SaaS sprawl: the five-step audit method
Software subscriptions pile up faster than anyone manages them: business units commit 70% of SaaS spend, and barely more than half of purchased licenses are actually used. Most leadership teams discover the true size of their application portfolio when the invoices arrive.
TL;DR
- The average organization runs 305 SaaS applications (median: 240) — 2026 index commissioned by Zylo, a SaaS management vendor, on a sample skewed toward large enterprises.
- Only 54% of purchased licenses are actually used; the best-run organizations exceed 90% (Zylo, 2026).
- 56% of applications in use have IT approval: nearly half the portfolio sits outside governance (BetterCloud, 2026).
- 70% of SaaS spend is committed by business units, not by IT (Zylo, 2025).
- 101 applications on SSO on average across Okta customers (2025), versus 305 measured by spend (Zylo, 2026): the gap is the blind spot.
- In Switzerland, Article 12 of the FADP requires a record of processing activities; the exemption under 250 employees is conditional — hard to demonstrate without an inventory.
A portfolio growing faster than its governance
The thesis of this article fits in one sentence: you cannot rationalize what you cannot see, so the inventory comes before any decision to cut — and five steps are enough to build it. If your portfolio is already mapped, measured and assigned owners, this article will teach you nothing.
The average organization in Zylo's sample uses 305 applications, with $55.7M in annual spend (2026 index, commissioned by Zylo). In the mid-market, the average portfolio grew from 116 to 164 applications in one year, +41% (2026 State of SaaS, commissioned by BetterCloud). In November 2024, Gartner forecast $299.1B in worldwide SaaS end-user spending for 2025 (+19.2%).
The trajectory matters more than the level: between 2021 and 2023, the average portfolio measured by Zylo had shrunk from 323 to 269 applications. Then AI restarted the inflation: 11% growth in one year, 27 "AI" applications per organization (BetterCloud, 2026), and 78% of IT leaders hit by unexpected charges tied to AI or consumption-based pricing (Zylo, 2026). An audit is not a one-off spring cleaning: it is a cycle.
Read the numbers with their sponsor in mind
A matter of hygiene: almost every SaaS sprawl statistic comes from vendors selling the solution to the problem they measure. Zylo and BetterCloud sell SaaS management platforms; Okta sells an identity platform. Their data remains the broadest available (40 million licenses on Zylo's side) but skews toward large enterprises. A 50-person company does not run 305 applications; the mechanism, though, is identical: decentralized purchasing, dormant licenses, functional duplicates. And shadow IT is not a moral failing.
"Shadow IT is rarely the result of malicious intent." — UK NCSC, "Shadow IT" guidance, July 2023.
The real causes, per the NCSC: request processes that are too slow, approved tools that fall short. An honest inventory therefore reveals as many underserved needs as subscriptions to cancel: reallocate before removing.
Four discovery families, four blind spots
Each family has a measurable blind spot — the argument for combining them rather than picking one.
| Discovery family | What it sees | What it misses |
|---|---|---|
| Billing (accounting, cards, expense reports) | Everything that is paid for, with amounts | Freemium and free trials, which still process data |
| SSO / directory (e.g. Entra ID's "Usage & insights", P1/P2 license) | Sign-ins per application, success rates, last sign-in date | Anything not integrated with SSO |
| OAuth grants (e.g. "Accessed apps", Google Workspace admin console) | Third-party apps that actually accessed data, with their scopes | Apps used outside the company account |
| Network traffic (e.g. Defender for Cloud Apps, 31,000+ app catalog; Cloudflare Shadow IT Discovery) | Actual usage, including outside SSO, classifiable as Approved / Unapproved | Usage outside the filtered perimeter; proportionality of monitoring |
Okta counts 101 applications per customer — only those integrated with its SSO — while Zylo, starting from spend, counts 305. The difference is not a measurement error: it is the size of a single method's blind spot.
The five-step method
Order matters: finance first, technology second, decisions last. Start by extracting twelve months of invoices, card statements and expense reports — the one source every leadership team already has. Then cross-check against the consoles already in place: SSO, OAuth grants, gateway logs. Every gap between the two lists is a discovery.
Then comes usage measurement — that is where the money sleeps: 54% of licenses actually used on average (Zylo, 2026), and every point below 100% is leverage at the next renewal. Next, qualify each application — named business owner, data processed, redundancies — then decide: reallocate, renegotiate, terminate. Finally, install a quarterly review, because the portfolio grows back. This discipline of inventory before decision sits at the heart of how we build; the same reflex structures our audit services.
What doing nothing costs — The average organization in Zylo's sample (skewed toward large enterprises) leaves $19.8M in unused licenses per year; $3.8M for organizations with 1 to 500 employees. Keep the ratio: 54% utilization means nearly one subscription dollar in two dormant. Add the risk: 18% of organizations experienced an incident tied to a former employee who kept access; only 25% automate offboarding (BetterCloud, 2026).
In Switzerland, the inventory is also a legal matter
Article 12 of the FADP requires a record of processing activities: purposes, categories of data and recipients, security measures, destination countries where applicable. Every SaaS application that touches personal data belongs in it.
Paragraph 5 exempts companies with fewer than 250 employees, on condition of a limited risk to the data subjects' personality rights (Article 24 of the Data Protection Ordinance). Yet demonstrating limited risk requires knowing which applications process which data: the exemption rests on the inventory. A well-run audit therefore feeds that record directly: two obligations, one project, in the spirit of our method.
The audit grid
| Step | Action | Data source | Expected outcome |
|---|---|---|---|
| 1. Financial inventory | Extract 12 months of invoices, cards and expense reports; isolate every recurring charge | Accounting, card statements, expense reports | Paid subscriptions: annual cost, owner, renewal date |
| 2. Technical discovery | Cross-check the financial list against SSO, OAuth grants and available gateway logs | Identity console, Workspace or Microsoft 365 console, gateway | Consolidated portfolio (paid + free + shadow IT) and gaps between sources |
| 3. Usage measurement | Record last sign-in and active users per application, against paid licenses | SSO reports, application admin consoles | Utilization rate per application; dormant licenses quantified |
| 4. Qualification | Name a business owner, list the data processed, flag duplicates | Business interviews, contracts, FADP processing record | One sheet per application: owner, criticality, compliance, redundancies |
| 5. Decision and cycle | Reallocate, renegotiate or terminate; set a quarterly review and a single purchasing channel | Deliverables from steps 1–4, budget | Costed action plan and recurring governance |
The limits of this approach
The figures cited come from samples skewed toward large enterprises: your amounts will be smaller, though not necessarily your ratios. The method assumes some technical centralization; without SSO or an administered collaboration suite, steps 2 and 3 shrink to billing and interviews — less precise, but enough for a first pass. Network traffic raises a genuine question of proportionality of monitoring, to be addressed before deployment. Finally, below roughly twenty applications, a spreadsheet and one meeting will do.
Key takeaways
- Cutting before inventorying destroys value: part of shadow IT signals real needs, to be reallocated rather than removed.
- Combining billing, SSO/OAuth and — with care — network logs is the only way to see the whole portfolio; each source alone lies by omission.
- The same audit feeds the record of processing activities required by the Swiss FADP: one project, two obligations covered.
Taking back control requires neither a dedicated platform nor a six-month project: twelve months of invoices, the consoles in place and a disciplined grid are enough for the first pass. The rest is a matter of rhythm — a review every quarter, one purchasing channel, one owner per application. Ownward helps companies perform better through technology — and above all, take back control.
Sources
- 2026 SaaS Management Index — Zylo (study commissioned by Zylo, a SaaS management vendor), accessed August 12, 2026.
- 2025 SaaS Management Index, press release — Zylo (commissioned by Zylo), January 16, 2025, accessed August 12, 2026.
- 2024 SaaS Management Index, press release — Zylo (commissioned by Zylo), February 27, 2024, accessed August 12, 2026.
- The 2026 State of SaaS Report — BetterCloud (study commissioned by BetterCloud, a SaaS management vendor), July 15, 2026, accessed August 12, 2026.
- Businesses at Work 2025 — Okta (study commissioned by Okta, an identity vendor), March 12, 2025, accessed August 12, 2026.
- Public cloud end-user spending forecast for 2025 — Gartner, press release of November 19, 2024, accessed August 12, 2026.
- "Shadow IT" guidance — National Cyber Security Centre (UK), July 27, 2023, accessed August 12, 2026.
- Swiss FADP, Article 12 — record of processing activities — Fedlex, Swiss federal law in force since September 1, 2023, accessed August 12, 2026.
- Set up Cloud Discovery, Defender for Cloud Apps documentation — Microsoft Learn, accessed August 12, 2026.
- Microsoft Entra ID Usage & insights report, documentation — Microsoft Learn, accessed August 12, 2026.
- Control which third-party apps access Google Workspace data — Google Workspace Admin Help, accessed August 12, 2026.
- Shadow IT Discovery, Cloudflare Zero Trust documentation — Cloudflare Docs, accessed August 12, 2026.
Data and pricing verified on August 12, 2026.
All trademarks belong to their respective owners. This article is neither sponsored nor endorsed by the vendors mentioned.
Is this on your desk right now?
Tell us where you stand. We reply with concrete elements — what we would do first, in your business.
Keep reading
All insightsSeptember 11, 2026 · 7 min read
Govern a Base Like an Internal Product
A spreadsheet updated by hand every Monday, a base built one evening that became critical: most business tools are born without an owner or rules. As long as nobody answers for them, they are not tools that last — they are shadow IT on borrowed time.
September 1, 2026 · 6 min read
Airtable as scaffolding: build what you plan to take down
In 2025, half of IT projects run over deadline, budget or scope, and nearly one in five is abandoned. Yet every internal tool starts as if it were definitive. Owning the temporary — a no-code base built in days, designed to be taken down — remains the decision nobody dares to claim.