Everything IT and finance teams need to know about discovering, governing, and optimising their SaaS stack — from first inventory to continuous governance.
The average mid-market organisation now runs somewhere between 100 and 300 SaaS applications, and the number grows every quarter. Most IT teams can name fewer than half of them from memory. SaaS management is the discipline of closing that gap — building and maintaining a complete, accurate picture of every application in use, who uses it, what it costs, and whether it still earns its place. This guide walks through the full lifecycle, from the first discovery exercise to a continuous governance rhythm.
Traditional software asset management assumed software was purchased centrally, installed on managed devices, and licensed in bulk. SaaS broke every one of those assumptions. Anyone with a corporate card or a free-tier signup can adopt a tool in minutes, and that tool lives in the vendor's cloud rather than on a device IT controls. The result is SaaS sprawl: a stack that grows organically, department by department, with no single owner and no complete inventory.
The consequences fall into three buckets. Cost: duplicate tools, unused seats, and forgotten auto-renewals quietly inflate spend by 20–30% in most organisations. Security and compliance: every ungoverned app is a place company data might live outside your controls, which matters directly for frameworks like ISO/IEC 27001 and SOC 2. Operational risk: when the person who bought a tool leaves, the knowledge of why it exists and who depends on it often leaves with them.
You cannot manage what you cannot see, so every SaaS management programme starts with discovery. There are four complementary methods, and the best results come from combining them rather than relying on any single one.
Identity provider / SSO logs are the highest-signal source. Any application an employee has signed into with "Log in with Microsoft" or "Log in with Google" leaves an authentication record, even if the app was never sanctioned. Exporting and analysing 90 days of SSO logs typically surfaces the majority of your real stack.
Finance and expense data catches the tools paid for on corporate cards or through accounts payable — including the ones bought outside procurement. Reconciling vendor payments against your known application list reliably surfaces shadow spend.
Directory and licence APIs from platforms like Microsoft 365 and Google Workspace expose assigned licences and, in the case of Microsoft Entra ID, per-user application assignments and usage. Browser or endpoint signals can round out the picture for web apps that never touch SSO, though this requires a privacy-conscious deployment.
Discovery produces a list; the inventory turns that list into an asset register. For each application, capture the fields that make it manageable: owner and department, contract and renewal date, cost and billing cycle, number of purchased versus assigned seats, data sensitivity classification, and whether it is connected to SSO. The inventory is the single source of truth that every later decision — a renewal, an audit, an offboarding — draws on.
The most common mistake is treating the inventory as a one-time spreadsheet. A stack that changes weekly needs a living record that updates automatically from your integrations, not a snapshot that is stale within a month.
Governance is where SaaS management shifts from visibility to control. The goal is not to block everything — that just pushes shadow IT further underground — but to bring new tools through a lightweight, fast approval path and to keep the inventory complete as the stack evolves. A good governance model assigns every application an owner, records a data processing agreement where personal data is involved (a direct requirement under the UK GDPR), and routes procurement through a channel that captures contract terms at the point of purchase.
With a complete inventory and basic governance in place, optimisation is where the money is. The three biggest levers are consistent across almost every organisation: reclaiming unused seats, consolidating tools that do the same job, and right-sizing licence tiers to actual usage. Applying FinOps discipline — the same financial-accountability practice used for cloud infrastructure — to SaaS routinely surfaces 15–30% in recoverable spend without removing a single tool anyone actually uses.
SaaS management is not a project with an end date; it is an operating rhythm. The stack keeps changing, so the inventory, the governance checks, and the optimisation reviews all need a cadence. A workable rhythm looks like: automated discovery running continuously, a monthly review of new applications and utilisation outliers, and a renewal review that begins 90 days before every contract end date. The organisations that get lasting value from SaaS management are the ones that turn it into a habit rather than an annual fire drill.
Discover your full SaaS stack, surface unused seats, and never miss a renewal — book a walkthrough with our team.
Book a demoA step-by-step framework for conducting a thorough licence audit — identifying what you own, what you're paying, and where the waste is hiding.
Practical tactics for optimising SaaS spend through right-sizing, consolidation, and smarter negotiation — without disrupting the teams who depend on these tools.
A vendor-by-vendor framework for managing renewals proactively — including negotiation tactics, notice-period strategies, and escalation workflows.
Ronke
Liceo product guide · AI assistant
Hi, I'm Ronke, Liceo's product guide. I can help you understand how we bring licence, vendor, and spend visibility together, or walk through plans and integrations. What are you trying to solve today?