Somewhere in your Microsoft or Google tenant is an application with read access to a shared mailbox. An employee who left two years ago authorized it, for a tool your finance team canceled at the following renewal. The seat is gone. Billing stopped. The token did not.
That gap between commercial termination and technical termination is the part of SaaS sprawl nobody owns. Finance treats subscriptions as spend. IT treats applications as access. Both read the same list from opposite ends, and the middle is where the interesting problems live.
A useful reframe for 2026: a subscription audit and an access audit are the same exercise performed in different vocabulary. Run either one properly and the other falls out as a byproduct. Most mid-sized companies run neither — the spending version feels like a cost-cutting chore, and the access version has no budget line.
Cancellation Ends the Invoice, Not the Grant
Worth stating plainly, because this is a fact about how modern authorization works rather than an opinion about any vendor: when a user connects a third-party application to your identity provider, the resulting consent grant lives in your directory, not in the vendor's billing system. Ending the subscription removes seats. Doing so does not revoke the grant, expire the refresh token, remove the application registration, or clear the mailbox and file permissions attached to it.
The same holds for the connective tissue that accumulates around any tool that was genuinely useful:
- API keys minted for the departing tool and pasted into systems that are still running
- Inbound webhooks and automation flows that still fire
- Service accounts with delegated mailbox or file rights, exempted from MFA years ago "temporarily"
- DNS records pointing a subdomain at infrastructure the vendor may have since recycled
- SFTP or file-share credentials shared during onboarding and never rotated
Employee offboarding is mature at most mid-sized companies. Application offboarding barely exists. When a person leaves, someone disables an account. When a tool leaves, someone stops paying — and that is the whole ritual. This is not negligence. Nobody was ever assigned the second job.
The Tool You Approved in 2022 Reads More Than It Did
Something changed recently enough that most of your approval decisions predate it. Business software has been adding embedded assistants, summarizers, and "chat with your data" features at speed. No number is needed to make the point, and none should be invented: open five tools your team uses and count the ones that gained an assistant after you bought them.
The consequence is analysis rather than a reported finding, and it is the part executives underestimate. Your original consent decision was made against a product description that no longer applies. A tool approved as a scheduling utility now reads meeting content to produce summaries. File-transfer services index what passes through them. Where the initial grant was broad — read all mail, read all files, read directory data — nobody had to ask you again. Nothing was violated. The product simply grew into permissions you had already given it.
Shadow AI sharpens the picture. Employees are not exfiltrating data maliciously; they paste a contract into whichever assistant renders it readable fastest. Companies that have invested seriously in Microsoft 365 governance and Copilot data controls sometimes find the harder problem sits outside that boundary entirely — in a free-tier tool signed up for with a work identity, which cost nothing and therefore appears in no ledger finance maintains.
The review question has moved. It used to be what does this application do. Now it is what can this application read, what does it do with what it reads, and where does that end up. Those are IT security questions wearing a procurement costume.
Finance Has the Best Software Inventory in the Building, and It Is Blind in One Direction
Card and AP data is the closest thing most 20-to-500 seat businesses have to a real software asset inventory. It is also systematically blind in exactly the wrong direction. Paid tools appear. Free tiers, expired trials whose integration quietly survived, personal-card purchases reimbursed as office expense, and self-serve signups authorized with a corporate Google or Microsoft identity do not. Those last ones frequently hold the broadest permissions, because free products lean hardest on OAuth to reduce signup friction.
So the audit worth running reconciles three ledgers that rarely agree:
- What finance pays for — the spend view, complete on cost, blind on access
- What your identity provider has authorized — the enterprise applications and consent grants, complete on access, silent on cost
- What your network and browsers actually talk to — the behavioral view, which catches what neither of the others knows exists
Findings live in the disagreements. An application in the identity provider with no matching invoice is either a free tool nobody vetted or a canceled tool nobody disconnected. Invoices with no matching sign-in activity are money leaving for nothing. A tool that appears in network traffic and in neither of the other two ledgers is the most instructive finding of the day, and usually the one that ends the "we don't really have a shadow IT problem" conversation.
Machine identities belong in the same reconciliation. Service accounts, API keys, and automation connectors have no leaver's date and no manager, which is precisely why they survive the humans who created them.
Build a Register, Not a Cancellation List
A cancellation list saves money once. A register changes how decisions get made. For each application that survives review, capture the business owner by name, the data classification it touches, whether authentication runs through single sign-on or a local password, how many people hold admin rights, what it can read inside your tenant, the steps required to disconnect it, and how you would get your data out if the vendor disappeared. That last field is where SaaS sprawl meets disaster recovery — a platform holding business records you cannot export is a continuity exposure regardless of the vendor's uptime.
Two operational notes make this stick. Use renewal dates as the governance clock; every renewal is a scheduled, budget-backed excuse to re-examine scope. Then put the disconnect procedure with whoever runs your IT support function, because that group sees a tool's entire lifecycle — the request, the integration, the tickets, the abandonment. If your company has recently completed a cyber insurance renewal questionnaire or a large customer's vendor review, you have likely met a version of these questions already, under time pressure.
Count Owners, Not Logos
Consolidation is the reflexive answer and only sometimes the right one. Collapsing a dozen tools into one platform trades vendor sprawl for concentration risk, which is a different exposure rather than a smaller one. The honest goal is fewer unowned applications — every tool attached to a named person who can say what it reads and how it would be removed.
A company with sixty governed applications is in better shape than one with fifteen where four hold permissions nobody can explain.
Pro Link Systems has supported Los Angeles businesses from Woodland Hills since 1999. The subscription review is the least intimidating door into a serious access conversation, because it opens on the CFO's turf. If you want that reconciliation run properly rather than as a spreadsheet exercise, our managed IT services team can start with what your directory has authorized that your invoices never mentioned.
Ready to talk to a real IT engineer?
Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.