SaaS was supposed to make software cheaper to run. For most organisations it has made software harder to see, and the two are not unrelated. You cannot govern what nobody has counted.
The scale of the problem
The portfolio is much larger than anyone thinks. The average enterprise now runs 305 SaaS applications. That number is not the result of a deliberate purchasing strategy; it is the accumulated residue of hundreds of individual decisions taken quickly and reasonably by people who needed a tool. SaaS is also increasingly not a choice — more publishers are moving to the model because it suits them.
The spend is large and it is difficult to forecast. Organisations spend an average of $55.7 million a year on SaaS. Unlike a perpetual licence, that figure moves on its own: seats get added mid-term, vendors reprice at renewal, and consumption-based components bill after the fact rather than before.
Most of it buys nothing. Around 46% of SaaS licences go unused — the average organisation actually uses 54% of what it pays for. In money, that is roughly $19.8 million a year per organisation wasted on unused SaaS licences alone. A one-size-fits-all approach to licence allocation makes onboarding simpler and over-allocation inevitable.
AI is compounding it. Spend on AI-native applications grew 393% at large enterprises. That is a new category arriving at speed, largely through the same decentralised buying route that produced the SaaS portfolio in the first place — and often on a personal card.
Why it becomes a financial black hole
Multiple teams pay for overlapping functionality because no one team can see the whole portfolio. Three project trackers, two whiteboards, two note-taking apps and four ways to make a diagram is a normal finding, not an unusual one. The cost is not just the duplicate subscriptions; it is the integration work, the admin overhead and the data spread across tools that do not talk to each other.
Renewals nobody saw coming
Without centralised renewal tracking, subscriptions auto-renew by default — including for tools nobody has opened in a year. A renewal you notice ninety days out is a negotiation. A renewal you notice on the invoice is a payment.
Licences that were never activated
Provisioning is easy and reclaiming is awkward, so the ratchet only turns one way. Most of us can name a tool we were assigned, used twice, and abandoned in favour of a different way of working. Nobody took the seat back, because nobody knew.
The security and compliance side
Limited oversight. Applications bought outside IT are not in the offboarding process, not in the access review, and not on anyone’s list when a vendor discloses a breach. The disclosure lands and nobody can answer the only question that matters: are we exposed?
A wider attack surface. Every SaaS tool that replaces an on-premises one moves data outside your perimeter. A threat actor who compromises one large SaaS vendor gets many organisations’ data at once, and you inherit that risk the moment someone signs up.
Dormant accounts. An unused licence is usually an inactive account, and inactive accounts are attractive targets — still valid, rarely monitored, often with lingering OAuth grants that hold read access to a company drive long after the person who consented to them left. Waste and risk are the same finding viewed from two angles.
What to do about it
Centralise discovery
One signal is never enough. Identity data tells you what was formally granted. Vendor APIs tell you what the vendor is billing you for. Only browser-level evidence tells you what people are actually opening.
CerteroX SaaS Management converges all three: identity provider sync from Entra ID and Okta including MFA enrolment, 47 vendor connectors pulling authoritative user and licence lists, and a browser extension that records SaaS domains, time-on-app and per-user attribution. Applications resolve against a catalogue of more than 35,000, so what comes back is a named product with a category rather than a domain you have to go and look up. Anything appearing in one signal but not the others is, by definition, what nobody told you about — including OAuth grants consented to on your users’ behalf.
That extends to AI. Shadow AI detection classifies tools from application feature tags in the catalogue rather than a hardcoded list, so the detection set keeps up with a market that changes monthly, and adoption risk is ranked by the share of your organisation using each tool.
Monitor usage continuously
Track licence use in real time so idle accounts surface on their own. Unused licence detection at 30 or more days of zero usage, an Active Usage Rate per application, cost per licensed user set against cost per active user, and an Optimization Score across utilisation, response and policy adherence. The point is to make the reclaim conversation routine and evidence-backed rather than annual and contested.
Automate governance
Enforce purchasing policy, access control and offboarding through automation tied to identity and HR systems, not through reminders. A workflow engine with eight triggers, eleven conditions and thirteen actions on one canvas handles provisioning and deprovisioning across Entra, Okta, Google and Microsoft 365, and every step is written to an audit log. Deprovisioning respects each vendor’s reality: some have no suspend API and need a soft mode that strips roles, some need file ownership transferred before the account is deactivated.
Rationalise and consolidate
Eliminate redundant applications, negotiate at the portfolio level rather than the team level, and align purchases to actual usage patterns. App rationalisation detects functional overlap and ranks it by recoverable saving, so the consolidation argument arrives with a number attached.
Control renewals deliberately
Review contracts early and renegotiate on measured utilisation, not on last year’s spend. An upcoming-renewals view with days-to-renewal alongside the utilisation rate turns that into a routine review rather than a scramble.
Forecast honestly
Model per-user and per-unit cost, predict renewals, and set per-application budgets with warning and critical thresholds so the overspend conversation happens before the invoice rather than after it. Report realised savings and realised avoidance by fiscal quarter — the number finance will ask for.
Final take
Unchecked SaaS sprawl is not an inconvenience. It is a standing tax on your IT budget, your security posture and your operational speed. The fix is unglamorous and entirely achievable: centralise discovery, automate governance, reclaim waste, govern renewals, and make measured data rather than assumption the basis of every spend decision.
If your CFO is not asking for this yet, they will be.