SV-008

Enterprise SaaS Portfolio Governance and Renewal Intelligence

One governed view of the SaaS estate — discovery across SSO, expense and browser signals, identity-correlated usage, duplicate and overlap detection, and a renewal calendar that produces negotiation positions rather than surprises.

Software Value 16 min read 11-stage operating workflow Illustrative — outcomes not guaranteed
At a glance
Challenge
SaaS spend, subscriptions, usage and renewals live in different systems, so duplicate licences, orphaned accounts and overlapping applications are invisible at executive level.
Approach
Discover across SSO, finance and browser signals, consolidate to publisher and tenant, correlate to identity, then govern renewals from a single portfolio view.
Primary KPI
% of total SaaS spend represented in the governed single-pane portfolio view.
Impact
One estate view, shelfware removed before renewal and negotiations entered with evidenced consumption.
01

Executive Summary

SaaS governance fails on coverage before it fails on optimisation. An organisation that can see sixty per cent of its SaaS spend can optimise that sixty per cent very effectively and still be surprised every quarter by the rest. The first objective is therefore not savings — it is the proportion of actual SaaS spend that appears in the governed view at all.

Discovery has to be multi-signal. SSO and identity provider logs find applications that are federated. Expense and accounts-payable data finds applications bought on a corporate card. Browser extension telemetry finds applications that are neither. Each signal alone leaves a material gap; together they close most of it, and the residue becomes a named, shrinking list.

The optimisation levers are then well understood: assigned-but-unused licences, orphaned accounts belonging to leavers, duplicate tenants from acquisitions or team-level purchases, overlapping SKU tiers on the same user, and functional overlap between applications doing the same job for different departments. What converts these into value is a renewal calendar with enough lead time to act before the auto-renewal clause bites.

02

Business Challenge

The structural problem is that no single system owns SaaS. Procurement sees contracts it was asked to sign. Finance sees invoices and card transactions. IT sees applications integrated with SSO. Each has a partial and internally consistent view, and nobody reconciles them. Executive reporting therefore describes whichever subset the reporting function happens to own.

The renewal problem compounds it. SaaS agreements auto-renew, often with a notice period measured in weeks. Without a renewal calendar and a usage position prepared in advance, the organisation discovers the renewal after the notice window closes and renews at current quantity because there is no alternative. The optimisation opportunity existed for eleven months and was available for none of them.

03

Typical Symptoms

Organisations that need this playbook usually recognise several of the following.

  • Nobody can state total SaaS spend, only the portion visible to whichever function is reporting.
  • Applications appear on corporate card statements that IT has never seen.
  • The same publisher is contracted under two or more tenants following an acquisition or a team-level purchase.
  • Users hold overlapping tiers of the same product — for example M365 E3 and F3 on the same identity.
  • Leavers retain active SaaS accounts because deprovisioning covers only SSO-federated applications.
  • Renewals are discovered after the notice period has closed, so auto-renewal happens by default.
  • Assigned licence counts are used as the renewal baseline because usage data was never collected.
  • Two departments run functionally identical tools with separate contracts and separate owners.
04

Business Risks

Business risks by domain, with the risk and its impact
DomainRiskImpact if unaddressed
Operational Deprovisioning that covers only SSO-federated applications Leavers retain active accounts in non-federated applications, creating both continuing subscription cost and a standing access risk that no periodic review will find.
Commercial Renewals discovered after the notice window has closed Auto-renewal proceeds at current quantity. The optimisation opportunity was available all year and exercisable in none of it.
Compliance Applications procured outside IT and security review Corporate data is processed by services that have had no data-protection, security or residency assessment, and the organisation cannot enumerate them to answer a regulator.
Technology Duplicate tenants of the same publisher across entities Volume aggregation is lost, users may hold licences in both tenants, and consolidation is invisible because no view spans them.
05

Operating Workflow and Reference Architecture

Operating workflow

11 stages, each producing a defined output. This workflow is specific to this playbook; the category lifecycle on the Software Value index is an overview of how the playbooks relate, not how any one of them runs.

Wide diagram — scroll horizontally, or use the arrow keys once it has focus. A text description is available to screen readers.

Enterprise SaaS Portfolio Governance and Renewal Intelligence — operating workflowA 11-stage operating workflow for enterprise saas portfolio governance and renewal intelligence: SaaS Discovery, Publisher & Tenant Consolidation, Contract & Subscription Baseline, Identity Correlation, Usage & Activity Analysis, Duplicate & Overlap Detection, Mover & Leaver Validation, Reclaim / Downgrade / Consolidate, Renewal Scenario Modelling, Contract Negotiation Input, Executive SaaS Portfolio Dashboard. Each stage shows the output it produces.01SaaS DiscoveryOUTPUTApplications found viaSSO, expense, browser andnetwork signals02Publisher & TenantConsolidationOUTPUTInstances consolidated toa single publisher andtenant view03Contract &SubscriptionBaselineOUTPUTContracts, terms,quantities and noticeperiods captured04Identity CorrelationOUTPUTAccounts correlated toEntra ID identities andemployment status05Usage & ActivityAnalysisOUTPUTAssigned versus activelicences assessed perapplication06Duplicate & OverlapDetectionOUTPUTDuplicate assignments,tiers and functionaloverlap identified07Mover & LeaverValidationOUTPUTOrphaned and departed-useraccounts identified acrossall apps08Reclaim / Downgrade/ ConsolidateOUTPUTActions raised, owned andtracked to completion09Renewal ScenarioModellingOUTPUTQuantity and tierscenarios modelled aheadof the notice window10Contract NegotiationInputOUTPUTEvidenced consumptionposition provided to thenegotiation team11Executive SaaSPortfolio DashboardOUTPUTCoverage, spend,utilisation and renewalpipeline published

Illustrative SaaS governance workflow. Discovery is multi-signal by design — SSO, finance and browser telemetry each miss a different part of the estate. Renewal modelling must complete before the contractual notice window. Outcomes are not guaranteed.

Reference architecture

The systems, data and controls the workflow above runs on.

Wide diagram — scroll horizontally, or use the arrow keys once it has focus. A text description is available to screen readers.

Reference architecture — SaaS portfolio governanceA four-layer reference architecture. Layer one, discovery signals, covers single sign-on and identity provider logs, expense and accounts-payable data, browser extension telemetry, network and egress data, and direct publisher admin API connections. Layer two, consolidation, covers publisher and tenant normalisation, contract and subscription baseline, notice period and renewal date capture, and spend reconciliation. Layer three, analysis, covers identity correlation, assigned versus active licence analysis, duplicate and tier overlap detection, orphaned account identification and functional overlap assessment. Layer four, governance outputs, covers the reclaim and downgrade backlog, the renewal calendar and scenario models, negotiation input packs, the consolidation pipeline and the executive portfolio dashboard.LAYER 1Discovery signalsMulti-signal bynecessitySSO and identity providerlogs (Entra ID, Okta)Expense andaccounts-payable dataBrowser extensiontelemetryNetwork and egress dataPublisher admin APIconnectionsLAYER 2ConsolidationOne record perpublisherPublisher and tenantnormalisationContract and subscriptionbaselineNotice period and renewal datecaptureSpend reconciliation to financeLAYER 3AnalysisWhere the opportunityis foundIdentity correlation andemployment statusAssigned versus activelicence analysisDuplicate assignment andtier overlapOrphaned and inactiveaccount identificationFunctional overlapbetween applicationsDuplicate tenantdetectionLAYER 4GovernanceoutputsActed on beforerenewalReclaim and downgradebacklogRenewal calendar andscenario modelsNegotiation input packConsolidation pipelineExecutive portfoliodashboard

Illustrative reference architecture. No single discovery signal is sufficient: SSO misses non-federated applications, expense data misses those inside a larger invoice, and browser telemetry misses server-to-server integrations.

06

Implementation Approach

A representative implementation sequences in 5 phases. Duration and overlap vary with estate size, data quality and the number of source systems in scope.

Phase 1

Multi-signal discovery and spend coverage

Establish how much of the estate you can actually see. Coverage is the first KPI because every subsequent number is a percentage of it.

  • SSO and identity discovery. Extract federated application usage from Entra ID or the identity provider, which finds the sanctioned, integrated portion of the estate.
  • Finance signal. Analyse accounts-payable and corporate card data for software vendors, which finds applications procured outside IT entirely.
  • Browser telemetry. Deploy browser extension discovery to managed browsers to find applications that are neither federated nor separately invoiced.
  • Spend reconciliation. Reconcile discovered applications against total software spend and report the coverage percentage with the residual named.
  • Shadow SaaS register. Record applications found outside the sanctioned estate with their data sensitivity, so security and privacy review can be prioritised.
Business value

Coverage becomes a measured, reportable figure, and the unseen residue becomes a named list that shrinks rather than an unknown that persists.

Phase 2

Consolidation and contract baseline

Turn discovered instances into one record per publisher, with the commercial terms that determine what can be changed and when.

  • Publisher and tenant normalisation. Consolidate name variants, subsidiaries and separate tenants into a single publisher record while retaining the underlying instances.
  • Duplicate tenant detection. Identify multiple tenants of the same publisher across entities and quantify the aggregation opportunity.
  • Contract capture. Capture term, quantity, tier, price, auto-renewal clause and — critically — the notice period, since it determines the action deadline.
  • Renewal calendar. Build a forward calendar keyed to the notice deadline rather than the renewal date, with owners assigned per renewal.
  • Ownership assignment. Assign a named business owner to every application; unowned applications are the ones that renew by default.
Business value

Every application has an owner, a renewal notice deadline and a contract position, which is what makes proactive renewal governance possible at all.

Phase 3

Identity correlation and utilisation analysis

Establish who holds what and who actually uses it. Assigned counts are not utilisation.

  • Identity correlation. Correlate application accounts to Entra ID identities and employment status, including contractors and guests.
  • Assigned versus active analysis. Compare assigned licences to demonstrable activity per application, using publisher admin APIs where available rather than sign-in proxies.
  • Orphaned account detection. Identify accounts belonging to departed users, particularly in non-federated applications that automated deprovisioning does not reach.
  • Duplicate and tier overlap. Detect users holding multiple tiers of the same product or duplicate accounts across tenants.
  • Inactivity thresholds. Agree inactivity definitions per application with the business owner rather than applying a single global threshold.
Business value

Shelfware becomes specific — named users, named applications, stated inactivity periods — which is the only form in which a business owner will accept a reclaim.

Phase 4

Optimisation and consolidation execution

Act on the findings before the renewal, not during it.

  • Reclaim execution. Reclaim unused and orphaned licences with the business owner's acceptance recorded, and return them to the assignable pool.
  • Tier downgrade. Downgrade users whose usage does not justify their tier, with the activity evidence attached to the decision.
  • Tenant consolidation. Consolidate duplicate tenants where commercially and operationally viable, sequencing against contract dates.
  • Functional overlap review. Assess applications performing the same function for different departments and route genuine duplication to portfolio rationalisation.
  • Deprovisioning integration. Extend leaver deprovisioning beyond SSO-federated applications, using the discovery signals to define the full account set.
Business value

Shelfware is removed and duplicate tenants consolidated during the term, so the renewal quantity reflects an already-optimised estate.

Phase 5

Renewal intelligence and executive reporting

Convert the portfolio view into negotiation leverage and a standing executive picture.

  • Pre-notice modelling. Complete quantity, tier and term scenario modelling before the notice window opens, so cancellation and reduction remain live options.
  • Negotiation input pack. Provide the negotiation team with evidenced consumption, utilisation trend, overlap position and benchmark context per renewal.
  • Renewal outcome tracking. Track modelled versus realised renewal outcome so forecasting improves and the governance function's value is evidenced.
  • Executive dashboard. Publish spend coverage, utilisation, shelfware, duplicate position, shadow SaaS and the renewal pipeline in one standing view.
  • New application intake. Route new SaaS requests through a check against the existing portfolio, so overlap is prevented rather than discovered.
Business value

Renewals are entered with an evidenced position while reduction is still contractually possible, and the executive sees one number for the SaaS estate rather than three.

07

Technology Components

Capability categories with representative examples. Many organisations can build the governed view from an existing identity provider, expense system and SAM platform before acquiring a dedicated SaaS management platform. Products are named as examples, not recommendations.

Discovery

  • Microsoft Entra ID / Okta SSO logs
  • Expense and AP data
  • Browser extension telemetry
  • Network egress analysis
  • Publisher admin APIs

Portfolio management

  • SaaS management platform capability
  • Contract repository
  • Renewal calendar
  • Publisher and tenant normalisation
  • Application ownership register

Identity and lifecycle

  • Entra ID user and status data
  • Joiner-mover-leaver workflow
  • Access reviews
  • Deprovisioning automation

Reporting and action

  • Executive portfolio dashboard
  • Reclaim and downgrade backlog
  • Renewal scenario model
  • Negotiation input pack
08

Governance Considerations

Governance should be proportionate. The six areas below are the minimum set that has to be explicit for this capability to hold up under internal review.

Ownership

A named SaaS portfolio owner accountable for coverage and the renewal calendar; a business owner per application accountable for utilisation and renewal decisions.

Decision rights

Business owners approve reclaim and downgrade for their users; the portfolio owner approves new application onboarding; renewal decisions above a value threshold go to the governance forum.

Policies

SaaS procurement policy routing purchases through the portfolio check, deprovisioning policy covering non-federated applications, and an ownership policy requiring a named owner before purchase.

Approvals

New SaaS applications approved only after an overlap check against the existing portfolio; auto-renewals above a value threshold require an explicit renew decision before the notice deadline.

Evidence

Utilisation evidence supporting each reclaim and downgrade, the contract and notice period on record per application, and the renewal decision with its rationale and approver.

Controls

Renewal notice-deadline alerting with sufficient lead time, orphaned account detection across all discovered applications, coverage threshold reporting, and an overlap gate on new purchases.

09

Success Metrics

Primary KPI

Governed spend coverage

Share of actual SaaS spend represented in the single-pane governed portfolio view, reconciled against finance rather than against the discovery tool's own total.

≥ 95% of total SaaS spend

Operational KPIs

Publishers discovered Tracked against baseline Distinct SaaS publishers in the governed view.
Active versus assigned licences ≥ 90% active Assigned licences with demonstrable activity.
Unused licences < 8% of assigned Assigned licences with no activity in the agreed window.
Inactive users Trending down Accounts inactive beyond the application's threshold.
Orphaned accounts Zero standing Accounts belonging to departed users.

Governance KPIs

Renewals reviewed before notice deadline 100% Renewals with a completed position before the window closes.
Applications with a named owner 100% Applications with an accountable business owner.
Duplicate assignments Zero standing Users holding overlapping tiers of the same product.
SKU overlaps Tracked and resolved Higher and lower tier overlaps on the same identity.
Shadow SaaS identified Tracked with review status Applications found outside the sanctioned estate.
Leaver recovery ≥ 98% within 5 days Accounts deprovisioned across federated and non-federated apps.

Value KPIs

Duplicate application categories Trending down Functional overlaps between applications.
Realised optimisation Tracked against modelled Reclaim and downgrade benefit realised.
Renewal outcome versus model Within ±10% Realised renewal against the modelled scenario.
Duplicate tenants consolidated Against identified Publisher tenants merged.
Indicative targets

Every target above is an indicative KPI for a typical enterprise, intended to support planning discussions. Baselines should be measured in the first operating cycle and targets set from them. These are not benchmarks, commitments or achieved client results.

10

Positive Business Impact

One number for the SaaS estate

Coverage reconciled to finance means the executive view describes the whole estate rather than the subset the reporting function happens to own.

Shelfware removed before the renewal

Reclaim and downgrade happen during the term, so the renewal quantity reflects an already-optimised position rather than an aspiration.

Renewals entered with leverage

Modelling completes before the notice window, so reduction and cancellation remain live options at the point of negotiation.

Identity lifecycle covering the whole estate

Deprovisioning extends beyond SSO-federated applications, closing both the cost leak and the standing access risk that orphaned accounts represent.

Duplicate tenants and tiers consolidated

Volume is aggregated across entities and overlapping tiers on the same identity are resolved, restoring the negotiating position that fragmentation removes.

Consolidation opportunities made visible

Functional overlap between departmental tools surfaces as a portfolio signal rather than as an anecdote someone mentions in a steering meeting.

Outcomes depend on estate, contracts, data quality and organisational context, and are not guaranteed.

11

Related Playbooks

Playbooks commonly delivered alongside, before or after this one.

Important — please read

This playbook describes a typical implementation approach and a representative operating model. It is illustrative guidance, not a statement of results. Any figures, targets or ranges shown are illustrative and are intended to support planning discussions rather than to predict or promise an outcome. Outcomes are not guaranteed and depend on the estate, contracts, data quality and organisational context of each engagement.

No client names, client data, engagement detail or confidential delivery material is disclosed anywhere in this library. Technology named in these pages appears only as an illustrative example of a capability category and does not imply a partnership, certification or recommendation.

Book a Value Discovery

A free 30-minute session to pressure-test where the value actually sits in your software, SaaS and AI estate — and what it would take to get to it.