
The invoice arrives and it's up again. Nobody changed anything, nobody bought anything, and yet the software line is bigger than last quarter.
This is the part that makes SaaS spend so frustrating to manage. It isn't that IT teams are careless with money. It's that SaaS spend grows through a hundred small, individually reasonable decisions - a team adds five seats, a contract auto-renews, someone leaves and their licenses quietly keep billing - and no single person sees all of them.
The fix isn't a spending freeze. It's visibility, followed by a repeatable process. This guide covers what SaaS spend management is, why costs escape in the first place, how to run an audit that actually finds the waste, and how to stop it growing back.
SaaS spend management is the practice of tracking, controlling, and optimizing what an organization spends on cloud software. It covers four things: knowing every application in use, knowing who holds a license for each one, knowing whether those licenses are actually being used, and controlling renewals before they happen rather than after.
It's worth being precise about what it isn't, because three adjacent disciplines get confused with it constantly:
Four structural forces push costs up, and none of them require anyone to make a bad decision.
SaaS removed the procurement gate. A department head can be live on a new platform in ten minutes without IT ever knowing. Individually these are small purchases. Collectively they become a stack nobody has an inventory of - and you cannot manage spend on applications you don't know exist.
Most SaaS contracts auto-renew. That means the default outcome of doing nothing is paying again, at whatever the new rate is. Renewal is the single highest-leverage moment in the lifecycle of a contract, and it routinely passes unnoticed.
When someone leaves, HR and IT usually handle the obvious systems - email, VPN, the core platforms. The long tail of departmental tools often gets missed. Those seats keep billing, sometimes for years. They're also an active security exposure, which we'll come back to.
Tiers get chosen once, at purchase, usually by whoever needed the most advanced feature. Everyone else inherits that tier. Over time you have an organization on Enterprise seats where most people need the functionality of the base plan.
The scale of the resulting waste is significant, though estimates vary a lot depending on who's measuring and how. Zylo's 2026 SaaS Management Index puts it at roughly 36% of licenses unused against recommended utilization levels; other vendor datasets report figures ranging from the low 20s to above 50%. Treat any single number with caution - the point isn't the benchmark, it's that a meaningful fraction of your own spend is almost certainly idle, and you can measure your own figure directly.
There's a security cost layered on top of the financial one. Every unmanaged application and every orphaned account widens your attack surface. IBM's 2026 Cost of a Data Breach Report puts the global average breach cost at $4.99 million, rising to $11.5 million in the US. Spend management and identity hygiene turn out to be the same exercise viewed from two angles.
An audit is the starting point - a one-time exercise to establish what's true today. Here's the sequence that works.
Start with what finance can give you: card statements, expense reports, invoices, the AP ledger. That gets you the sanctioned stack.
It will not get you everything. Free tiers don't appear on any invoice. Personal cards reimbursed as expenses are easy to miss. Tools bought under a departmental budget line described as "software" tell you nothing.
To close the gap you need discovery that works from the identity side rather than the finance side - looking at SSO logs, OAuth grants, and browser-level signals to find applications people are actually signing into. That's the only reliable way to surface shadow IT. Once you have the list, tag each app with owner, department, cost, contract end date, and renewal terms.
This is where the money is. For each application, pull two numbers: seats you're paying for, and seats with meaningful activity in the last 90 days. The gap between them is your immediate opportunity.
Ninety days matters. A 30-day window flags people who were on parental leave or a long project; a 12-month window is so forgiving it finds nothing.
Group applications by what they actually do rather than by vendor name. Most organizations of any size discover they're running two or three tools in the same category - separate project management platforms bought by separate teams, two video conferencing tools, overlapping design software.
Consolidation is rarely purely a cost exercise. Expect pushback; teams get attached to their tools for real reasons. The argument that lands is usually operational rather than financial: one platform means one integration, one access review, one offboarding path.
Split users into those who need the premium tier and those who don't, and move the second group down. Reclaim seats from anyone with zero activity. This is the least disruptive saving available - nobody loses a tool they use.
An audit without follow-up controls buys you about two quarters. Before you close it out, put in place: a renewal calendar with alerts well ahead of each date, a lightweight approval path for new purchases, and automated deprovisioning tied to your offboarding process.
"Unused" is doing a lot of work in most spend conversations, and it's worth splitting into three categories, because each has a different fix.
Zero-activity licenses are seats with no logins at all in the review window. These are the clearest wins - usually departed employees, contractors whose engagements ended, or people who were provisioned for a project that finished. Reclaim them outright.
Low-activity licenses belong to people who log in occasionally but don't use the tool in earnest. These need a conversation, not an automatic cancellation. Sometimes occasional use is entirely legitimate; sometimes it indicates a tool that was adopted and quietly abandoned.
Over-tiered licenses are active users on a plan more expensive than their actual usage requires. Nobody loses access here - you're just stopping payment for capability that isn't being touched.
The arithmetic is straightforward. Take an organization with 500 licenses across its stack at an average of $300 per seat per year - $150,000 in annual spend. At 20% unused, that's $30,000 a year being spent on nothing. At the 36% figure from Zylo's benchmark, it's closer to $54,000.
Run the same calculation against your own numbers before you present anything internally. A figure you derived from your own stack is far more persuasive than an industry average, and it's the number your CFO will ask for.
Not every recovered seat should be cancelled. If you have a waiting list for a tool, reallocating an idle license is faster than buying a new one and costs nothing. Cancel when the seat has no internal demand; reallocate when it does. Either way, the license stops being waste.
Removing idle seats is the fastest saving, but it's a one-time gain. Sustained SaaS cost optimization comes from changing how contracts are handled.
Take the renewal calendar seriously. Every contract should have an owner and a review date set well before the renewal deadline -enough lead time to act on what you find. Auto-renewal is the mechanism by which most overspend becomes permanent. Automating renewal management is the highest-return process change available here.
Negotiate with usage data in hand. A renewal conversation where you can show that 40% of purchased seats are idle is a fundamentally different conversation from one where you're asking for a discount on principle. Usage data is leverage. Our guide to negotiating SaaS contracts covers how to structure those discussions.
Watch contract terms, not just price. Multi-year commitments look cheaper per seat and remove your ability to right-size for the duration. Seat minimums do the same. A lower headline rate that locks in a seat count you'll outgrow - in either direction - isn't a saving.
Centralize purchasing where you can. Three departments buying the same platform separately pay three times the list rate and get none of the volume discount. Consolidating those into one contract is often the largest single line item in an optimization exercise.
Here's what makes SaaS spend genuinely hard, and why finance-led approaches tend to plateau.
Every license is attached to a person. A seat isn't wasted because of an accounting error - it's wasted because an identity that no longer needs access still has it. Which means the question "what are we overspending on?" is the same question as "who has access to what, and should they?"
This has a practical consequence. Spend tools that work purely from invoice and contract data can tell you what you're paying. They can't reliably tell you whether it's justified, because they don't know who's on the other end of each seat or whether that person is still an employee.
It also means the fix compounds. Automating deprovisioning so that access is revoked the day someone leaves closes a security gap and stops a recurring charge in the same action. Running regular user access reviews surfaces both over-permissioned accounts and over-provisioned licenses from the same data. You're not choosing between saving money and reducing risk — the same control does both.
This is also why orphaned accounts deserve attention beyond their security profile. They are, quite literally, money leaving the building every month for a person who no longer works there.
Audits decay. New tools arrive, headcount shifts, contracts renew. Without a standing process, you'll be back where you started within a year.
What keeps it stable is modest:
Josys approaches SaaS spend from the identity side rather than the invoice side, which is what allows it to answer the questions that matter.
It discovers the applications actually in use across your organization - including those never routed through procurement - and maps every license back to the identity holding it. That mapping is what makes the rest possible: you can see which seats have no activity, which belong to people who have left, and which sit on tiers richer than their usage warrants.
From there, deprovisioning runs automatically as part of offboarding, so licenses are reclaimed the day access is revoked rather than at the next audit. Renewal dates and license counts live in one place, so the renewal conversation starts with data.
In practice, Josys typically finds around 25% of SaaS spend is going to waste. Book a demo to see what that figure looks like for your stack.
SaaS spend management is the practice of tracking, controlling, and optimizing what an organization spends on cloud software. It covers discovering every application in use, mapping licenses to the people holding them, measuring actual usage against licenses purchased, and managing renewals before they auto-renew.
Estimates vary widely by source and methodology. Zylo's 2026 SaaS Management Index reports roughly 36% of licenses sitting unused against recommended utilization, while other vendor datasets range from the low 20s to above 50%. Rather than relying on a benchmark, measure your own: compare seats purchased against seats with activity in the last 90 days.
Spend management is the ongoing discipline - maintaining visibility, ownership, and control over software costs. Cost optimization refers to the specific actions taken to reduce those costs: reclaiming unused licenses, right-sizing tiers, consolidating overlapping tools, and renegotiating contracts. Optimization is what you do; spend management is the system that tells you what to do and stops the waste returning.
Compare the number of seats purchased for each application against the number with meaningful activity in the last 90 days. Ninety days is the practical window — shorter periods flag people on leave, longer ones are too forgiving to surface anything. Split the results into zero-activity seats (reclaim immediately), low-activity seats (review with the team), and over-tiered seats (downgrade).
Run a full audit annually and a lighter review quarterly. Quarterly cadence catches new applications and approaching renewals while there's still time to act. Between reviews, automated alerts for new application discovery and upcoming renewal dates are more effective than scheduled reports.
It improves it. Most SaaS waste is licenses attached to identities that should no longer have access - departed employees, finished contractors, abandoned tools. Removing those seats closes security exposure and stops the charge at the same time. Unmanaged applications also sit outside your security controls entirely, so discovering them serves both purposes.
Sign-up for a 14-day free trial and transform your IT operations.
