All insights
InsightscostsSaaS sprawlaudit

SaaS sprawl: the five-step audit method

Software subscriptions pile up faster than anyone manages them: business units commit 70% of SaaS spend, and barely more than half of purchased licenses are actually used. Most leadership teams discover the true size of their application portfolio when the invoices arrive.

Published on June 30, 20266 min readexecutive leveldata verified on August 12, 2026

TL;DR

  • The average organization runs 305 SaaS applications (median: 240) — 2026 index commissioned by Zylo, a SaaS management vendor, on a sample skewed toward large enterprises.
  • Only 54% of purchased licenses are actually used; the best-run organizations exceed 90% (Zylo, 2026).
  • 56% of applications in use have IT approval: nearly half the portfolio sits outside governance (BetterCloud, 2026).
  • 70% of SaaS spend is committed by business units, not by IT (Zylo, 2025).
  • 101 applications on SSO on average across Okta customers (2025), versus 305 measured by spend (Zylo, 2026): the gap is the blind spot.
  • In Switzerland, Article 12 of the FADP requires a record of processing activities; the exemption under 250 employees is conditional — hard to demonstrate without an inventory.
01

A portfolio growing faster than its governance

The thesis of this article fits in one sentence: you cannot rationalize what you cannot see, so the inventory comes before any decision to cut — and five steps are enough to build it. If your portfolio is already mapped, measured and assigned owners, this article will teach you nothing.

The average organization in Zylo's sample uses 305 applications, with $55.7M in annual spend (2026 index, commissioned by Zylo). In the mid-market, the average portfolio grew from 116 to 164 applications in one year, +41% (2026 State of SaaS, commissioned by BetterCloud). In November 2024, Gartner forecast $299.1B in worldwide SaaS end-user spending for 2025 (+19.2%).

The trajectory matters more than the level: between 2021 and 2023, the average portfolio measured by Zylo had shrunk from 323 to 269 applications. Then AI restarted the inflation: 11% growth in one year, 27 "AI" applications per organization (BetterCloud, 2026), and 78% of IT leaders hit by unexpected charges tied to AI or consumption-based pricing (Zylo, 2026). An audit is not a one-off spring cleaning: it is a cycle.

02

Read the numbers with their sponsor in mind

A matter of hygiene: almost every SaaS sprawl statistic comes from vendors selling the solution to the problem they measure. Zylo and BetterCloud sell SaaS management platforms; Okta sells an identity platform. Their data remains the broadest available (40 million licenses on Zylo's side) but skews toward large enterprises. A 50-person company does not run 305 applications; the mechanism, though, is identical: decentralized purchasing, dormant licenses, functional duplicates. And shadow IT is not a moral failing.

"Shadow IT is rarely the result of malicious intent." — UK NCSC, "Shadow IT" guidance, July 2023.

The real causes, per the NCSC: request processes that are too slow, approved tools that fall short. An honest inventory therefore reveals as many underserved needs as subscriptions to cancel: reallocate before removing.

03

Four discovery families, four blind spots

Each family has a measurable blind spot — the argument for combining them rather than picking one.

Discovery familyWhat it seesWhat it misses
Billing (accounting, cards, expense reports)Everything that is paid for, with amountsFreemium and free trials, which still process data
SSO / directory (e.g. Entra ID's "Usage & insights", P1/P2 license)Sign-ins per application, success rates, last sign-in dateAnything not integrated with SSO
OAuth grants (e.g. "Accessed apps", Google Workspace admin console)Third-party apps that actually accessed data, with their scopesApps used outside the company account
Network traffic (e.g. Defender for Cloud Apps, 31,000+ app catalog; Cloudflare Shadow IT Discovery)Actual usage, including outside SSO, classifiable as Approved / UnapprovedUsage outside the filtered perimeter; proportionality of monitoring

Okta counts 101 applications per customer — only those integrated with its SSO — while Zylo, starting from spend, counts 305. The difference is not a measurement error: it is the size of a single method's blind spot.

04

The five-step method

Order matters: finance first, technology second, decisions last. Start by extracting twelve months of invoices, card statements and expense reports — the one source every leadership team already has. Then cross-check against the consoles already in place: SSO, OAuth grants, gateway logs. Every gap between the two lists is a discovery.

Then comes usage measurement — that is where the money sleeps: 54% of licenses actually used on average (Zylo, 2026), and every point below 100% is leverage at the next renewal. Next, qualify each application — named business owner, data processed, redundancies — then decide: reallocate, renegotiate, terminate. Finally, install a quarterly review, because the portfolio grows back. This discipline of inventory before decision sits at the heart of how we build; the same reflex structures our audit services.

What doing nothing costs — The average organization in Zylo's sample (skewed toward large enterprises) leaves $19.8M in unused licenses per year; $3.8M for organizations with 1 to 500 employees. Keep the ratio: 54% utilization means nearly one subscription dollar in two dormant. Add the risk: 18% of organizations experienced an incident tied to a former employee who kept access; only 25% automate offboarding (BetterCloud, 2026).

06

The audit grid

StepActionData sourceExpected outcome
1. Financial inventoryExtract 12 months of invoices, cards and expense reports; isolate every recurring chargeAccounting, card statements, expense reportsPaid subscriptions: annual cost, owner, renewal date
2. Technical discoveryCross-check the financial list against SSO, OAuth grants and available gateway logsIdentity console, Workspace or Microsoft 365 console, gatewayConsolidated portfolio (paid + free + shadow IT) and gaps between sources
3. Usage measurementRecord last sign-in and active users per application, against paid licensesSSO reports, application admin consolesUtilization rate per application; dormant licenses quantified
4. QualificationName a business owner, list the data processed, flag duplicatesBusiness interviews, contracts, FADP processing recordOne sheet per application: owner, criticality, compliance, redundancies
5. Decision and cycleReallocate, renegotiate or terminate; set a quarterly review and a single purchasing channelDeliverables from steps 1–4, budgetCosted action plan and recurring governance
07

The limits of this approach

The figures cited come from samples skewed toward large enterprises: your amounts will be smaller, though not necessarily your ratios. The method assumes some technical centralization; without SSO or an administered collaboration suite, steps 2 and 3 shrink to billing and interviews — less precise, but enough for a first pass. Network traffic raises a genuine question of proportionality of monitoring, to be addressed before deployment. Finally, below roughly twenty applications, a spreadsheet and one meeting will do.

Key takeaways

  • Cutting before inventorying destroys value: part of shadow IT signals real needs, to be reallocated rather than removed.
  • Combining billing, SSO/OAuth and — with care — network logs is the only way to see the whole portfolio; each source alone lies by omission.
  • The same audit feeds the record of processing activities required by the Swiss FADP: one project, two obligations covered.

Taking back control requires neither a dedicated platform nor a six-month project: twelve months of invoices, the consoles in place and a disciplined grid are enough for the first pass. The rest is a matter of rhythm — a review every quarter, one purchasing channel, one owner per application. Ownward helps companies perform better through technology — and above all, take back control.

Sources

Data and pricing verified on August 12, 2026.

All trademarks belong to their respective owners. This article is neither sponsored nor endorsed by the vendors mentioned.

Is this on your desk right now?

Tell us where you stand. We reply with concrete elements — what we would do first, in your business.

Talk about your situation

Keep reading

All insights