SaaS Management: Track, Secure and Control Your Apps

SaaS management is keeping track of every piece of cloud software a business pays for: what it costs, who owns it, who can get into it, what data it holds and when it renews. It covers choosing new apps well, securing the ones you have, and cancelling the ones nobody uses.

 

Ask a business owner how many cloud apps the company pays for and the answer usually comes quickly. Ask them to produce the list and it takes considerably longer. The accounting system and Microsoft 365 are easy. The design tool somebody in marketing started a trial of, the reporting app finance added two years ago and the survey tool that renews every March are the ones that get forgotten.

This page covers what SaaS management involves, what New Zealand government guidance says about keeping a software inventory, who is responsible under the Privacy Act when a software provider has a breach, how to choose new apps, how to secure the ones you have, and where the money actually goes.

What is SaaS management?

SaaS management is the ongoing work of knowing, approving, securing and reviewing every software-as-a-service subscription a business uses. SaaS means software you rent and use over the internet rather than install and own, which now covers most business software: email, accounting, payroll, customer records and the specialist tools each team relies on.

Good SaaS management answers four questions at any moment. What are we paying for? Who is using it? Where does our data sit? What could we cut? Most businesses cannot answer all four today, which is the whole reason the discipline exists.

How is SaaS different from software you own?

Traditional software was bought once, installed on your own server or computers, and upgraded occasionally at considerable expense. SaaS reverses each of those: an ongoing subscription instead of a one-off cost, hosting by the vendor instead of by you, continuous updates instead of periodic upgrades, and pricing per user instead of per installation.

The trade is real, and it is where SaaS management begins. You no longer maintain servers or apply updates, and a new tool can be working the same afternoon. In return your data lives with the vendor, moving to a competitor after several years is a genuine project, and costs that look small per user add up quietly across a whole portfolio.

Why it has become harder to keep track of

Because a subscription can start with a company card and five minutes, with no IT involvement and no record. Each one is small enough not to trigger a second look, so the count grows faster than anybody notices. Software used to be difficult to acquire and easy to account for. SaaS made it easy to acquire and difficult to account for, and SaaS management is the correction.

What is software sprawl and why is it a problem?

Software sprawl is the uncontrolled growth of cloud apps across a business, and it is what happens by default when nobody owns SaaS management. No single subscription feels expensive, which is exactly why the total is rarely examined.

Without SaaS management, sprawl costs money in predictable ways: two teams paying for different tools that do the same job, trials that converted to paid plans, licences still billing for staff who left. It costs time as well, because work scattered across overlapping apps means files in three places and nobody quite sure which version is current.

The security cost is the one SaaS management most needs to fix. Every unmanaged app is a set of credentials nobody is watching and a copy of business data with settings nobody has checked. It overlaps closely with shadow IT, and it is how accounts belonging to people who left the business stay active for months afterwards.

  • Nobody can produce a complete list of the apps the business pays for.
  • Card statements carry software charges nobody recognises.
  • Two or more teams use different tools for the same job.
  • Subscriptions renew with no review of whether they are still used.
  • People who have left still have working accounts in business apps.

 

If two or three of those sound familiar, SaaS management is already overdue, and the fix is more straightforward than the problem makes it look.

What does NZ guidance say about keeping a software inventory?

The National Cyber Security Centre asks organisations to keep a single, current record of every system they use, and it is explicit that software and cloud services belong on it. The inventory that sits at the centre of SaaS management is, in other words, something New Zealand’s government security agency already recommends for a different reason.

Its Critical Control on asset lifecycle management asks organisations to “record, track, and maintain every system asset they use”, naming software and cloud-based systems alongside hardware, and it lists shadow IT, systems “set up unofficially by users”, as a specific risk. The related minimum standard, Assets and their Importance, goes further and names “as-a-service (aaS) offerings” directly.

Two honest caveats. The NCSC’s reason is security rather than spend: it wants you to know what exists so it can be patched, protected and retired properly, and it does not mention subscriptions or renewals at all. And the minimum standards are written for government agencies. Neither is an obligation on a private business. Both describe the same list a good SaaS management process produces anyway.

What to record for each app Why it matters
App name and what the business uses it for Shows where two tools are doing the same job
Business owner Somebody has to answer for it. The NCSC lists an owner for every asset.
Cost, billing method and licensing model The licensing model is one of the NCSC’s own suggested fields
Licences paid for and licences actually used The gap between the two is usually the first saving
Renewal date and cancellation notice period Decides whether you choose to renew or find out afterwards
What data it holds and how sensitive it is Decides how much protection the app needs, and what you owe under the Privacy Act if it is breached
Whether it is connected to single sign-on Shows which apps leave with a departing staff member automatically and which do not

 

A shared spreadsheet is enough SaaS management tooling for most small businesses. What matters is that the list is complete, that one person owns it, and that the data column is filled in. It is the field most businesses skip, and as the next section explains, it is the one with legal consequences.

Who is responsible when a SaaS provider has a privacy breach?

You are. When a software provider holds personal information purely to store or process it on your behalf, the Privacy Act treats that information as held by your business, which means the duty to notify a breach is yours even though the breach happened on their systems.

The rule is in section 11 of the Privacy Act 2020. Where one agency holds information “for safe custody or processing on behalf of” another, the information “is to be treated as being held by” the business it belongs to, not the provider. The Act adds that this applies whether or not the provider is outside New Zealand.

The Privacy Commissioner’s guidance on working with third-party providers names SaaS directly as “a classic example”, and puts the consequence plainly: “your organisation remains fully responsible under the Privacy Act for what happens to that information.”

The notification clock starts before you know

This is the part most businesses have never considered. The Commissioner generally expects to be told about a notifiable breach within 72 hours, and says that period “starts when the third-party provider knows about the breach, not when they tell you”. The Act supports that reading: what an agent knows about a breach is treated as known by the business it acts for.

So if your payroll provider discovers a breach on Monday and emails you on Thursday, you may already be past the point at which the Commissioner expects to hear from you. The Act itself says notification must happen as soon as practicable, and a provider’s delay does not reset that. The practical fix is contractual. The Commissioner strongly recommends that agreements with providers require them to report any breach to you promptly, and that clause is worth checking in every SaaS agreement that touches personal information.

What about providers based overseas?

Storing personal information with an overseas provider acting as your agent is not a disclosure under the Act, so the cross-border rules in information privacy principle 12 do not apply to it. They can apply if the provider uses the information for its own purposes, at which point it holds the information in its own right as well. Our page on data sovereignty covers the overseas question in more depth.

A timeline showing the Privacy Commissioner's 72 hours starting when a SaaS provider finds a breach, not when it tells you

How do you choose a new SaaS app?

Start with the problem rather than the product, test it on real work before committing, and check the company as carefully as the software. Most SaaS purchases that go wrong skipped at least one of those, and every bad choice becomes somebody’s SaaS management problem for years.

The most common mistake, and the one that creates the most SaaS management work later, is working backwards from a tool that looked good in a demonstration. Name the problem first, in a sentence, then look at two or three options that genuinely address it.

  • Cost over three years, not the headline price per user. Include the plan tier you will actually need once the trial features disappear.
  • Security: how the vendor handles your data and access, whether it supports single sign-on and multi-factor authentication, and what it tells customers when something goes wrong.
  • Fit with what you already run, including whether it connects to the systems it needs to exchange data with.
  • Whether people will use it. A capable tool the team avoids is more expensive than a simpler one they adopt.

 

Then run a proper trial with a few real users on a real piece of work, not the vendor’s demonstration scenario. Two weeks of genuine use tells you more than any number of sales calls.

Finally, check the vendor, because this is the part SaaS management cannot fix later. Who owns it, how long it has been operating, where it stores data, what support hours look like from New Zealand, and how you get your data out if you leave. If it holds personal information, read the breach notification clause before you sign rather than after something happens.

How do you get SaaS management under control?

SaaS management starts with an audit, a simple approval rule and a regular review. The audit gives you visibility once. The other two stop the list growing back.

  • Run the audit from the money, not from memory. Card statements, expense claims and the accounting system find subscriptions that nobody in IT knows about. Then fill in the inventory fields above for each one.
  • Set one route to a new subscription. A short request and a check against what you already have is enough to stop most duplicates. It does not need to be bureaucratic to work.
  • Review quarterly. Cancel what nobody uses, remove licences for people who have left, merge overlapping tools, and look at renewals coming up in the next three months.
  • Budget software as one line. Scattered across departments, the total is invisible. Brought together with an owner for each item, duplicates become obvious.

 

Usage data is one of the most useful SaaS management inputs at each review, where the app provides it. A tool paid for by twenty people and opened by three is the clearest downsizing decision you will ever make.

Card statements, expense claims and the accounting system feeding one SaaS management inventory

How should SaaS apps be secured?

By putting as many of them as possible behind one sign-in, with multi-factor authentication on that sign-in, and by treating every app that cannot join as a separate risk to manage. For most businesses that is usually the biggest security improvement SaaS management delivers.

Single sign-on

Single sign-on lets staff use one business identity to reach many apps, so there is one password to protect, one place to enforce multi-factor authentication and one place to switch access off when someone leaves, which is why it sits at the centre of SaaS management. If your business is on Microsoft 365, single sign-on to preintegrated SaaS applications through Microsoft Entra ID is included at no extra cost on every plan, and the old limit on how many apps each person could use it for was removed in 2020. The higher plans add conveniences, such as assigning apps to whole groups at once rather than person by person.

A reputable business app that cannot join single sign-on at all is worth asking questions about before you buy it.

For the apps that cannot join

Use a business password manager, turn on multi-factor authentication wherever the app offers it, and avoid shared logins, which make it impossible to know who did what or to remove one person’s access cleanly.

Offboarding

This is where SaaS management most often fails in practice. When somebody leaves, the apps behind single sign-on close automatically. The others close only if somebody remembers they exist, which is why the single sign-on column in the inventory earns its place. Put every app the person used on the departure checklist, not just the obvious ones.

How does SaaS management save money?

SaaS management saves money by finding spending you cannot currently see. The first review usually turns up subscriptions nobody can explain, and removing them costs nothing but the time to cancel.

  • Cancelling apps that are no longer used, or were only ever trials.
  • Removing licences for people who have left.
  • Merging two or three tools that do the same job.
  • Moving to the plan tier you actually need.
  • Deciding on renewals before they bill for another year.

 

How much that adds up to depends entirely on the business, and we would be suspicious of anybody quoting you a typical percentage before looking. What is consistent is the pattern: none of the individual items looks large, and together they are rarely trivial.

The other half of the saving is getting full value from what you keep. Many businesses pay for Microsoft 365 and use a fraction of it, then pay separately for tools that duplicate features they already own. Part of good SaaS management is checking what the core platform already does before buying something to do it again.

Apps behind single sign-on closing when a leaver's account is disabled, while separate logins stay open

Common SaaS management mistakes

The most common is treating SaaS management as a clean-up rather than a habit. A business sorts its apps out once, feels good about it, and the list grows back over the following year.

  • Relying on memory instead of a record. Knowledge of what the business pays for is usually spread across several people, none of whom has all of it.
  • Letting each team buy on its own. Duplication becomes almost certain, integrations break, and the business loses the leverage of buying once.
  • Leaving the data column blank. Without it you cannot tell which apps hold personal information, which means you cannot tell which breaches would be yours to report.
  • Never reading the breach clause. A provider that tells you about a breach a week later leaves you explaining the delay to the Privacy Commissioner.
  • Forgetting the apps outside single sign-on at offboarding. They are the ones that stay open.

 

A small business with a handful of apps can handle SaaS management with a spreadsheet and a quarterly meeting. Once the portfolio runs to a dozen or more tools across several teams, the job usually outgrows the person doing it part-time, and that is the point at which it is worth bringing in help.

Frequently Asked Questions

What is SaaS management?

SaaS management is keeping track of every cloud software subscription a business pays for: what it costs, who owns it, who can get into it, what data it holds and when it renews. It also covers choosing new apps well, securing the ones you have and cancelling the ones nobody uses. The aim is to be able to say exactly what you pay for and why.

What is software sprawl?

Software sprawl is the uncontrolled growth of cloud apps across a business, where subscriptions multiply because each one is too small to attract attention. It shows up as duplicate tools, trials that became paid plans, licences for people who have left and business data sitting in apps nobody is watching. It is what happens by default when nobody owns SaaS management.

What is the difference between choosing SaaS and managing it?

Choosing is a one-off decision about fit, cost and the vendor, made before you sign. Managing is everything after that: keeping the app on the inventory, controlling who has access, reviewing whether it is still worth paying for and closing accounts when people leave. Good choices make management easier, but they do not replace it.

What should a SaaS inventory record?

For each app: its name and purpose, a business owner, the cost and licensing model, licences paid for against licences used, the renewal date and notice period, what data it holds and how sensitive that is, and whether it is connected to single sign-on. The data field is the one most businesses skip and the one with legal consequences.

Does the NCSC say we should keep a software inventory?

Yes. The NCSC’s Critical Control on asset lifecycle management asks organisations to record, track and maintain every system asset they use, explicitly including software and cloud-based systems, with an owner for each. Its minimum standard on assets names as-a-service offerings directly. Its reason is security rather than cost, and the minimum standards are written for government agencies, but the list it describes is the same one SaaS management produces.

Who notifies the Privacy Commissioner if our SaaS provider has a breach?

Usually your business does. Where a provider holds personal information purely to store or process it for you, section 11 of the Privacy Act treats the information as held by you, and the Privacy Commissioner’s guidance says your organisation remains fully responsible. The Commissioner generally expects notification within 72 hours, starting from when the provider knew about the breach, so contracts should require prompt reporting to you.

Is using an overseas SaaS provider a disclosure under the Privacy Act?

Not if the provider is only storing or processing the information on your behalf. In that case the transfer is not a disclosure, so the cross-border rules in information privacy principle 12 do not apply, and the Commissioner says that in most circumstances you are not legally required to have a special agreement for overseas cloud storage. It changes if the provider uses the information for its own purposes.

How do we choose a new SaaS app?

Name the problem first, then compare two or three options on cost over three years, security, fit with your existing systems and whether people will actually use it. Trial the best candidate with real users on real work for a couple of weeks. Then check the vendor: ownership, track record, where data is stored, how you get it out, and what the contract says about breaches.

Does Microsoft 365 include single sign-on for other apps?

Yes. Single sign-on to preintegrated SaaS applications through Microsoft Entra ID is included at no extra cost, and an earlier limit on how many apps each person could use it for was removed in 2020. Higher plans add conveniences such as assigning apps to whole groups at once rather than one person at a time. Connecting apps to single sign-on also makes offboarding far more reliable and SaaS management far simpler.

How often should we review our subscriptions?

Quarterly SaaS management reviews work for most businesses. At each review, cancel what nobody uses, remove licences for people who have left, merge overlapping tools and look ahead at renewals falling due in the next three months so you decide before they bill. A regular cycle is what stops the list growing back after the first clean-up.

How much money does poor SaaS management waste?

It depends entirely on the business, and a figure quoted before anyone has looked at your subscriptions should be treated with suspicion. The consistent pattern is that the first review finds subscriptions nobody can explain, and that the individual amounts are small enough to have escaped notice while the total is not. Removing them is usually the quickest saving available.

Can a small business manage SaaS without IT help?

Yes, up to a point. A handful of apps can be managed well with a shared spreadsheet, one owner and a quarterly review. Once the portfolio runs to a dozen or more tools across several teams, keeping the inventory complete and the offboarding reliable usually outgrows a part-time job, and that is when outside help tends to pay for itself.

NEXT STEP

Find out what you are actually paying for

An IT assessment lists every cloud app your business pays for, who owns it, which ones hold personal information and which ones would stay open after somebody leaves. You get the findings whether or not you work with us. Christchurch, Dunedin and across the South Island.

Or read more about our cloud solutions.

Start typing and press Enter to search

Business IT support models: flat vector comparing in-house, outsourced, and co-managed IT support options.Security awareness training NZ -- flat vector of NZ business team engaged in cyber security training with phishing simulation Call Us Now