Skip to content

By challenge
Shadow IT

Your catalogue lists forty applications.
Finance is paying for the rest.

Identity provider, vendor APIs and a browser extension converge on the same question from three directions. What comes back is every application in use, who uses it, how often, what it costs and when it renews.

Answered on one platform. One data model across ITAM, SAM, SaaS, Cloud and AI.

Discovery · converging signals

Illustrative

Applications in use this month

Identity provider · 47 connectors · browser extension

Seen by identity provider Entra ID and Okta sign-ins
212
Seen by vendor connector authoritative user and licence lists
68
Seen by browser extension domain, time-on-app, per-user
141
Unique applications
287
Not in the catalogue no owner, no contract, no review
247

SSO coverage

31% · ranked gap list attached

The problem

Three hundred applications arrived one purchase at a time.

SaaS sprawl is the predictable result of a purchase that needs a card, a browser and nothing else.

46%

of SaaS licences go unused — the average organisation uses 54%

Which means the first thing to do with a SaaS budget is usually not to spend it.

  1. 01 discovery by invoice

    You find out about the application when the renewal lands.

    By then it has forty users, three integrations and a business case. The moment to make a decision about it was eleven months ago, when one team started a trial.

    Browser extension detecting SaaS domains, time-on-app and per-user attribution SaaS Management

  2. 02 four tools, one job

    Three project trackers, two design tools, two places to write things down.

    Each was the right call for the team that bought it. Together they are duplicated spend, duplicated onboarding and seven vendors holding your data instead of three.

    App Rationalization — overlap detection ranked by recoverable saving SaaS Management

  3. 03 provisioned at onboarding

    The seat has been provisioned since onboarding and opened twice.

    Nobody reclaims a licence they cannot see, and nobody argues with a renewal quote that matches last year’s headcount. That is how utilisation quietly halves.

    Unused licence detection at 30+ days of zero usage SaaS Management

  4. 04 outside the front door

    The application with your data in it is not behind SSO.

    It was bought by a team, wired to a personal-style login and never routed through identity. Offboarding cannot reach it, MFA does not cover it, and no report lists it.

    SSO Coverage widget with a ranked list of high-value gap applications SaaS Management

  5. The fix is seeing the purchase on the day it happens, and having somewhere for it to land.
How it is actually done

From a list of applications to a managed portfolio.

Discovery is the easy half. What separates a SaaS inventory from SaaS management is what happens in the next three steps.

  1. See every application

    Three signals that fail in different ways, so what one misses another catches.

    • Identity provider sync from Entra ID and Okta including MFA enrolment SaaS Management
    • Connector sync pulling authoritative user and licence lists from the vendor SaaS Management
    • Browser extension detecting SaaS domains, time-on-app and per-user attribution SaaS Management
    • OAuth grant discovery for consented third-party applications SaaS Management
    • Executive Dashboard rolling up apps, users, spend and trend SaaS Management
  2. Rank what is worth doing

    Three hundred applications is a list. Ranked by recoverable spend it is an afternoon’s work.

    • App Rationalization — overlap detection ranked by recoverable saving SaaS Management
    • Usage Summary with Active Usage Rate and power-user identification SaaS Management
    • Cost per licensed user versus cost per active user SaaS Management
    • Optimization Score from 0 to 100 across utilisation, response and adherence SaaS Management
    • Upcoming renewals with days-to-renewal and utilisation rate SaaS Management
  3. Reclaim the spend

    Six actions, one bulk wizard, and a record of what the decision was worth.

    • Unused licence detection at 30+ days of zero usage SaaS Management
    • Actions: reclaim, reassign, downgrade tier, archive, remind, dismiss SaaS Management
    • Bulk deprovision wizard for multi-select offboarding SaaS Management
    • Realized savings, realized avoidance and ROI by fiscal quarter SaaS Management
  4. Give every application an owner

    Sprawl regrows wherever nothing is anybody’s. Four owner types and a budget fix that.

    • Four owner types: application, business, technical and data owner SaaS Management
    • Subscription lifecycle with purchased, assigned, available and oversubscribed SaaS Management
    • Per-application budgets with warning and critical thresholds SaaS Management
    • Workflow engine: 8 triggers, 11 conditions, 13 actions on one canvas SaaS Management
    • Risk assessment on data sensitivity, compliance and business criticality SaaS Management

Ask to see any one of these running in the product itself, on the screen where it happens.

Why three signals

Each one is blind somewhere.

The identity provider cannot see what never touched it. A connector only knows the vendors you have connected. The extension sees a browser and nothing else. Run all three and the blind spots stop lining up.

What each discovery method can and cannot see
What you are trying to find out Identity provider Entra ID and Okta Vendor connector 47 vendor APIs Browser extension domain and time-on-app
An application behind single sign-on Sees it. Every sign-in, plus MFA enrolment Partly. Only vendors you have connected Sees it. Anything opened in a browser
An application bought on a card last Tuesday Blind. No sign-in to see Blind. Nothing to connect to yet Sees it. The first visit is the discovery
Who opens it, and for how long Partly. Sign-in events only Partly. Seat assignment, from the vendor Sees it. Time-on-app, attributed per user
How many seats you are paying for Blind. Access is not entitlement Sees it. The vendor’s own licence list Blind. Usage, never the contract
Something with no browser in front of it Sees it. OAuth grants to third parties Partly. Where a connector exists Blind. Nothing runs in a browser

Every row is answered by at least one column, and no column answers every row. That is the whole argument for running three.

The end state

What good looks like.

The goal is the right number of applications, each with a name against it.

  1. 01

    New applications surface the week somebody buys one.

    The browser extension sees the first sign-in. You get to decide whether the tool becomes sanctioned, consolidated or blocked while that decision is still cheap.

  2. 02

    Renewals arrive with a utilisation figure attached.

    Days-to-renewal next to active usage rate turns the annual conversation from “same again?” into a number you can negotiate against.

  3. 03

    Overlap is measured in money.

    App Rationalization ranks duplicate categories by recoverable saving, so consolidation is argued with a figure attached to each duplicate category.

  4. 04

    Every application has four owners and one budget.

    Application, business, technical and data owner. When something needs a decision there is no search for who is accountable.

  5. 05

    Cost per active user is the number you watch.

    Cost per licensed user flatters everybody. Cost per active user is the one that tells you what the tool is really costing.

Eliminate SaaS sprawl, specifically

Questions worth asking us.

Not the one you came with? Ask it directly and we will answer it in writing.

Is the browser extension surveillance?

It records which SaaS domains are used, for how long, attributed to a user: the same facts your identity provider already logs for anything behind SSO. It is not a keylogger and it does not capture page content. Deploy it to the population where shadow IT is a genuine risk and rely on identity and connector signals elsewhere.

Why does this run three discovery signals at once?

Because no single signal is authoritative for everything. Identity misses whatever never went behind SSO, which is exactly where shadow IT lives. Connectors are authoritative for the 47 vendors you have connected and blind past them, and the browser extension only ever sees a browser.

Can it reclaim licences, or only report on them?

It acts. Reclaim, reassign, downgrade tier, archive, remind or dismiss, individually or through a bulk wizard, with provisioning and deprovisioning across Entra, Okta, Google, M365 and more. Realized savings and realized avoidance are then tracked by fiscal quarter, so the reclamation has a number against it.

How does this handle AI tools, which are the fastest-growing category?

AI tools are classified from application feature tags in the catalogue, so the detection set grows on its own as vendors add AI features to products you already own. The Shadow AI Dashboard then ranks adoption by the share of your organisation using each tool.

What happens to the applications we decide to keep?

They get owners, a subscription record with purchased, assigned, available and oversubscribed counts, a budget with warning and critical thresholds, a risk assessment and a renewal date. At that point the list has become a portfolio somebody manages.

Start with discovery

See what three signals find
that one signal never will.

Applications in use, seats nobody has opened in thirty days, and the ranked list of everything outside SSO, on a populated SaaS position at real scale. Name what you suspect is already out there and the session is built around it.

One session, nothing to connect, and a technical person answering as we go.