Skip to Main Content

How to get started with SaaS management

About this guide

This guide is for IT leaders who know they have a SaaS management problem and are ready to do something about it. It is vendor-neutral and applicable to any SaaS Management Platform (SMP). If you are looking for a product-specific walkthrough, the Beginner's Guide to 1Password SaaS Manager is a natural next step after reading this.


Introduction: IT's moment to lead

Every team has its favorite tools.

Designers swear by their creative suites. Finance teams rely on specialized reporting apps. Sales teams live inside CRMs, prospecting tools, and engagement platforms. Somewhere in the background, engineers are quietly signing up AI agents, and marketing teams are feeding content briefs into generative AI tools that no one in IT has evaluated.

That flexibility is a genuine productivity advantage and a security and controls issue for IT. When IT isn’t part of the story, employees and business units find workarounds to stay productive. Shadow IT proliferates and IT is left cleaning up a problem that grows larger by the day. 1Password's 2025 Annual Report found that 52% of employees have downloaded apps without IT approval, and 42% say they bypass IT specifically to boost productivity. 

AI has made this problem significantly more urgent. Employees are adopting tools like ChatGPT, Claude, Cursor, and Copilot, often through personal accounts or expense reports that never cross IT's desk. Gartner estimates that most organizations are only aware of about 40% of the applications actually in use, and that estimate was made before AI tools began compounding the gap. 

This is not just a SaaS management problem anymore, it's a SaaS and AI management problem, and the two are converging fast.

The good news is you can solve this problem holistically. SaaS management is about confidence, not control for its own sake. Confidence that you know what is in use, including the AI tools your employees adopted last week; that the right people have the right access; that compliance obligations are met; and that the business is not paying for software nobody is using. When those things are true, IT teams become what it was always meant to be, a business enabler.

Gartner forecasts that through 2028, over 70% of organizations will centralize SaaS management using a dedicated SaaS Management Platform (SMP), up from less than 30% in 2025.1 This guide gives you the four-step SaaS governance framework to reposition IT from the department that says "no" to the function that makes it safe for the business to move fast.

The four-step SaaS governance framework

Step 1: SaaS app discovery – Map your SaaS and AI landscape

Before you can govern anything, you have to know what tools are in use.

Most IT teams have a solid handle on the apps in their identity provider (IdP), the SSO-connected tools that show up in dashboards, and the licenses that flow through procurement. But not every app makes it into SSO. Federation takes time and effort, and when teams need a tool, they often sign up first and ask permission later. A marketing coordinator signs up for a design tool on a free trial. An engineer grants an AI plugin OAuth access to the company's code repository. A sales rep expenses a prospecting tool that finance categorizes as "software – other." None of these show up in the IdP, and none triggered an IT review.

1Password research found that 34% of SaaS apps in the average organization are not protected by SSO, and 49% of security professionals say unapproved software has compromised their ability to maintain adequate protections. 

Shadow AI: the newest discovery challenge

AI tools highlight the limits of SSO. Cyberhaven's 2026 AI Adoption and Risk Report found that 32% of ChatGPT usage and 58% of Claude usage happens through personal accounts that bypass corporate SSO entirely, and the National Cybersecurity Alliance's 2025 survey of 6,500 workers found that 43% share sensitive workplace information with AI tools without their employer's knowledge. 1Password's AI research found that only 21% of security leaders have full visibility into AI tools used in their organization.

Shadow AI introduces risks beyond traditional shadow IT. AI tools ingest and process data in ways traditional SaaS does not. Employees paste internal documents, customer data, and source code into AI interfaces, creating data exposure security teams cannot monitor. The IBM 2025 Cost of a Data Breach Report found shadow AI adds $670,000 to average breach costs.

How to build your app inventory

Gartner defines multi-method SaaS discovery as a mandatory SMP capability. Effective discovery requires pulling from multiple sources simultaneously:

  • Identity providers and SSO systems reveal managed apps and login frequency, but miss anything outside of federated tools and apps

  • Finance and procurement systems surface purchases that bypassed IT, including credit card and cloud marketplace transactions

  • Browser extensions and device management tools expose apps accessed through the browser, including AI tools

  • Expense reports and credit card feeds flag subscriptions purchased directly by employees

  • OAuth and API integrations reveal apps granted access to company systems, including AI plugins

What to do with what you find

The goal is not to ban everything. It is to categorize and decide which apps are approved and managed. Which are in use but unsanctioned, and should they be? Which presents security or compliance risk? Which are redundant? Employees who adopted shadow IT or shadow AI found tools that help them work. The right response is often to bring those tools into governance by providing employees with a catalog of approved tools to browse and request,  reducing shadow IT at its source.

The output of step 1: A complete, continuously updated app inventory that includes shadow IT and shadow AI, categorized by approval status, risk level, and ownership.

Step 2: SaaS lifecycle management – Onboarding, offboarding, and access requests

Once you know what tools are in use, the next question is who has access, and how did they get it?

Let’s start with a scenario. A new hire joins the sales team. Their manager sends a Slack message to IT requesting CRM access, copies a colleague to share a login for the team's prospecting tool, and forgets to mention the AI notetaker the rest of the team started using last month. Three weeks later, the new hire has access to some of the tools they need, workarounds for the rest, and IT has an incomplete record of both.

Now reverse the scenario. That same employee leaves six months later. Their identity provider access is revoked, but the prospecting tool login they shared with a colleague still works. The AI notetaker still has its OAuth connection to the company calendar. Their ChatGPT Enterprise seat, with six months of conversation history containing customer call notes, is still active.

1Password's 2025 Annual Report found that 38% of employees have successfully accessed a prior employer's account after leaving; this is how that happens.

Gartner identifies automated lifecycle workflows as a mandatory SMP feature. A mature program covers three transitions:

  • Onboarding. Connect HR systems and identity providers so a new hire record automatically triggers access workflows. Define baseline access for every role and team, including approved AI tools. Make sure access arrives before day one.

  • Offboarding. Go beyond the identity provider: revoke access across all managed apps, including AI platforms; reclaim licenses; transfer shared resources; revoke API keys and OAuth tokens, and document every action for audit purposes.

  • Access requests. Provide a self-service catalog of approved apps, including vetted AI tools, with clear approval routing and automated provisioning. When it takes minutes rather than weeks to get access through the official channel, employees stop going around IT.

The output of step 2: Structured, automated workflows for onboarding, offboarding, and access requests that cover the full SaaS and AI estate.

Step 3: Regular access reviews to meet compliance requirements

Lifecycle automation handles the predictable transitions: day one, last day, and the access requests in between. It does not handle the slow drift that happens between those events. An engineer gets temporary admin access for a migration project and never loses it. A manager moves from finance to operations but keeps her licenses to the old team's reporting tools. A contractor's engagement ends quietly, and their accounts in three apps outside SSO persist for months because no one triggers the offboarding workflow.

This is access creep, one of the most common findings in security audits. Gartner's Strategic Planning Assumptions warn that organizations without centralized SaaS lifecycle management are five times more susceptible to a cyber incident or data loss. Regular access reviews are the mechanism that catches what automation misses, and the evidence trail that proves your governance processes are working when an auditor asks.

The AI and compliance dimension

The stakes are rising. Gartner predicts that by 2030, more than 40% of enterprises will experience security or compliance incidents linked to unauthorized shadow AI. 

AI tools that ingest customer or employee data should be treated as high-risk by default. IBM's research found that only 24% of generative AI initiatives include a security component, meaning the other 76% launched without a formal security review. If those tools are not included in your access reviews, you have a blind spot that immediately grows every time you conduct one.

A practical approach

Running effective quarterly access reviews Quarterly is a strong baseline for most organizations. High-risk apps and AI tools handling sensitive data may need more frequent review, whereas lower-risk tools can be reviewed annually. Consistency matters more than frequency. Predictable reviews with a defined scope are more defensible to auditors than ad hoc efforts under time pressure.

Assign reviews to the people with the most context App owners (RevOps for CRM, Marketing Ops for their stack) handle application-level review. IT or Security covers high-risk apps and AI platforms. Line managers confirm whether their direct reports still need specific access. Reviewers should see the user's current role, access level, last login, and any flags, and be able to act directly from the review interface: approve, revoke, or downgrade.

Build audit-ready documentation into the process  For each review cycle, capture which apps and AI tools were reviewed, which users were included, each reviewer's decision with timestamps, any exceptions and their rationale, and evidence of remediation for revoked access. This is the documentation auditors look for during SOC 2, ISO 27001, SOX, and PCI assessments. Assembling it manually at the end of an audit cycle is one of the most common sources of compliance friction; building it into the review workflow removes that pressure entirely.

The output of step 3: A repeatable, documented access review process that produces audit-ready evidence and verifies the governance processes from steps 1 and 2 are functioning as intended.

Step 4: SaaS license optimization – align spend with actual use

Steps 1 through 3 give you visibility, lifecycle governance, and compliance evidence. Step 4 is where the financial return shows up.

Most organizations know, in rough terms, what they spend on SaaS. Few know whether that spend reflects actual usage. Gartner's SMP research estimates that approximately 25% of provisioned SaaS licenses are not regularly used, and only 14% of organizations actively manage all SaaS costs on an ongoing basis. That gap between purchase and use is where optimization starts.

Recovering unused licenses

Most unused licenses go undetected because usage data is scattered and no single team owns the decision. Centralizing that data into one place changes the equation. Start by identifying who has a license, their last login date, and whether usage reflects active need. From there, define thresholds (e.g., no login in 90 days) to trigger a review. Notify the user or manager, allow time to confirm access is still needed, and automatically remove or downgrade if there's no response. This is less disruptive than unilateral revocation and leads to better decisions.

Managing renewals proactively

The leverage in a software negotiation peaks before the contract auto-renews, and most organizations miss that window entirely. WorldCC research found that 71% of contracts are never monitored after signing. Centralizing renewal dates, seat counts, and costs in one place gives you that window back. Link contract data to real usage metrics and set automated reminders 60 to 90 days before each renewal. A 500-seat contract with only 320 people logging in over the last 90 days is a clear negotiation opportunity, but only if you see it in time.

Staying ahead of the change AI is making in SaaS economics

Traditional SaaS is priced per seat to be predictable, linear, and easy to audit. But AI tools operate differently. Deloitte's 2026 TMT Predictions notes 83% of AI-native SaaS companies offer usage-based pricing, charging by tokens, API calls, or compute minutes instead of seats. A single team experimenting with an AI coding assistant can generate costs that fluctuate wildly month to month.

AI features are also embedded into existing SaaS products as paid add-ons. Microsoft Copilot, Salesforce Einstein, and others charge per-user AI fees that appear in renewal invoices rather than procurement requests, making them easy to miss. These dynamics mean AI spend can grow quickly and quietly across line items finance teams are not yet watching.

Getting ahead requires the same principles as traditional SaaS optimization, applied with more granularity: centralize AI-specific subscriptions, API costs, and consumption charges into your existing system of record; set per-team baselines and budgets so you can spot anomalies before they become surprises; and right-size contracts as usage data matures. Deloitte found 86% of organizations expect AI infrastructure budgets to at least triple within three years, so those that build this discipline now will be better positioned than those that wait.

The output of step 4: A continuous cycle and real-time reporting of license optimization, AI spend tracking, app consolidation, and proactive renewal management.

IT as an enabler: bringing it together

Building a complete app inventory is what makes access management possible. Understanding who has access and how they use it is what makes spend optimization meaningful. And the processes and documentation built along the way are what turn compliance from a scramble into a repeatable, provable outcome.

Together, they represent a shift in how IT operates. Instead of telling employees what they cannot use, IT provides a governed path to the tools they need, including AI tools. Employees get speed, the business gains confidence, and IT teams become strategic partners.

How 1Password SaaS Manager brings this framework to life

The four steps in this guide are tool-agnostic. You could start with spreadsheets and willpower, but the volume of apps, the velocity of change, and the complexity of AI-era governance will quickly outpace manual processes. A dedicated SaaS Management Platform is what makes this a sustainable discipline rather than a one-time cleanup.

1Password SaaS Manager, our SMP, is organized into four pillars – Discover, Control, Optimize, and Integrate – that map directly to this guide's four steps.

Discover every app, including the ones no one told you about  SaaS Manager pulls simultaneously from five discovery sources, including your identity provider, OAuth token grants, finance and expense tools, a browser extension that tracks logins via work email, and 1Password's own vault and credential data. That last source is unique because employees store credentials in 1Password for apps that bypass SSO, which surfaces shadow IT and shadow AI that no other SMP can see. The result is a real-time inventory matched against a library of over 40,000 known applications, with every app classified by status, risk level, and AI category.

Control access across every lifecycle transition When a new hire appears in your HRIS or IdP, SaaS Manager generates an access plan based on their team and role, provisioning access via direct API, SCIM, or manual task. Offboarding reverses the process, revoking OAuth tokens, ending sessions, deprovisioning from every managed app, and logging every action in a complete audit trail. Customers have reduced offboarding by up to three hours per leaver. Access reviews run directly in the platform with auto-assigned reviewers, in-line actions, and audit-ready exports for SOC 2, ISO 27001, SOX, GDPR, HIPAA, and PCI DSS.

Optimize spend and prove it  SaaS Manager shows purchased licenses, active users, and 90-day logins in a single visual. A license optimization workflow identifies inactive users, notifies them, escalates if needed, and auto-downgrades on confirmation. Every reclaimed license is added to the savings tracker. Customers have achieved up to 35% reductions in SaaS spend and 10x ROI through license optimization. For contracts, AI-powered extraction reads uploaded PDFs and automatically populates fields, and a renewal calendar ensures no deadline passes without a decision.

Integrate with the tools you already use SaaS Manager connects to 400+ direct app integrations across identity providers, AI tools, HRIS platforms, finance tools, and the SaaS applications your teams use every day. That depth means discovery is more complete, lifecycle automation reaches further, and usage data is richer than what any single source can provide.

Your first 90 days with a SaaS Management Platform, like 1Password SaaS Manager

Days 1 to 30: Discover

Connect your identity provider, at least one finance or expense tool, and deploy a browser extension for endpoint-level discovery. If your organization uses 1Password, enable vault discovery for credential-level visibility into shadow IT and shadow AI. Your SMP will begin populating your app inventory immediately. Categorize what you find by approval status and risk level, and filter for AI apps early to get a read on your shadow AI landscape. Look for redundancies where multiple teams have adopted overlapping tools.

Milestone: A live, multi-source app inventory that includes shadow IT and shadow AI, classified by status and risk.

Days 31 to 60: Control

Connect your HRIS as a lifecycle source so your SMP can automatically detect new hires and departures. Define baseline access policies for your most common roles, specifying which apps each role gets on day one, including approved AI tools. Configure offboarding workflows to revoke tokens, end sessions, deprovision from managed apps, and transfer resources. Publish an app catalog with vetted apps and AI tools so employees have a governed path to the tools they need. Run a pilot access review on a small set of high-risk applications where you enroll apps, assign reviewers, launch, and export results for your compliance team.

Milestones: Automated lifecycle workflows running. App catalog live. A completed pilot access review with audit-ready documentation.

Days 61 to 90: Optimize

For your highest-spend apps, add contract details to unlock utilization reporting. Build your first license optimization workflow where you set the trigger (licensed users inactive for 90+ days), configure notifications, and define the endpoint (auto-downgrade or deactivate). Import contract data and configure renewal reminders with 60 to 90-day notification windows. Identify the largest contracts approaching renewal and cross-reference them against utilization data so you enter negotiations with evidence.

Milestones: A running license optimization program with measurable savings. A renewals pipeline with usage-backed negotiation data. A savings report ready for your next finance review.

What to do next

Getting AI and SaaS management right is less about the tools you buy and more about the habits you build around them. Knowing what's in use, keeping access current, and tying spend to actual usage are disciplines that compound over time. The organizations that do this well aren't doing anything extraordinary. They just made the decision to start.

Watch the Empower IT webinar to hear from IT practitioners who have implemented SaaS management programs.

Watch the webinar

Read the Beginner's Guide to 1Password SaaS Manager for deeper worked examples, integration details, and workflow walkthroughs.

Download the Beginner's Guide

Explore the 1Password SaaS Manager product page to see how a modern SMP addresses each step of this framework.

See the product