SaaS Sprawl Moves from IT Nuisance to Enterprise-Wide Management Challenge
As enterprises rapidly expand their SaaS portfolios—and employees increasingly adopt AI-powered tools independently—organisations are facing growing challenges around visibility, cost, security and compliance. Vasudevan Seshadri, Director of Product Management at ManageEngine, explains why SaaS sprawl requires continuous portfolio management, how businesses can identify genuine opportunities for consolidation, and how IT teams can balance employee flexibility with stronger application governance.
How serious has SaaS sprawl become for enterprises, and what are its biggest operational challenges?
SaaS sprawl has become a significant operational challenge because the number of applications in use can easily outpace the processes used to track and manage them. While cost contributes greatly to the issue, the broader challenge is maintaining a reliable view of what applications exist, who is using them, and what the organisation truly needs to be paying for.
A lack of visibility in any of these can create several downstream problems. IT and procurement teams may have a harder time spotting duplicate subscriptions, unused licenses, upcoming renewals, or spend that sits outside normal purchasing channels. Security and compliance teams can also be left with gaps around user access, application permissions, and how company data is being handled.
AI services add to this complexity because new subscriptions can be set up in minutes, often on personal or corporate cards, and can start generating spend before procurement teams have any visibility into them.
Look at SaaS sprawl less as a periodic clean-up exercise and more as an ongoing management challenge. A regularly updated view of applications, usage, access, and spend gives teams a stronger basis for making decisions across the SaaS portfolio.
How can organisations identify redundant, overlapping, or underutilised SaaS applications?
A useful way to identify SaaS waste is to look at the application portfolio from two angles: utilisation and redundancy. For underutilisation, viewing assigned licenses is only the starting point. It helps to evaluate them against application-level usage, frequency of use, and the type of workflow the tool supports.
A 30-day window may be useful for everyday productivity tools, while applications used for monthly, quarterly, or seasonal work need to be assessed from a much longer window. This helps avoid treating low frequency tools as low value. Redundancy is slightly different. Two applications can both be well used and still overlap if different teams are paying for tools that solve largely the same problem.
Grouping applications by function, then comparing their capabilities, cost, usage, and the teams relying on them can make that overlap easier to see. The final check is context. Before classifying a license or application as waste, it is worth understanding why it exists and whether a specific workflow depends on it. Usage data identifies where to look; business context helps determine whether there is a genuine opportunity to consolidate or right-size applications.
What are the biggest security and compliance risks created by uncontrolled SaaS adoption?
The biggest security and compliance risk with SaaS sprawl is losing consistent control over who can access applications, what data is being shared, and whether those applications meet the organisation’s security and regulatory requirements. Access is one part of this.
Employees can accumulate permissions as they change roles, and previous privileges may remain after they are no longer needed. If deprovisioning is missed when someone leaves, a former employee could continue to access company systems or data. There is also the risk of applications operating outside IT or security oversight. When a tool has not gone through security, privacy, or contractual review, the organisation may not have a clear view of how data is stored, processed, shared, or retained.
This can create compliance concerns around cross-border transfers of personal data, contractual obligations, and whether appropriate safeguards are in place. AI tools compound these risks since they are often adopted at the individual level, sometimes before anyone has reviewed what data the tools access or how that data is processed. Maintaining visibility across applications, users, permissions, and data flows can help security and compliance teams identify gaps early and address them before they become larger issues.
How can IT teams balance employee demand for specialised tools with the need for greater application control?
Balancing employee choice with application control works best when IT is not positioned as the team that automatically says no. Because employees often turn to specialised tools to solve a specific problem quickly, the goal is to offer this same flexibility but with sensible boundaries.
A practical middle ground is to make the approved path simple and predictable. Low-risk tools could move through a lighter review, while applications that handle sensitive data, request broad permissions, or create regulatory concerns would naturally need closer scrutiny. Clear guidance on what requires review gives employees a better sense of where the boundaries are.
It also helps to understand why a new tool is being requested before deciding whether it should be restricted. Sometimes an existing approved application already covers the need, while, in other cases, the specialised tool may genuinely be the better fit.
This gives employees enough flexibility to work effectively while giving IT teams enough visibility to understand what is being used, what data it touches, and where intervention is necessary.
Is SaaS consolidation becoming a strategic priority for CIOs, and what should enterprises consider before retiring applications?
SaaS consolidation is gaining more attention as CIOs look to reduce costs and complexity, although rationalisation would be a more useful objective than simply reducing application count. A smaller portfolio is not automatically a better one if useful tools are removed just to reach a target number. The more important question is which applications are delivering enough value to justify their cost and which are continuing largely because no one has reevaluated the decision to renew them.
Looking at SaaS as a portfolio can help here. Usage data provides an important signal, but it should be considered alongside cost, business value, and the workflows an application supports. Before retiring any application, it is worth checking whether people are actively using it, whether another application can genuinely cover the same need, and whether there are dependencies that may not be immediately visible.
For instance, a low-usage application can still be feeding data into another system that people rely on. Rationalisation works best when the goal is to remove unnecessary duplication and spend without disrupting the work employees still depend on.
What practical steps can organisations take to reduce SaaS sprawl without affecting employee productivity or business operations?
A practical way to reduce SaaS sprawl without disrupting day-to-day work is to start with a clear picture of what is being used, what it costs, and which teams depend on it. Procurement records, identity-provider data, and application-level usage can each add useful context, especially when considered together. From there, renewal periods can be a natural point to review whether an application is still delivering enough value to justify its cost.
Low usage or overlap with another tool may be a reason to look more closely at an application or license, but it is not necessarily a reason to remove either immediately. Some applications support a small group of users or a workflow that is critical even if overall usage appears low. Application reviews can also help involve the teams using a tool before making a consolidation decision.
These reviews can often surface dependencies, integrations, or use cases that are not obvious from license or usage data alone. Where a tool is retired, having a suitable alternative and a clear transition path helps preserve productivity while still reducing unnecessary applications and spend.



