Your catalogue lists forty applications.
Finance is paying for the rest.
Identity provider, vendor APIs and a browser extension converge on the same question from three directions. What comes back is every application in use, who uses it, how often, what it costs and when it renews.
Answered on one platform. One data model across ITAM, SAM, SaaS, Cloud and AI.
Discovery · converging signals
IllustrativeApplications in use this month
Identity provider · 47 connectors · browser extension
- Seen by identity provider Entra ID and Okta sign-ins
- 212
- Seen by vendor connector authoritative user and licence lists
- 68
- Seen by browser extension domain, time-on-app, per-user
- 141
- Unique applications
- 287
- Not in the catalogue no owner, no contract, no review
- 247
SSO coverage
31% · ranked gap list attached
The problem
Three hundred applications arrived one purchase at a time.
SaaS sprawl is the predictable result of a purchase that needs a card, a browser and nothing else.
46%
of SaaS licences go unused — the average organisation uses 54%
Which means the first thing to do with a SaaS budget is usually not to spend it.
- 01 discovery by invoice
You find out about the application when the renewal lands.
By then it has forty users, three integrations and a business case. The moment to make a decision about it was eleven months ago, when one team started a trial.
Browser extension detecting SaaS domains, time-on-app and per-user attribution SaaS Management
- 02 four tools, one job
Three project trackers, two design tools, two places to write things down.
Each was the right call for the team that bought it. Together they are duplicated spend, duplicated onboarding and seven vendors holding your data instead of three.
App Rationalization — overlap detection ranked by recoverable saving SaaS Management
- 03 provisioned at onboarding
The seat has been provisioned since onboarding and opened twice.
Nobody reclaims a licence they cannot see, and nobody argues with a renewal quote that matches last year’s headcount. That is how utilisation quietly halves.
Unused licence detection at 30+ days of zero usage SaaS Management
- 04 outside the front door
The application with your data in it is not behind SSO.
It was bought by a team, wired to a personal-style login and never routed through identity. Offboarding cannot reach it, MFA does not cover it, and no report lists it.
SSO Coverage widget with a ranked list of high-value gap applications SaaS Management
- The fix is seeing the purchase on the day it happens, and having somewhere for it to land.
Three of the five disciplines.
Each runs standalone and shares one asset model, so the parts of this that span products need no integration work.
- Primary CerteroX SaaS Management Three discovery signals, 47 connectors, the licence engine and the workflow that acts on it. Product page
- Also applies CerteroX AI Management AI tools classified from feature tags, so the newest sprawl is visible as it starts. Product page
- Also applies CerteroX ITAM Browser monitoring and file metering as discovery methods on the same asset record. Product page
From a list of applications to a managed portfolio.
Discovery is the easy half. What separates a SaaS inventory from SaaS management is what happens in the next three steps.
-
See every application
Three signals that fail in different ways, so what one misses another catches.
- Identity provider sync from Entra ID and Okta including MFA enrolment SaaS Management
- Connector sync pulling authoritative user and licence lists from the vendor SaaS Management
- Browser extension detecting SaaS domains, time-on-app and per-user attribution SaaS Management
- OAuth grant discovery for consented third-party applications SaaS Management
- Executive Dashboard rolling up apps, users, spend and trend SaaS Management
-
Rank what is worth doing
Three hundred applications is a list. Ranked by recoverable spend it is an afternoon’s work.
- App Rationalization — overlap detection ranked by recoverable saving SaaS Management
- Usage Summary with Active Usage Rate and power-user identification SaaS Management
- Cost per licensed user versus cost per active user SaaS Management
- Optimization Score from 0 to 100 across utilisation, response and adherence SaaS Management
- Upcoming renewals with days-to-renewal and utilisation rate SaaS Management
-
Reclaim the spend
Six actions, one bulk wizard, and a record of what the decision was worth.
- Unused licence detection at 30+ days of zero usage SaaS Management
- Actions: reclaim, reassign, downgrade tier, archive, remind, dismiss SaaS Management
- Bulk deprovision wizard for multi-select offboarding SaaS Management
- Realized savings, realized avoidance and ROI by fiscal quarter SaaS Management
-
Give every application an owner
Sprawl regrows wherever nothing is anybody’s. Four owner types and a budget fix that.
- Four owner types: application, business, technical and data owner SaaS Management
- Subscription lifecycle with purchased, assigned, available and oversubscribed SaaS Management
- Per-application budgets with warning and critical thresholds SaaS Management
- Workflow engine: 8 triggers, 11 conditions, 13 actions on one canvas SaaS Management
- Risk assessment on data sensitivity, compliance and business criticality SaaS Management
Ask to see any one of these running in the product itself, on the screen where it happens.
Each one is blind somewhere.
The identity provider cannot see what never touched it. A connector only knows the vendors you have connected. The extension sees a browser and nothing else. Run all three and the blind spots stop lining up.
| What you are trying to find out | Identity provider Entra ID and Okta | Vendor connector 47 vendor APIs | Browser extension domain and time-on-app |
|---|---|---|---|
| An application behind single sign-on | Sees it. Every sign-in, plus MFA enrolment | Partly. Only vendors you have connected | Sees it. Anything opened in a browser |
| An application bought on a card last Tuesday | Blind. No sign-in to see | Blind. Nothing to connect to yet | Sees it. The first visit is the discovery |
| Who opens it, and for how long | Partly. Sign-in events only | Partly. Seat assignment, from the vendor | Sees it. Time-on-app, attributed per user |
| How many seats you are paying for | Blind. Access is not entitlement | Sees it. The vendor’s own licence list | Blind. Usage, never the contract |
| Something with no browser in front of it | Sees it. OAuth grants to third parties | Partly. Where a connector exists | Blind. Nothing runs in a browser |
Every row is answered by at least one column, and no column answers every row. That is the whole argument for running three.
What good looks like.
The goal is the right number of applications, each with a name against it.
- 01
New applications surface the week somebody buys one.
The browser extension sees the first sign-in. You get to decide whether the tool becomes sanctioned, consolidated or blocked while that decision is still cheap.
- 02
Renewals arrive with a utilisation figure attached.
Days-to-renewal next to active usage rate turns the annual conversation from “same again?” into a number you can negotiate against.
- 03
Overlap is measured in money.
App Rationalization ranks duplicate categories by recoverable saving, so consolidation is argued with a figure attached to each duplicate category.
- 04
Every application has four owners and one budget.
Application, business, technical and data owner. When something needs a decision there is no search for who is accountable.
- 05
Cost per active user is the number you watch.
Cost per licensed user flatters everybody. Cost per active user is the one that tells you what the tool is really costing.
Questions worth asking us.
Not the one you came with? Ask it directly and we will answer it in writing.
Is the browser extension surveillance?
It records which SaaS domains are used, for how long, attributed to a user: the same facts your identity provider already logs for anything behind SSO. It is not a keylogger and it does not capture page content. Deploy it to the population where shadow IT is a genuine risk and rely on identity and connector signals elsewhere.
Why does this run three discovery signals at once?
Because no single signal is authoritative for everything. Identity misses whatever never went behind SSO, which is exactly where shadow IT lives. Connectors are authoritative for the 47 vendors you have connected and blind past them, and the browser extension only ever sees a browser.
Can it reclaim licences, or only report on them?
It acts. Reclaim, reassign, downgrade tier, archive, remind or dismiss, individually or through a bulk wizard, with provisioning and deprovisioning across Entra, Okta, Google, M365 and more. Realized savings and realized avoidance are then tracked by fiscal quarter, so the reclamation has a number against it.
How does this handle AI tools, which are the fastest-growing category?
AI tools are classified from application feature tags in the catalogue, so the detection set grows on its own as vendors add AI features to products you already own. The Shadow AI Dashboard then ranks adoption by the share of your organisation using each tool.
What happens to the applications we decide to keep?
They get owners, a subscription record with purchased, assigned, available and oversubscribed counts, a budget with warning and critical thresholds, a risk assessment and a renewal date. At that point the list has become a portfolio somebody manages.
See what three signals find
that one signal never will.
Applications in use, seats nobody has opened in thirty days, and the ranked list of everything outside SSO, on a populated SaaS position at real scale. Name what you suspect is already out there and the session is built around it.
One session, nothing to connect, and a technical person answering as we go.