At a glance
- Challenge
- SaaS spend, subscriptions, usage and renewals live in different systems, so duplicate licences, orphaned accounts and overlapping applications are invisible at executive level.
- Approach
- Discover across SSO, finance and browser signals, consolidate to publisher and tenant, correlate to identity, then govern renewals from a single portfolio view.
- Primary KPI
- % of total SaaS spend represented in the governed single-pane portfolio view.
- Impact
- One estate view, shelfware removed before renewal and negotiations entered with evidenced consumption.
01
Executive Summary
SaaS governance fails on coverage before it fails on optimisation. An organisation that can see sixty per cent of its SaaS spend can optimise that sixty per cent very effectively and still be surprised every quarter by the rest. The first objective is therefore not savings — it is the proportion of actual SaaS spend that appears in the governed view at all.
Discovery has to be multi-signal. SSO and identity provider logs find applications that are federated. Expense and accounts-payable data finds applications bought on a corporate card. Browser extension telemetry finds applications that are neither. Each signal alone leaves a material gap; together they close most of it, and the residue becomes a named, shrinking list.
The optimisation levers are then well understood: assigned-but-unused licences, orphaned accounts belonging to leavers, duplicate tenants from acquisitions or team-level purchases, overlapping SKU tiers on the same user, and functional overlap between applications doing the same job for different departments. What converts these into value is a renewal calendar with enough lead time to act before the auto-renewal clause bites.
02
Business Challenge
The structural problem is that no single system owns SaaS. Procurement sees contracts it was asked to sign. Finance sees invoices and card transactions. IT sees applications integrated with SSO. Each has a partial and internally consistent view, and nobody reconciles them. Executive reporting therefore describes whichever subset the reporting function happens to own.
The renewal problem compounds it. SaaS agreements auto-renew, often with a notice period measured in weeks. Without a renewal calendar and a usage position prepared in advance, the organisation discovers the renewal after the notice window closes and renews at current quantity because there is no alternative. The optimisation opportunity existed for eleven months and was available for none of them.
03
Typical Symptoms
Organisations that need this playbook usually recognise several of the following.
- Nobody can state total SaaS spend, only the portion visible to whichever function is reporting.
- Applications appear on corporate card statements that IT has never seen.
- The same publisher is contracted under two or more tenants following an acquisition or a team-level purchase.
- Users hold overlapping tiers of the same product — for example M365 E3 and F3 on the same identity.
- Leavers retain active SaaS accounts because deprovisioning covers only SSO-federated applications.
- Renewals are discovered after the notice period has closed, so auto-renewal happens by default.
- Assigned licence counts are used as the renewal baseline because usage data was never collected.
- Two departments run functionally identical tools with separate contracts and separate owners.
04
Business Risks
Business risks by domain, with the risk and its impact
| Domain | Risk | Impact if unaddressed |
| Operational |
Deprovisioning that covers only SSO-federated applications |
Leavers retain active accounts in non-federated applications, creating both continuing subscription cost and a standing access risk that no periodic review will find. |
| Commercial |
Renewals discovered after the notice window has closed |
Auto-renewal proceeds at current quantity. The optimisation opportunity was available all year and exercisable in none of it. |
| Compliance |
Applications procured outside IT and security review |
Corporate data is processed by services that have had no data-protection, security or residency assessment, and the organisation cannot enumerate them to answer a regulator. |
| Technology |
Duplicate tenants of the same publisher across entities |
Volume aggregation is lost, users may hold licences in both tenants, and consolidation is invisible because no view spans them. |
05
Operating Workflow and Reference Architecture
Operating workflow
11 stages, each producing a defined output. This workflow is specific to this
playbook; the category lifecycle on the
Software Value index is an overview of how the playbooks relate,
not how any one of them runs.
↔ Wide diagram — scroll horizontally, or use the
arrow keys once it has focus. A text description is available to screen readers.
Illustrative SaaS governance workflow. Discovery is multi-signal by design — SSO, finance and browser telemetry each miss a different part of the estate. Renewal modelling must complete before the contractual notice window. Outcomes are not guaranteed.
Reference architecture
The systems, data and controls the workflow above runs on.
↔ Wide diagram — scroll horizontally, or use the
arrow keys once it has focus. A text description is available to screen readers.
Illustrative reference architecture. No single discovery signal is sufficient: SSO misses non-federated applications, expense data misses those inside a larger invoice, and browser telemetry misses server-to-server integrations.
06
Implementation Approach
A representative implementation sequences in 5 phases. Duration and overlap
vary with estate size, data quality and the number of source systems in scope.
Phase 1
Multi-signal discovery and spend coverage
Establish how much of the estate you can actually see. Coverage is the first KPI because every subsequent number is a percentage of it.
- SSO and identity discovery. Extract federated application usage from Entra ID or the identity provider, which finds the sanctioned, integrated portion of the estate.
- Finance signal. Analyse accounts-payable and corporate card data for software vendors, which finds applications procured outside IT entirely.
- Browser telemetry. Deploy browser extension discovery to managed browsers to find applications that are neither federated nor separately invoiced.
- Spend reconciliation. Reconcile discovered applications against total software spend and report the coverage percentage with the residual named.
- Shadow SaaS register. Record applications found outside the sanctioned estate with their data sensitivity, so security and privacy review can be prioritised.
Business value
Coverage becomes a measured, reportable figure, and the unseen residue becomes a named list that shrinks rather than an unknown that persists.
Phase 2
Consolidation and contract baseline
Turn discovered instances into one record per publisher, with the commercial terms that determine what can be changed and when.
- Publisher and tenant normalisation. Consolidate name variants, subsidiaries and separate tenants into a single publisher record while retaining the underlying instances.
- Duplicate tenant detection. Identify multiple tenants of the same publisher across entities and quantify the aggregation opportunity.
- Contract capture. Capture term, quantity, tier, price, auto-renewal clause and — critically — the notice period, since it determines the action deadline.
- Renewal calendar. Build a forward calendar keyed to the notice deadline rather than the renewal date, with owners assigned per renewal.
- Ownership assignment. Assign a named business owner to every application; unowned applications are the ones that renew by default.
Business value
Every application has an owner, a renewal notice deadline and a contract position, which is what makes proactive renewal governance possible at all.
Phase 3
Identity correlation and utilisation analysis
Establish who holds what and who actually uses it. Assigned counts are not utilisation.
- Identity correlation. Correlate application accounts to Entra ID identities and employment status, including contractors and guests.
- Assigned versus active analysis. Compare assigned licences to demonstrable activity per application, using publisher admin APIs where available rather than sign-in proxies.
- Orphaned account detection. Identify accounts belonging to departed users, particularly in non-federated applications that automated deprovisioning does not reach.
- Duplicate and tier overlap. Detect users holding multiple tiers of the same product or duplicate accounts across tenants.
- Inactivity thresholds. Agree inactivity definitions per application with the business owner rather than applying a single global threshold.
Business value
Shelfware becomes specific — named users, named applications, stated inactivity periods — which is the only form in which a business owner will accept a reclaim.
Phase 4
Optimisation and consolidation execution
Act on the findings before the renewal, not during it.
- Reclaim execution. Reclaim unused and orphaned licences with the business owner's acceptance recorded, and return them to the assignable pool.
- Tier downgrade. Downgrade users whose usage does not justify their tier, with the activity evidence attached to the decision.
- Tenant consolidation. Consolidate duplicate tenants where commercially and operationally viable, sequencing against contract dates.
- Functional overlap review. Assess applications performing the same function for different departments and route genuine duplication to portfolio rationalisation.
- Deprovisioning integration. Extend leaver deprovisioning beyond SSO-federated applications, using the discovery signals to define the full account set.
Business value
Shelfware is removed and duplicate tenants consolidated during the term, so the renewal quantity reflects an already-optimised estate.
Phase 5
Renewal intelligence and executive reporting
Convert the portfolio view into negotiation leverage and a standing executive picture.
- Pre-notice modelling. Complete quantity, tier and term scenario modelling before the notice window opens, so cancellation and reduction remain live options.
- Negotiation input pack. Provide the negotiation team with evidenced consumption, utilisation trend, overlap position and benchmark context per renewal.
- Renewal outcome tracking. Track modelled versus realised renewal outcome so forecasting improves and the governance function's value is evidenced.
- Executive dashboard. Publish spend coverage, utilisation, shelfware, duplicate position, shadow SaaS and the renewal pipeline in one standing view.
- New application intake. Route new SaaS requests through a check against the existing portfolio, so overlap is prevented rather than discovered.
Business value
Renewals are entered with an evidenced position while reduction is still contractually possible, and the executive sees one number for the SaaS estate rather than three.
07
Technology Components
Capability categories with representative examples. Many organisations can build the governed view from an existing identity provider, expense system and SAM platform before acquiring a dedicated SaaS management platform. Products are named as examples, not recommendations.
Discovery
- Microsoft Entra ID / Okta SSO logs
- Expense and AP data
- Browser extension telemetry
- Network egress analysis
- Publisher admin APIs
Portfolio management
- SaaS management platform capability
- Contract repository
- Renewal calendar
- Publisher and tenant normalisation
- Application ownership register
Identity and lifecycle
- Entra ID user and status data
- Joiner-mover-leaver workflow
- Access reviews
- Deprovisioning automation
Reporting and action
- Executive portfolio dashboard
- Reclaim and downgrade backlog
- Renewal scenario model
- Negotiation input pack
08
Governance Considerations
Governance should be proportionate. The six areas below are the minimum set that has to be
explicit for this capability to hold up under internal review.
Ownership
A named SaaS portfolio owner accountable for coverage and the renewal calendar; a business owner per application accountable for utilisation and renewal decisions.
Decision rights
Business owners approve reclaim and downgrade for their users; the portfolio owner approves new application onboarding; renewal decisions above a value threshold go to the governance forum.
Policies
SaaS procurement policy routing purchases through the portfolio check, deprovisioning policy covering non-federated applications, and an ownership policy requiring a named owner before purchase.
Approvals
New SaaS applications approved only after an overlap check against the existing portfolio; auto-renewals above a value threshold require an explicit renew decision before the notice deadline.
Evidence
Utilisation evidence supporting each reclaim and downgrade, the contract and notice period on record per application, and the renewal decision with its rationale and approver.
Controls
Renewal notice-deadline alerting with sufficient lead time, orphaned account detection across all discovered applications, coverage threshold reporting, and an overlap gate on new purchases.
09
Success Metrics
Primary KPI
Governed spend coverage
Share of actual SaaS spend represented in the single-pane governed portfolio view, reconciled against finance rather than against the discovery tool's own total.
≥ 95% of total SaaS spend
Operational KPIs
Publishers discovered
Tracked against baseline
Distinct SaaS publishers in the governed view.
Active versus assigned licences
≥ 90% active
Assigned licences with demonstrable activity.
Unused licences
< 8% of assigned
Assigned licences with no activity in the agreed window.
Inactive users
Trending down
Accounts inactive beyond the application's threshold.
Orphaned accounts
Zero standing
Accounts belonging to departed users.
Governance KPIs
Renewals reviewed before notice deadline
100%
Renewals with a completed position before the window closes.
Applications with a named owner
100%
Applications with an accountable business owner.
Duplicate assignments
Zero standing
Users holding overlapping tiers of the same product.
SKU overlaps
Tracked and resolved
Higher and lower tier overlaps on the same identity.
Shadow SaaS identified
Tracked with review status
Applications found outside the sanctioned estate.
Leaver recovery
≥ 98% within 5 days
Accounts deprovisioned across federated and non-federated apps.
Value KPIs
Duplicate application categories
Trending down
Functional overlaps between applications.
Realised optimisation
Tracked against modelled
Reclaim and downgrade benefit realised.
Renewal outcome versus model
Within ±10%
Realised renewal against the modelled scenario.
Duplicate tenants consolidated
Against identified
Publisher tenants merged.
Indicative targets
Every target above is an indicative KPI for a typical enterprise, intended to support
planning discussions. Baselines should be measured in the first operating cycle and targets
set from them. These are not benchmarks, commitments or achieved client results.
10
Positive Business Impact
One number for the SaaS estate
Coverage reconciled to finance means the executive view describes the whole estate rather than the subset the reporting function happens to own.
Shelfware removed before the renewal
Reclaim and downgrade happen during the term, so the renewal quantity reflects an already-optimised position rather than an aspiration.
Renewals entered with leverage
Modelling completes before the notice window, so reduction and cancellation remain live options at the point of negotiation.
Identity lifecycle covering the whole estate
Deprovisioning extends beyond SSO-federated applications, closing both the cost leak and the standing access risk that orphaned accounts represent.
Duplicate tenants and tiers consolidated
Volume is aggregated across entities and overlapping tiers on the same identity are resolved, restoring the negotiating position that fragmentation removes.
Consolidation opportunities made visible
Functional overlap between departmental tools surfaces as a portfolio signal rather than as an anecdote someone mentions in a steering meeting.
Outcomes depend on estate, contracts, data quality and organisational context, and are not guaranteed.
11
Related Playbooks
Playbooks commonly delivered alongside, before or after this one.
Important — please read
This playbook describes a typical implementation approach and a representative operating
model. It is illustrative guidance, not a statement of results. Any figures, targets or
ranges shown are illustrative and are intended to support planning discussions rather than
to predict or promise an outcome. Outcomes are not guaranteed and depend on the estate,
contracts, data quality and organisational context of each engagement.
No client names, client data, engagement detail or confidential delivery material is
disclosed anywhere in this library. Technology named in these pages appears only as an
illustrative example of a capability category and does not imply a partnership,
certification or recommendation.