- Home
- saas account waste best practices
How to Cut SaaS Account Waste

What is SaaS account waste, and how much are you losing?
SaaS account waste is the cost of unused, duplicate, or misaligned software subscriptions. It occurs because SaaS applications are easy to provision, hard to track, and difficult to decommission when employees change roles or leave. According to Gartner, 30% of the $102 billion spent on SaaS globally went unused as of 2020 That waste multiplies because you pay the subscription cost annually instead of once—and you pay it for licenses no one uses. The result: unused seats, duplicate tools, "shadow IT" purchases employees make without approval, and licensing mismatches when employees are promoted or reassigned. A single inactive account you don't notice costs money every month. Multiply that across a 5,000-person organization and the leak becomes visible.
Why this matters: Unlike hardware devices, which are visibly returned when employees leave, SaaS licenses are invisible. A former employee's Salesforce seat, a contractor's Jira license, or a duplicate Creative Cloud subscription can run for months undetected. The lever that stops waste is visibility: knowing who uses what, whether they actually need it, and whether a cheaper alternative exists.
This guide covers 10 practices to build that visibility and cut SaaS account waste at scale. At the end, we include a monthly checklist you can run to keep your software costs under control.
How should I categorize SaaS users by role and access need?
Start by categorizing users into internal (permanent, full-time) and external (contractors, temporary), because each group needs different monitoring. Your HR department is your partner here: they maintain the authoritative employee list and can flag role changes and departures.
Why this matters: Internal users—such as a product manager who needs Jira for years—can be locked into longer, discounted contracts. External users—consultants or seasonal staff—need active license tracking so you don't continue paying after their project ends. Internal users typically need constant access and justify long-term licensing commitments. External users are often temporary and require close attention: when their engagement ends, their license should be deactivated within days, not months.
Example: A product manager assigned to a core team might hold a Jira subscription for 3 years. A contractor hired for a 6-month feature build needs the same tool but should have their seat reclaimed the day their contract ends. Without this distinction, you'll continue paying for the contractor's license long after they leave.
Pro tip: Work with HR to automate this categorization. A regular sync between HR's employee list and your SaaS licenses catches orphaned accounts before they accumulate cost.
Key points:
- Internal users warrant longer-term contracts and less frequent audits.
- External users require weekly or monthly activity checks and immediate deactivation workflows.
- Role changes matter as much as new hires: if a designer moves to finance, their Adobe subscription may no longer be needed.
- Categorization is the foundation for the practices that follow.
Why track employee lifecycle (JML) for SaaS licenses?
The Joiner-Mover-Leaver (J-M-L) process aligns SaaS licensing with HR events. A "joiner" is a new employee; a "mover" is a promotion or role change; a "leaver" is a termination or departure. Each event is a trigger to review what SaaS access that person should have.
Why this matters: Most SaaS waste comes from the gaps between an employee's role change and the license updates that should follow. A salesperson promoted to sales engineering might keep their old Salesforce license even though they no longer need it. An employee on parental leave keeps their Adobe seat even though they're not working. J-M-L catches these gaps before they become recurring charges.
Example: Your J-M-L salesperson
Key J-M-L checkpoints
Joiners
Don't assign SaaS licenses until the employee is actually starting work. Verify the role's business requirements; don't assign the full suite by default.
Movers
If a role change means the employee no longer needs a tool, deactivate the license and free the seat for someone else. Coordinate with HR on timing.
Leavers
Deactivate SaaS licenses on or before the employee's last day. If the employee is terminated, deactivate before they're notified to prevent data theft.
Best practice: Tie your license deactivation workflows to HR's termination process. Automate notifications so IT and HR both confirm the action has occurred.
Key insights:
- Joiners add cost only when they start, not weeks before.
- Movers unlock hidden savings when role changes eliminate tool needs.
- Leavers are the largest waste category: unlicensed accounts continue billing for weeks if not caught immediately.
- Automate the workflow so no J-M-L event is missed.
How do I identify the real person behind each SaaS account?
Associate each SaaS login with a real employee name, not a generic email or shared credential. Generic emails like marketing@company.com or test accounts like testuser1 make it impossible to know who is actually using a license—or whether anyone is.
Why this matters: If you can't identify the person, you can't deactivate the account when they leave. You also risk compliance violations (SAP, for example, flags generic functional accounts as audit risk and may charge for remediation). Generic accounts also hide duplicate licenses: two people in different departments might unknowingly both have the same tool under shared credentials.
Example:
Rule:
Key points:
- Named accounts are auditable: you can track who uses what, when, and why.
- Generic emails hide duplicates and prevent deactivation.
- SAP and other vendors flag generic accounts as compliance risk during audits.
- Start with a clean account audit: find all unnamed or test accounts and either name them or deactivate them.
What inactivity threshold disables SaaS access?
Set activity thresholds based on the role and the tool. A financial analyst might not touch SAP for three months but still need access; a sales representative should be flagged after 30 days of inactivity. Use Active Directory (AD), Single Sign-On (SSO), and email logs to measure activity.
Why this matters: Inactivity is the largest single source of SaaS waste. An employee on leave, a person who changed roles internally, or someone who left the company can accumulate unused licenses for months. An automated activity threshold catches these without manual review. The challenge: Set the threshold too high (180 days) and you'll miss cost recovery. Set it too low (30 days) and you'll deactivate licenses for people on vacation, parental leave, or temporary project gaps—and they'll be angry. Coordinate with HR and department heads to find the right window.
How to measure activity:
- Active Directory (AD) / Single Sign-On (SSO): Track login records. SSO logs show which cloud apps were accessed and when.
- Exchange Online / Email: If an employee hasn't sent an email in 60 days, they may not need their SaaS tools either.
- Application audit logs: Some SaaS apps expose their own activity logs (Salesforce, Microsoft 365). Pull those directly to know the last login date.
Example:
Best practice:
Key thresholds:
- 30-60 days is typical for user-based SaaS (Slack, Jira, Salesforce).
- 90-180 days makes sense for tools used seasonally (tax/audit software, reporting tools).
- Exception list matters as much as the threshold: parental leave, sabbatical, medical leave, and executive travel can legitimately create long inactive periods.
- Monthly review and re-harvest prevents cost creep.
How do I detect shadow IT SaaS purchases?
Shadow IT is software employees procure without IT approval. Because SaaS is cheap and accessible directly from a web browser, a marketer might sign up for Dropbox on their corporate card without telling IT. One person becomes a team; five separate Dropbox accounts become a security and compliance risk.
Why this matters: Shadow IT is invisible cost leak. It also introduces unmanaged security and compliance risks (unsanctioned data storage, untracked user provisioning, no audit trail). The goal is not to punish employees but to understand what they're trying to do and whether a centrally approved alternative exists.
How to detect shadow IT:
- Single Sign-On (SSO) logs: If your company uses SSO, review the login records. Logins to non-approved domains or apps will stand out.
- Browser logs and DNS records: If you use a network monitoring tool or DNS firewall, review the sites employees are visiting. A spike in traffic to Dropbox, Box, or other file-sharing apps signals activity.
- Accounts Payable (AP) and expense reports: Check credit card charges. Any recurring SaaS charge from an employee's card that's not on your approved list is likely shadow IT.
- Procurement system: If you use a purchasing tool, query for unapproved vendors or recurring charges.
Example:
Pro tip:
Key insights:
- Small shadow IT (a few subscriptions, <$100/month) is a sign, not a crisis.
- Large shadow IT (dozens of instances, >$1K/month) is a control failure and needs investigation.
- Browser and network logs are the best detection method for small organizations.
- AP/expense reports are the best source for large organizations with many cards and vendors.
Duplicate vs. redundant SaaS licenses?
A duplicate is when the same person or team pays for the same tool twice. A redundancy is when different teams use different tools that do the same job. Duplicates are straightforward: a person has both a Salesforce Professional license and a Salesforce Standard license, or two people in the same role both have their own Adobe Creative Cloud subscriptions when the company could buy one shared group license. The fix is consolidation. Redundancies are trickier: your company uses Slack for instant messaging but also Teams, and some departments prefer one over the other. Or you use both Dropbox and Box for file storage. The tools aren't wrong—they may have different purposes—but they're also not coordinated, and costs add up. The fix requires a decision: standardize on one tool, or cost-justify why both are needed.
Example (redundancy):
Example (duplicate):
Rule:
Key points:
- Duplicates waste money immediately and have no upside.
- Redundancies can be deliberate (the premium Slack experience) or accidental (no one knew the other tool existed).
- Bundles and suites introduce hidden duplicates: Microsoft 365 E5 includes Project, Power BI Pro, and Visio web. Users who also have standalone Project or Power BI licenses are duplicated.
- Monthly review catches both, but redundancy decisions should be strategic, not reactive.
What are the 3 biggest SaaS waste buckets?
SaaS waste falls into three categories. Use "rule sets" (automated conditions) to identify each bucket and then decide how to act. A rule set is a condition applied to your entire user base to find a specific pattern. For example, "find all users who haven't logged in for 120 days and are still assigned a Salesforce license." Rule sets are powerful because they scale: one rule catches waste across thousands of users.
1. Inactive user accounts
An employee uses a subscription rarely or not at all. The condition: "last login date > 90 days ago." The action: deactivate and reassign the seat (called "re-harvesting").
2. Unknown user accounts
An employee left the company and their SaaS license is still active. The condition: "user not found in HR employee list." The action: deactivate the account.
3. Right-sizing opportunities
An employee is not using the full tier of their license. The condition: "user assigned Microsoft 365 E5 but only uses email and calendar (not Teams, not advanced compliance features)." The action: downgrade to Microsoft 365 E1 or E3 and save the difference.
Example:
The result:
Challenge:
Key insights:
- Inactive accounts are the easiest bucket to fix: set a threshold, run the rule, deactivate.
- Unknown accounts are the second easiest: match SaaS users to HR roster, deactivate mismatches.
- Right-sizing is the most complex and requires domain knowledge of your licensing tiers.
- Rule sets scale: one rule can recover thousands in licenses across your organization.
Apply same rules to all users or tailor by role?
Tailor rules by role, department, and geography. A salesperson in Chicago has different SaaS needs than a financial analyst in Paris, and both have different needs than a data scientist in the US. This is called "user scoping."
Why this matters: One-size-fits-all rules will either miss waste or break workflows. A financial person who doesn't touch SAP for three months is still a critical user who needs immediate access when month-end close starts. A salesperson with 60 days of inactivity is more likely to be disengaged or between deals. Geography matters too: A user in France must comply with GDPR and may have different SaaS options than a user in the US. Regional data residency requirements, local vendor relationships, and localized contracts all affect which tools are available and appropriate.
Example:
Example (geography):
Best practice:
Key points:
- Role scoping is the biggest opportunity to reduce false positives (deactivating licenses you shouldn't).
- Geography scoping is often required by compliance (GDPR, local data residency).
- Department scoping helps because different departments use different tools and have different activity patterns.
- Scoped rules require knowledge of your organization, so involve department heads in rule design.
Should I ask users before disabling SaaS access?
Yes. When in doubt, ask a department head or the employee directly. People are more likely to accept a decision if they're involved in the process and they understand the rationale.
Why this matters: Surprising an employee by disabling their access creates friction and frustration. If a license is essential to their role, the sudden loss of access can block their work for hours. But if you explain the deactivation process in advance and provide a way to appeal or request reinstatement, people feel heard and the change feels fair.
How to communicate:
- Notifications: Tie license deactivation to automated email workflows. Warn users 30 days before an inactive license is disabled. Give them a way to request reinstatement.
- Department coordination: Contact the employee's manager or department head before deactivation. They may know something you don't (leave of absence, maternity leave, sabbatical).
- Approval workflows: If a license is mission-critical to a role, require human approval before deactivation, even if the user is inactive.
Example:
Example:
Best practice:
Key points:
- Notifications reduce surprise and friction.
- Department heads often know when someone is temporarily unavailable (leave, sabbatical, medical leave).
- Appeal processes build trust and catch mistakes.
- Tie deactivation to HR workflows so it doesn't happen by accident during leave.
What's a practical monthly checklist for SaaS optimization?
Here's the checklist we recommend for the three most common SaaS platforms: Microsoft 365, Adobe Creative Cloud, and Salesforce. Run this at the end of each month to keep waste from accumulating.
Data extraction and validation
- Extract users: Export all users from Microsoft 365, Adobe Creative Cloud, and Salesforce using Graph API, CSV, or your preferred method. Note the export date.
- Check domains: Review email domains assigned to accounts. Flag any non-company domains (e.g., @gmail.com, @temporary-vendor.com) and validate whether they should have a license.
- Cross-check against Active Directory: Compare all SaaS users to your Active Directory or LDAP. Flag users not in AD (likely left the company or are contractors without a formal record).
License optimization
- Consolidate standalone Adobe licenses: Any user with more than three standalone Creative Cloud products should be converted to Creative Cloud All Apps. It's cheaper and gives them access to everything.
- Check for double allocations: Flag any user assigned multiple licenses of the same type (e.g., Microsoft 365 E1 and E3 for the same person, or Project P1 and P2). This is always a duplicate.
- Remove redundant standalones: After consolidation, remove standalone products that are now included in bundles.
Deactivation and right-sizing
- Deactivate inactive accounts: Cross-check the user extract against Active Directory. Any user marked as "disabled" in AD should be deactivated in SaaS. Any user with no login activity in 120+ days should be reviewed for deactivation.
- Right-size to the cheapest plan: Identify users with multiple licenses or higher tiers than they need. Move them to the cheapest plan that covers their role.
- Check for duplicate bundles: For each user, ensure they don't have overlapping bundle subscriptions (e.g., both Microsoft 365 E3 and E5 in different systems).
Close and documentation
- Archive the user extract: Save the final list as a record of active users and monthly spend per product. Use this as your baseline for next month's comparison and to track trends.
Tools matter here: manual execution of this checklist is error-prone and slow. A platform designed for SaaS management automates all 10 steps and flags exceptions for human review.
Key insights:
- Extraction and validation catches unknowns (contractors, test accounts, departmental soft licenses).
- Consolidation and right-sizing are the biggest immediate cost-reductions.
- Deactivation closes the loop and prevents waste from accumulating month to month.
- Archive every month so you can measure progress and spot trends (e.g., user count growth vs. license cost growth).
Frequently Asked Questions
How much SaaS spend is typically wasted?
What's the difference between shadow IT and an unauthorized duplicate?
Shadow IT is SaaS that an employee procures and pays for without IT approval (e.g., a marketer paying for Dropbox from their corporate card). An unauthorized duplicate is when an employee or department buys a license for a tool your company already provides (e.g., a second Salesforce license without IT's knowledge). Shadow IT is new risk; duplicates are redundancy within existing approved software. Both are waste, but they require different fixes: shadow IT needs discovery and standardization; duplicates need consolidation.
How do I start measuring SaaS account activity if I don't have monitoring in place today?
When should I use automation vs. manual review for disabling access?
Get in touch with an expert
Do you have questions about our offering? A quick call can be way more helpful than a long email chain. Talk to one of our experts to explore our products and see them in action.

Brian Riley
Sales Development
IT Service Management
Send us a message
No matter if you like to partner with USU or just have a few questions.



