• Home
  • saas account waste best practices

How to Cut SaaS Account Waste

Stop paying for unused SaaS licenses. Learn 10 practices IT and procurement teams use to identify waste, cut costs, and track user activity.
usu_sam_wp_futureproof-it-budget_lp-header_1920x1080px-1-2

What is SaaS account waste, and how much are you losing?

SaaS account waste is the cost of unused, duplicate, or misaligned software subscriptions. It occurs because SaaS applications are easy to provision, hard to track, and difficult to decommission when employees change roles or leave. According to Gartner, 30% of the $102 billion spent on SaaS globally went unused as of 2020 That waste multiplies because you pay the subscription cost annually instead of once—and you pay it for licenses no one uses. The result: unused seats, duplicate tools, "shadow IT" purchases employees make without approval, and licensing mismatches when employees are promoted or reassigned. A single inactive account you don't notice costs money every month. Multiply that across a 5,000-person organization and the leak becomes visible.

Why this matters: Unlike hardware devices, which are visibly returned when employees leave, SaaS licenses are invisible. A former employee's Salesforce seat, a contractor's Jira license, or a duplicate Creative Cloud subscription can run for months undetected. The lever that stops waste is visibility: knowing who uses what, whether they actually need it, and whether a cheaper alternative exists.

This guide covers 10 practices to build that visibility and cut SaaS account waste at scale. At the end, we include a monthly checklist you can run to keep your software costs under control.

How should I categorize SaaS users by role and access need?

Start by categorizing users into internal (permanent, full-time) and external (contractors, temporary), because each group needs different monitoring. Your HR department is your partner here: they maintain the authoritative employee list and can flag role changes and departures.

Why this matters: Internal users—such as a product manager who needs Jira for years—can be locked into longer, discounted contracts. External users—consultants or seasonal staff—need active license tracking so you don't continue paying after their project ends. Internal users typically need constant access and justify long-term licensing commitments. External users are often temporary and require close attention: when their engagement ends, their license should be deactivated within days, not months.

Example: A product manager assigned to a core team might hold a Jira subscription for 3 years. A contractor hired for a 6-month feature build needs the same tool but should have their seat reclaimed the day their contract ends. Without this distinction, you'll continue paying for the contractor's license long after they leave.

Pro tip: Work with HR to automate this categorization. A regular sync between HR's employee list and your SaaS licenses catches orphaned accounts before they accumulate cost.

Key points:

    • Internal users warrant longer-term contracts and less frequent audits.
    • External users require weekly or monthly activity checks and immediate deactivation workflows.
    • Role changes matter as much as new hires: if a designer moves to finance, their Adobe subscription may no longer be needed.
    • Categorization is the foundation for the practices that follow.

Why track employee lifecycle (JML) for SaaS licenses?

The Joiner-Mover-Leaver (J-M-L) process aligns SaaS licensing with HR events. A "joiner" is a new employee; a "mover" is a promotion or role change; a "leaver" is a termination or departure. Each event is a trigger to review what SaaS access that person should have.

Why this matters: Most SaaS waste comes from the gaps between an employee's role change and the license updates that should follow. A salesperson promoted to sales engineering might keep their old Salesforce license even though they no longer need it. An employee on parental leave keeps their Adobe seat even though they're not working. J-M-L catches these gaps before they become recurring charges.

Example: Your J-M-L salesperson

A new salesperson is hired (joiner) and assigned Salesforce. Six months later, she's promoted to sales engineer (mover) and now needs different Salesforce permission levels—potentially a different license tier. Two years later, she leaves the company (leaver) and her license should be deactivated immediately. Without J-M-L tracking, any of these transitions is easy to miss.

Key J-M-L checkpoints

Joiners

Don't assign SaaS licenses until the employee is actually starting work. Verify the role's business requirements; don't assign the full suite by default.

Movers

If a role change means the employee no longer needs a tool, deactivate the license and free the seat for someone else. Coordinate with HR on timing. 

Leavers

Deactivate SaaS licenses on or before the employee's last day. If the employee is terminated, deactivate before they're notified to prevent data theft. 

Best practice: Tie your license deactivation workflows to HR's termination process. Automate notifications so IT and HR both confirm the action has occurred.

Key insights:

    • Joiners add cost only when they start, not weeks before.
    • Movers unlock hidden savings when role changes eliminate tool needs.
    • Leavers are the largest waste category: unlicensed accounts continue billing for weeks if not caught immediately.
    • Automate the workflow so no J-M-L event is missed.

How do I identify the real person behind each SaaS account?

Associate each SaaS login with a real employee name, not a generic email or shared credential. Generic emails like marketing@company.com or test accounts like testuser1 make it impossible to know who is actually using a license—or whether anyone is.

Why this matters: If you can't identify the person, you can't deactivate the account when they leave. You also risk compliance violations (SAP, for example, flags generic functional accounts as audit risk and may charge for remediation). Generic accounts also hide duplicate licenses: two people in different departments might unknowingly both have the same tool under shared credentials.

Example:

A marketing admin assigns a Creative Cloud license to the shared email marketing@company.com. Three months later, a new marketing coordinator is hired and assigned the same email-based license. Now the company is paying for two licenses but has no way to tell them apart.

Rule:

Never assign a SaaS license to a group email, test account, or shared credential. Tie every license to a named employee. Keep an up-to-date list of account holders and verify it monthly.

Key points:

    • Named accounts are auditable: you can track who uses what, when, and why.
    • Generic emails hide duplicates and prevent deactivation.
    • SAP and other vendors flag generic accounts as compliance risk during audits.
    • Start with a clean account audit: find all unnamed or test accounts and either name them or deactivate them.

What inactivity threshold disables SaaS access?

Set activity thresholds based on the role and the tool. A financial analyst might not touch SAP for three months but still need access; a sales representative should be flagged after 30 days of inactivity. Use Active Directory (AD), Single Sign-On (SSO), and email logs to measure activity.

Why this matters: Inactivity is the largest single source of SaaS waste. An employee on leave, a person who changed roles internally, or someone who left the company can accumulate unused licenses for months. An automated activity threshold catches these without manual review. The challenge: Set the threshold too high (180 days) and you'll miss cost recovery. Set it too low (30 days) and you'll deactivate licenses for people on vacation, parental leave, or temporary project gaps—and they'll be angry. Coordinate with HR and department heads to find the right window.

How to measure activity:

    • Active Directory (AD) / Single Sign-On (SSO): Track login records. SSO logs show which cloud apps were accessed and when.
    • Exchange Online / Email: If an employee hasn't sent an email in 60 days, they may not need their SaaS tools either.
    • Application audit logs: Some SaaS apps expose their own activity logs (Salesforce, Microsoft 365). Pull those directly to know the last login date.

Example:

Your organization sets a threshold of 90 days of inactivity. The workflow checks each user's last login date against AD and SSO records. A marketing employee hasn't logged into Adobe in 120 days—they're deactivated and the license is freed. But your CFO hasn't logged into Tableau in 4 months and is flagged for a human review (because finance roles often have seasonal usage patterns).

Best practice:

Use a tool to automate threshold checks. Manual reviews are error-prone and slow. Combine automated rules with human exceptions for roles where inactivity is normal.

Key thresholds:

    • 30-60 days is typical for user-based SaaS (Slack, Jira, Salesforce).
    • 90-180 days makes sense for tools used seasonally (tax/audit software, reporting tools).
    • Exception list matters as much as the threshold: parental leave, sabbatical, medical leave, and executive travel can legitimately create long inactive periods.
    • Monthly review and re-harvest prevents cost creep. 

How do I detect shadow IT SaaS purchases?

Shadow IT is software employees procure without IT approval. Because SaaS is cheap and accessible directly from a web browser, a marketer might sign up for Dropbox on their corporate card without telling IT. One person becomes a team; five separate Dropbox accounts become a security and compliance risk.

Why this matters: Shadow IT is invisible cost leak. It also introduces unmanaged security and compliance risks (unsanctioned data storage, untracked user provisioning, no audit trail). The goal is not to punish employees but to understand what they're trying to do and whether a centrally approved alternative exists.

How to detect shadow IT:

    • Single Sign-On (SSO) logs: If your company uses SSO, review the login records. Logins to non-approved domains or apps will stand out.
    • Browser logs and DNS records: If you use a network monitoring tool or DNS firewall, review the sites employees are visiting. A spike in traffic to Dropbox, Box, or other file-sharing apps signals activity.
    • Accounts Payable (AP) and expense reports: Check credit card charges. Any recurring SaaS charge from an employee's card that's not on your approved list is likely shadow IT.
    • Procurement system: If you use a purchasing tool, query for unapproved vendors or recurring charges.

Example:

A marketing manager enrolls her team in Dropbox to send files to a print vendor. The cost is $10/month per person, so it seems invisible—until you see five $10 charges in your AP system. IT reviews SSO logs and sees Dropbox logins from the marketing department's IP range. Rather than shut it down, IT asks: why do you need this instead of SharePoint? The answer might be speed, simplicity, or the vendor's requirement. Either way, you now have a conversation and a decision

Pro tip:

Shadow IT often reveals where your official solutions fall short. Use it as feedback for your SaaS rationalization: if people are buying Dropbox because they find SharePoint slow, that's a product improvement opportunity.

Key insights:

    • Small shadow IT (a few subscriptions, <$100/month) is a sign, not a crisis.
    • Large shadow IT (dozens of instances, >$1K/month) is a control failure and needs investigation.
    • Browser and network logs are the best detection method for small organizations.
    • AP/expense reports are the best source for large organizations with many cards and vendors.

Duplicate vs. redundant SaaS licenses?

A duplicate is when the same person or team pays for the same tool twice. A redundancy is when different teams use different tools that do the same job. Duplicates are straightforward: a person has both a Salesforce Professional license and a Salesforce Standard license, or two people in the same role both have their own Adobe Creative Cloud subscriptions when the company could buy one shared group license. The fix is consolidation. Redundancies are trickier: your company uses Slack for instant messaging but also Teams, and some departments prefer one over the other. Or you use both Dropbox and Box for file storage. The tools aren't wrong—they may have different purposes—but they're also not coordinated, and costs add up. The fix requires a decision: standardize on one tool, or cost-justify why both are needed.

Example (redundancy):

The company provides Microsoft Teams for all employees but the design team also pays for Slack out of their department budget because they say it's easier to use. Both are messaging tools. A cost-justification review shows that Slack costs $8/user/month and Teams is included in Microsoft 365. The decision: standardize on Teams, or continue paying Slack's premium in exchange for the UX that the design team prefers. Either way, it's a deliberate choice, not a leak.

Example (duplicate):

An employee's manager purchased a Microsoft 365 E5 license for them. Three months later, their new department purchased the same license without realizing it was already assigned. Now the company is paying for two E5 licenses for one person. The duplicate is caught during a monthly audit and removed.

Rule:

Duplicates are always a waste. Redundancies sometimes are—review them quarterly and decide deliberately.

Key points:

    • Duplicates waste money immediately and have no upside.
    • Redundancies can be deliberate (the premium Slack experience) or accidental (no one knew the other tool existed).
    • Bundles and suites introduce hidden duplicates: Microsoft 365 E5 includes Project, Power BI Pro, and Visio web. Users who also have standalone Project or Power BI licenses are duplicated.
    • Monthly review catches both, but redundancy decisions should be strategic, not reactive.

What are the 3 biggest SaaS waste buckets?

SaaS waste falls into three categories. Use "rule sets" (automated conditions) to identify each bucket and then decide how to act. A rule set is a condition applied to your entire user base to find a specific pattern. For example, "find all users who haven't logged in for 120 days and are still assigned a Salesforce license." Rule sets are powerful because they scale: one rule catches waste across thousands of users.

1. Inactive user accounts

An employee uses a subscription rarely or not at all. The condition: "last login date > 90 days ago." The action: deactivate and reassign the seat (called "re-harvesting").

2. Unknown user accounts

An employee left the company and their SaaS license is still active. The condition: "user not found in HR employee list." The action: deactivate the account.

3. Right-sizing opportunities

An employee is not using the full tier of their license. The condition: "user assigned Microsoft 365 E5 but only uses email and calendar (not Teams, not advanced compliance features)." The action: downgrade to Microsoft 365 E1 or E3 and save the difference.

Example:

A global IT team runs a rule set on Microsoft 365 to find all users with last login greater than 120 days. The query returns 40 users. Upon review, the team identifies the following: 30 inactive employees who should be deactivated and re-harvested, 5 employees currently on parental or medical leave who require a temporary hold rather than deactivation, 3 executives who use Microsoft 365 lightly but whose roles justify full access and should be noted in an exception log, and 2 accounts tied to system processes.

The result:

30 licenses freed for reuse, and a decision trail for the exceptions.

Challenge:

With tools like Microsoft 365, rule sets can get complex. Microsoft 365 has dozens of license tiers and bundle combinations. A Technical Project Manager might need M365 E5, Project P5, and Visio Pro. Determining "right-size" requires knowing the role, the tool, and the feature set. A professional SaaS management platform automates this analysis; manual review is slow and error-prone.

Key insights:

    • Inactive accounts are the easiest bucket to fix: set a threshold, run the rule, deactivate.
    • Unknown accounts are the second easiest: match SaaS users to HR roster, deactivate mismatches.
    • Right-sizing is the most complex and requires domain knowledge of your licensing tiers.
    • Rule sets scale: one rule can recover thousands in licenses across your organization.

Apply same rules to all users or tailor by role?

Tailor rules by role, department, and geography. A salesperson in Chicago has different SaaS needs than a financial analyst in Paris, and both have different needs than a data scientist in the US. This is called "user scoping."

Why this matters: One-size-fits-all rules will either miss waste or break workflows. A financial person who doesn't touch SAP for three months is still a critical user who needs immediate access when month-end close starts. A salesperson with 60 days of inactivity is more likely to be disengaged or between deals. Geography matters too: A user in France must comply with GDPR and may have different SaaS options than a user in the US. Regional data residency requirements, local vendor relationships, and localized contracts all affect which tools are available and appropriate.

Example:

Your organization gives all admin assistants a Salesforce Standard license, but the Executive Assistant to the VP of Sales needs a Salesforce Professional license to create opportunities and manage company records on behalf of the VP. If you apply the same rule to all admins, you'll downgrade the wrong license and break the role.

Example (geography):

Employees in your German headquarters use Microsoft OneDrive. Employees in your US office prefer Dropbox because it integrates with some of their vendor tools. Your marketing team spans both countries and needs both licenses to collaborate. A global rule ("everyone uses OneDrive") would break the marketing team's workflow; a scoped rule ("Germany: OneDrive, US: Dropbox, Marketing: both") respects local needs.

Best practice:

Start with broad rule sets (global inactive threshold, duplicate detection), then apply scoped rules for specific roles or regions that need different logic.

Key points:

    • Role scoping is the biggest opportunity to reduce false positives (deactivating licenses you shouldn't).
    • Geography scoping is often required by compliance (GDPR, local data residency).
    • Department scoping helps because different departments use different tools and have different activity patterns.
    • Scoped rules require knowledge of your organization, so involve department heads in rule design.

Should I ask users before disabling SaaS access?

Yes. When in doubt, ask a department head or the employee directly. People are more likely to accept a decision if they're involved in the process and they understand the rationale.

Why this matters: Surprising an employee by disabling their access creates friction and frustration. If a license is essential to their role, the sudden loss of access can block their work for hours. But if you explain the deactivation process in advance and provide a way to appeal or request reinstatement, people feel heard and the change feels fair.

How to communicate:

    • Notifications: Tie license deactivation to automated email workflows. Warn users 30 days before an inactive license is disabled. Give them a way to request reinstatement.
    • Department coordination: Contact the employee's manager or department head before deactivation. They may know something you don't (leave of absence, maternity leave, sabbatical).
    • Approval workflows: If a license is mission-critical to a role, require human approval before deactivation, even if the user is inactive.

Example:

Your rule set identifies an analyst who hasn't logged into Salesforce in 120 days. Before deactivating, you email the employee and their manager: "We're about to free this Salesforce seat to reduce costs. If you still need it, reply within 5 days." The manager replies that the analyst is on medical leave for another month and will need the license when they return. You add them to the exception list. When they return, the license is re-activated.

Example:

A contractor's project ends and their Jira license is deactivated on their last day. Before the deactivation, you notify them: "Your access will be removed on [date]. If you need to download your work, let us know by [date - 3 days]." They have time to extract their data.

Best practice:

Automation handles the rule logic; humans handle the exception and the communication.

Key points:

    • Notifications reduce surprise and friction.
    • Department heads often know when someone is temporarily unavailable (leave, sabbatical, medical leave).
    • Appeal processes build trust and catch mistakes.
    • Tie deactivation to HR workflows so it doesn't happen by accident during leave.

What's a practical monthly checklist for SaaS optimization?

Here's the checklist we recommend for the three most common SaaS platforms: Microsoft 365, Adobe Creative Cloud, and Salesforce. Run this at the end of each month to keep waste from accumulating.

Data extraction and validation 

    • Extract users: Export all users from Microsoft 365, Adobe Creative Cloud, and Salesforce using Graph API, CSV, or your preferred method. Note the export date.
    • Check domains: Review email domains assigned to accounts. Flag any non-company domains (e.g., @gmail.com, @temporary-vendor.com) and validate whether they should have a license.
    • Cross-check against Active Directory: Compare all SaaS users to your Active Directory or LDAP. Flag users not in AD (likely left the company or are contractors without a formal record).

License optimization

    • Consolidate standalone Adobe licenses: Any user with more than three standalone Creative Cloud products should be converted to Creative Cloud All Apps. It's cheaper and gives them access to everything.
    • Check for double allocations: Flag any user assigned multiple licenses of the same type (e.g., Microsoft 365 E1 and E3 for the same person, or Project P1 and P2). This is always a duplicate.
    • Remove redundant standalones: After consolidation, remove standalone products that are now included in bundles.

Deactivation and right-sizing 

    • Deactivate inactive accounts: Cross-check the user extract against Active Directory. Any user marked as "disabled" in AD should be deactivated in SaaS. Any user with no login activity in 120+ days should be reviewed for deactivation.
    • Right-size to the cheapest plan: Identify users with multiple licenses or higher tiers than they need. Move them to the cheapest plan that covers their role.
    • Check for duplicate bundles: For each user, ensure they don't have overlapping bundle subscriptions (e.g., both Microsoft 365 E3 and E5 in different systems).

Close and documentation

    • Archive the user extract: Save the final list as a record of active users and monthly spend per product. Use this as your baseline for next month's comparison and to track trends.

Tools matter here: manual execution of this checklist is error-prone and slow. A platform designed for SaaS management automates all 10 steps and flags exceptions for human review.

Key insights:

    • Extraction and validation catches unknowns (contractors, test accounts, departmental soft licenses).
    • Consolidation and right-sizing are the biggest immediate cost-reductions.
    • Deactivation closes the loop and prevents waste from accumulating month to month.
    • Archive every month so you can measure progress and spot trends (e.g., user count growth vs. license cost growth).

Frequently Asked Questions

How much SaaS spend is typically wasted?

According to Gartner [2020], 30% of the $102 billion spent on SaaS went unused. That's approximately $30 billion annually in waste across enterprises globally. For a mid-market organization spending $2 million per year on SaaS, that's roughly $600,000 in potential waste annually. The exact percentage varies by organization and how tightly licenses are managed, but the 30% baseline is widely cited. 

What's the difference between shadow IT and an unauthorized duplicate?

Shadow IT is SaaS that an employee procures and pays for without IT approval (e.g., a marketer paying for Dropbox from their corporate card). An unauthorized duplicate is when an employee or department buys a license for a tool your company already provides (e.g., a second Salesforce license without IT's knowledge). Shadow IT is new risk; duplicates are redundancy within existing approved software. Both are waste, but they require different fixes: shadow IT needs discovery and standardization; duplicates need consolidation.

How do I start measuring SaaS account activity if I don't have monitoring in place today?

Start with your SSO and Active Directory logs if you have them—these are usually free and already available. If you don't use SSO, pull browser logs or DNS records from your network firewall. For each platform (Microsoft 365, Salesforce, Adobe), export your user list and check the "last login" date in their admin portals. Once you have baseline activity data, set a threshold (e.g., 90 days of inactivity) and run a manual audit. Document the results so you can repeat monthly or quarterly.  

When should I use automation vs. manual review for disabling access?

 Automate the low-risk cases: deactivating accounts for employees who have left the company (match SaaS users to Active Directory) and flagging inactive accounts for review. Keep humans in the loop for role-based exceptions (financial staff who use tools seasonally), employees on leave, and high-value users (executives, key contributors). Rule of thumb: if the decision is straightforward (user is in AD as "disabled" → deactivate the license), automate it. If the decision involves judgment (is 120 days of inactivity normal for this role?), require human review. 

Get in touch with an expert

Do you have questions about our offering? A quick call can be way more helpful than a long email chain. Talk to one of our experts to explore our products and see them in action.

Brian Riley

Brian Riley

Sales Development

IT Service Management

Send us a message

No matter if you like to partner with USU or just have a few questions.