Business software subscriptions usually start from a reasonable need: the marketing team requires an email tool, the design team uses a collaboration platform, sales tries a new CRM, and the finance department selects an application for reporting. Problems arise when all these services continue to be renewed without anyone actually checking if they are still in use.
This is often referred to as SaaS sprawl, a condition where the number of subscription-based applications increases without centralized management. SaaS is software used over the internet and is generally paid for monthly or annually. For small businesses, one or two forgotten subscriptions may seem trivial. However, if this occurs across many teams, the costs can accumulate into routine expenses that are hard to track.
The FinOps Foundation includes license management and SaaS as an important part of technology cost control. They emphasize the need to look at costs, usage rates, ownership, and contract renewal times simultaneously, not just the total bill. The FinOps Foundation guide on licensing and SaaS also mentions unused or underutilized licenses as optimization opportunities.
The Problem Isn't Too Many Applications
Having many applications is not automatically bad. Growing companies do need various tools to operate. The issue arises when each application stands alone, there is no clear owner, and purchasing decisions are made based on momentary demands.
For example, a team might subscribe to a project management application because they find the old platform too complicated. A few months later, some team members still use spreadsheets, while others use the new application for just one type of task. The company ends up paying for two or three systems with similar functions.
Another risk is security. When employees create accounts using company emails without going through an official process, the company can lose track of what data is stored, who has access, and what happens if that person leaves. CISA includes the detection of shadow IT or the use of unauthorized software as part of cloud security capabilities. CISA's document on cloud usage explains the importance of detecting systems and software used outside of official management.
Start with Inventory, Not Cost Cutting
A common mistake in SaaS audits is to immediately cancel subscriptions that seem expensive. This approach is risky because those applications may be essential for operations, even if only used by a few people.
The first step is to create a simple inventory. There is no need to immediately purchase a SaaS management platform. A spreadsheet is sufficient for the initial stage. Record at least the following information:
- Application name and its main function.
- Team or person responsible.
- Number of licenses purchased and the number actively used.
- Monthly or annual cost.
- Contract renewal date.
- Type of data stored.
- Other applications with similar functions.
- Status of integration with other systems.
The last column is often overlooked. An application may rarely be opened by a human but still sends data to a CRM or accounting system. Canceling it without checking the integration could halt unseen business processes.
Measure Value, Not Just Login Frequency
The number of logins is useful, but it is not the only metric. An application used once a week could be very important if it helps complete payroll processes or monthly reporting.
Use some practical questions:
- What business processes depend on this application?
- What would be the impact if the application were unavailable for a week?
- How much time is saved compared to manual methods?
- Are all the paid features truly necessary?
- Do the available licenses match the number of active users?
- Are there other applications that already have similar functions?
From here, each application can be categorized into four groups: must keep, need optimization, need re-evaluation, or worth stopping. This categorization is more useful than just a list of expensive and cheap applications.
Check Licenses Before Renewal Time
The best time to conduct an audit is a few weeks or months before the contract is renewed. If the review is done after the annual bill is issued, the negotiation space is usually tighter.
Pay attention to the pricing model used. Some services calculate costs based on the number of users, while others are based on usage, storage capacity, transaction volume, or feature levels. Two businesses with the same number of employees may not necessarily need the same package.
For user-based services, differentiate between active users, occasional users, and accounts that are no longer in use. Microsoft, for example, provides license management through groups and advises companies to remove licenses that will not be used again to avoid paying for unnecessary capacity. Microsoft documentation on license assignment also explains that licenses for users that are no longer needed can be released or removed from the subscription.
However, do not assume all inactive accounts are wasteful. There is a possibility that those accounts are used as service accounts, emergency accounts, or part of an integration. Ensure the system owner checks the context before making deletions.
Establish Lightweight Purchasing Rules
A one-time audit will not solve the problem if purchasing patterns remain the same. Companies need simple rules that do not slow down teams.
For example, every request for a new application must answer three questions: what problem is being solved, whether similar functions are already available, and who will be responsible after the application is purchased. For applications that store customer or financial data, add security and privacy checks.
These rules do not mean all decisions must wait for lengthy approvals. For low-cost and low-risk services, the process can be quick. Conversely, applications that connect to many systems or store sensitive data need to go through stricter checks.
What You Can Do Now
- Download the software transaction list from the company account for the last 12 months.
- Combine the names of the same applications, including payments made through personal cards or marketplaces.
- Assign an owner for each application.
- Mark inactive licenses and contracts that will renew within 90 days.
- Review applications with overlapping functions.
- Contact user teams before downgrading packages or canceling services.
- Keep a record of decisions: retained, downgraded, merged, or terminated.
The FinOps Foundation recommends merging cost, usage, and ownership data so that SaaS decisions are not just a finance department issue. The FinOps Framework for SaaS also emphasizes the importance of managing users as they join and leave the organization, as well as reviewing unused subscriptions or those with duplicate functions.
Conclusion
The goal of a SaaS audit is not to make the company use as few applications as possible. The aim is to ensure that every digital cost has a reason, an owner, and measurable outcomes.
Businesses that can connect software costs with work processes will find it easier to make decisions. They can save money without shutting down productivity, reduce the risk of abandoned accounts, and avoid purchasing applications that are already available within the systems they use.
Start with a simple list and conduct regular reviews every quarter. In practice, small disciplines like checking licenses, renewal dates, and application owners often have a more tangible impact than just searching for new software to speed up work.
Sources & Further Reading
- FinOps Foundation β Licensing & SaaS FinOps Framework Capability
- CISA β TIC 3.0 Cloud Use Case
- Microsoft Learn β Assign or unassign licenses for users and groups
- FinOps Foundation β Applying the FinOps Framework to SaaS
β Rio Yotto @rioyotto
