Managed IT · June 5, 2026 · intSignal Team

SaaS Management: Taming License Sprawl and Shadow Subscriptions

Share this article

The spending IT can't see

Ask an IT director how many SaaS applications their company uses and you will usually get a number that is confidently wrong — low by a wide margin. Any employee with a credit card and a business need can sign up for a tool in minutes, and thousands of them have. The result is SaaS sprawl: a long tail of subscriptions IT never provisioned, spread across departments, renewing automatically, and invisible on any central inventory.

Sprawl is not just a budget problem, though the wasted money is real — most organizations pay for a meaningful share of seats that sit unused. It is a security and compliance problem too, because every unmanaged app is a place company data lives outside IT's controls, an account that never gets deprovisioned when someone leaves, and an integration granting third-party access nobody reviewed. SaaS management is the practice of getting this under control without becoming the department that says no to everything.

You can't manage what you can't see: discovery first

Every SaaS management effort starts with discovery, because the tools you do not know about are exactly the ones creating risk and cost. There are several complementary ways to find them, and mature programs use more than one:

  • Financial data. Expense reports and corporate card statements are the richest source of shadow SaaS. A recurring charge to a vendor nobody in IT recognizes is a subscription you did not know you had. Accounts payable often knows about spend that IT does not.
  • Single sign-on logs. If apps authenticate through your identity provider, its logs show what is actually being used and by whom — one of the cleanest signals available.
  • Network and endpoint telemetry. Traffic to SaaS domains and browser or cloud-access data reveal apps that bypass SSO entirely.
  • Direct vendor and OAuth grants. Reviewing which third-party applications users have granted access to your Microsoft 365 or Google Workspace tenant surfaces integrations that quietly hold data access.

The output is a real inventory: every application, its owner, its user count, its cost, and its data sensitivity. That inventory is the foundation everything else builds on, and it is worth folding into your broader IT asset management so software subscriptions are tracked with the same rigor as hardware.

Reclaim the licenses you're already paying for

Once you can see the portfolio, the fastest savings come from license optimization — matching what you pay for to what you actually use. The waste hides in a few predictable places:

  • Inactive users. Seats assigned to people who left, changed roles, or simply stopped using the tool. Usage data tells you which licenses have gone cold, and reclaiming them is pure savings.
  • Over-provisioned tiers. Users on a premium license who only use basic features. Downgrading to the right tier costs nothing in capability.
  • Duplicate tools. Three overlapping apps that do the same job because three teams each bought their own. Consolidating onto one both cuts cost and reduces the surface you have to secure.
  • Unused seats in a bulk contract. Enterprise agreements sized for a headcount you no longer have, waiting for the renewal where you right-size the commitment.

The single most effective moment for savings is the renewal. Automatic renewals lock in last year's over-provisioned size by default. Track every renewal date, review actual usage in the weeks before, and go into the negotiation with data on what you truly need. Consistent renewal discipline typically recovers more than any one-time cleanup.

Offboarding is where SaaS management meets security

The most dangerous gap in an unmanaged SaaS estate is what happens when someone leaves. Central systems get deprovisioned through HR-triggered workflows; the random app a departed employee signed up for two years ago does not. Their account stays active, their access to company data persists, and nobody is watching it.

Closing this gap is both a security control and a licensing win:

  • Connect deprovisioning to identity. Where an app integrates with your identity and access management platform, a leaver's access is cut everywhere at once. This is the strongest argument for pulling shadow apps under SSO — it makes offboarding automatic.
  • Maintain a per-app offboarding list for the tools that cannot integrate, so the manual revocations actually happen instead of being forgotten.
  • Reclaim the seat at the same time. Every account you close on departure is also a license you stop paying for, which is why offboarding hygiene and cost control reinforce each other.

An orphaned SaaS account is both a recurring charge and an unmonitored door into your data. Fixing offboarding closes both at once.

Govern new SaaS without becoming the department of no

The instinct after discovering sprawl is to lock everything down and require IT approval for every tool. That fails. Users adopted shadow SaaS because it solved real problems faster than IT did, and a hard "no" just pushes the behavior further underground. Effective governance channels the demand rather than blocking it:

  • A fast, lightweight intake path for requesting a new app, so the sanctioned route is genuinely quicker than a rogue credit-card signup. If your process is slower than a self-service trial, you will lose.
  • A tiered review that scales scrutiny to risk. A low-risk tool touching no sensitive data gets a quick yes; an app that will hold customer or financial data gets a real security and data-handling review.
  • A short list of sanctioned tools for common needs, so most requests resolve to "use the one we already have and secure" — which also curbs duplication.
  • Clear data rules about what categories of information may go into externally hosted tools, so users know the boundaries without asking every time.

The goal is to be the department that provides good options quickly, not the one that blocks everything slowly.

Run it as an ongoing practice

SaaS management is not a project you finish; the portfolio changes constantly as teams adopt, abandon, and renew tools. Sustain it with a light operating rhythm:

  • A living inventory kept current from your discovery signals, not a spreadsheet someone updated once.
  • A renewal calendar with usage reviewed before each date, so no contract renews on autopilot at last year's size.
  • Periodic usage sweeps to reclaim cold licenses and flag newly appeared shadow apps.
  • Ownership assigned per application, so every tool has a business owner accountable for whether it is still needed.

A quarterly review of spend, usage, and new discoveries is enough to keep sprawl from rebuilding. The work compounds: the more current your inventory, the faster each cycle gets.

Where to start

Begin with discovery you can do this month: pull expense data and SSO logs, and build the first honest inventory of what your organization actually runs and pays for. That list alone almost always reveals redundant tools, cold licenses, and apps IT never knew existed — enough to fund the rest of the program from the savings.

intSignal helps organizations bring SaaS under control through IT asset management and identity-driven governance, turning invisible subscription sprawl into a managed, right-sized portfolio. If you suspect you are paying for software nobody uses, talk to our team.

Share this article