Management does about it

This is the part of the original article that most needed rewriting. In 2019 the honest answer was that a SaaS management tool could pull data from your cloud applications into one place, and the rest was down to you. That is no longer the answer.

Discovery from three converging signals. An identity provider sync from Entra ID or Okta, connector syncs that pull the authoritative user and licence list from the vendor’s own API, and a browser extension that detects SaaS domains, time-on-app and per-user attribution. Salesforce is covered by a connector, and the browser signal is what catches the applications no connector would ever be pointed at, because nobody in IT knows they are in use. Forty-seven connectors ship today, resolving against a catalogue of over 35,000 applications.

Unused licence detection. Seats with 30 or more days of zero usage are surfaced automatically, with cost per licensed user shown against cost per active user — the pair of numbers that turns “we have 900 Salesforce seats” into a decision.

Offboarding you can prove finished. Every departing user gets a checklist showing each licence they hold, the connector status behind it, and whether revocation is pending, in progress or complete — plus the estimated monthly cost of anything still open. A wasted-spend metric tracks licences still held by people who have left. A bulk deprovision wizard handles multi-select offboarding after a restructure or a divestment.

App rationalisation. Overlap between applications is detected and ranked by recoverable saving, which is the form of that analysis a finance director will act on. Upcoming renewals are listed with days-to-renewal against utilisation rate, so the seat count is reviewed before the renewal rather than after it.

OAuth grants. The third-party applications your users have consented to are discovered and risk-scored from 0 to 100 on data sensitivity, scope breadth, consent type and dormancy. Grants can be revoked in one click, or automatically as a workflow action. This is the part of Salesforce and Microsoft 365 sprawl that is a security problem rather than a cost problem, and it is invisible to spend analysis.

Automation instead of administration. The workflow engine gives you eight triggers, eleven conditions and thirteen actions on one canvas — so “when a user has not opened Salesforce in 45 days, notify their manager, then reclaim the seat if there is no response” is a rule that runs, not a process somebody remembers.

Every provisioning and deprovisioning step is written to an audit log, and a dedicated Auditor role exists in the six-tier permission model so the evidence can be handed over without granting change rights.

Where Salesforce licensing itself needs interrogating rather than just counting, CerteroX SAM carries a dedicated Salesforce licence engine alongside those for Microsoft, Oracle, IBM, SAP and Adobe.

The version of this problem that did not exist in 2019

Everything above was written about SaaS. It now applies at least as sharply to AI tools, and it is moving faster: +393% growth in AI-native application spend at large enterprises.

Those tools arrive the way Salesforce AppExchange packages arrived: adopted by individuals, expensed rather than procured, and frequently granted access to company data through an OAuth consent nobody reviewed.

CerteroX SaaS Management classifies AI tools from application feature tags in the catalogue rather than a hardcoded list, so the detection set grows on its own as new tools appear. The Shadow AI dashboard ranks adoption risk by the share of the organisation using each tool, because ten people using an unsanctioned model is a different problem from a thousand, and each detected tool carries a status of managed, blocked or ignored.

The lesson from Salesforce transfers directly. Costs do not spiral because of a decision somebody made. They spiral because of a series of decisions nobody recorded.

Related reading

Other posts covering the same ground.

From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.