Why SaaS sprawl feels invisible until it’s expensive
The “we can’t answer three simple questions” problem
Most NYC SMBs don’t lose control of SaaS because they’re careless—they lose it because purchasing is decentralized, teams move fast, and no one owns the monthly reconciliation. The result is predictable: duplicate tools, orphaned accounts, surprise renewals, and a growing gap between what Finance pays for and what IT can see.
What a “monthly close” does that audits don’t
A SaaS close is not a once-a-year audit or a panic before renewal. It’s a short, repeatable operating rhythm that produces the same three artifacts every month: an app inventory, a license reconciliation, and an owner map.
What you can do with what you already have
The minimum viable toolset for a 20–200 seat company
You don’t need a SaaS-management platform to get meaningful control. For most Microsoft-centric SMBs, you can start with:
- Microsoft Entra ID (Azure AD): enterprise apps list, SSO assignments where available, sign-in logs.
- Your finance system export: credit card + AP bills, vendor name, amount, renewal cadence (if known).
- HR roster: current employees, start/end dates, department, manager.
- A shared spreadsheet or lightweight tracker: one file that becomes the “system of record” for this process.
The “close” mindset: treat SaaS like a controllable operating expense
The goal isn’t to block tools or shame teams for experimenting. The goal is to make app usage, ownership, and licensing visible enough that your business can intentionally decide what to keep, consolidate, and secure.
The 90‑minute operating rhythm (calendar + roles)
A simple monthly cadence that fits real SMB schedules
Pick a consistent time—many teams do it during the first week of the month. Keep it short and repeatable.
- Day 1 (Prep, 20 minutes, async): Finance exports SaaS transactions; IT exports Entra “enterprise apps” list and notable sign-ins.
- Day 2 (Close meeting, 60 minutes): Review deltas, license drift, new apps, ownership, and next actions.
- Day 3 (Follow-through, 10 minutes): Send action log; owners confirm changes.
Who attends (and what they’re responsible for)
This works best with four roles, even if one person wears two hats.
- Facilitator (MSP or internal IT lead): runs the agenda, updates the tracker, assigns actions.
- Finance rep: provides spend export, flags renewals, confirms vendor names and billing accounts.
- HR/People ops rep (or ops manager): confirms joiners/leavers, contractors, department ownership.
- Department app owners (as-needed): joins when their app is being reviewed or newly discovered.
The three recurring artifacts you’ll maintain
The close produces a few documents you can actually use.
- SaaS Inventory Register: app name, vendor, purpose, spend, billing source, owner, risk tier.
- License Reconciliation Sheet: seats paid vs seats assigned vs seats active (usage), drift notes.
- App Owner Map: one accountable owner per app, plus backup owner and escalation path.
Step 1: Build your “Paid Apps” baseline from finance (fast and imperfect is fine)
Start from transactions, not memory
Your first close is about coverage, not perfection. Export 30–45 days of transactions that include:
- vendor/merchant name
- amount
- payment method (card, ACH, invoice)
- memo/category (if available)
Normalize vendor names to avoid hiding duplicates
The same tool may show up as multiple merchant strings (e.g., “ATLASSIAN,” “Atlassian Pty,” “JIRA”). In the register, pick one canonical name and list aliases so you can spot duplicates month-to-month.
Mark what’s “definitely SaaS” vs “maybe SaaS”
You’ll see cloud infrastructure, domains, and professional services mixed in. Tag each line item:
- SaaS (business app)
- Cloud/hosting
- IT services
- Unknown—needs triage
Step 2: Reconcile “license drift” against identity and HR changes
Define license drift in business terms
License drift is the gap between what you’re paying for and what your people actually need—and it usually comes from HR events. Every month, reconcile around:
- Leavers: terminated employees still licensed or still able to sign in
- Role changes: users holding multiple overlapping tools after a team move
- Contractors: accounts that never got an end date
- Auto-upgrades: seats bumped to higher tiers without a deliberate decision
- Pull HR list of joiners/leavers since last close (include contractors).
- For each paid SaaS app, confirm who is assigned (from the admin portal or Entra where SSO is used).
- Compare to HR: remove or suspend leavers within the agreed SLA.
- Identify users with duplicate tools (e.g., two project tools) and assign a decision to the relevant owner.
- Flag inactive seats (no sign-in/usage for a set period) for downgrade/removal.
- Record actions: who changed what, when, and what the new paid seat count should be.
Set thresholds that prevent endless debate
Drift is normal; ignoring it is expensive. Pick pragmatic thresholds so the close yields decisions.
- Leavers: access removed within 24–72 hours (depending on your policy).
- Inactivity: review seats with 60–90 days of no usage (app-dependent).
- Duplicates: if two apps overlap, require an owner decision within 30 days.
Make Entra ID work for you—even if SSO coverage is partial
You may not have SSO for every app (yet). Still, Entra helps you centralize what’s connected and see sign-in activity for what is.
- Use Enterprise Applications to list SSO-connected apps and assignments.
- Use Sign-in logs to see recent activity and spot unknown app integrations.
- Treat non-SSO apps as “visibility gaps” and prioritize them for owner confirmation.
Step 3: Triage newly discovered apps and assign an owner (the part most teams skip)
Find shadow apps without endpoint agents
You can discover a lot using finance + identity signals.
- From Finance: any new vendor line item is a “new app” until proven otherwise.
- From Entra: new enterprise app integrations or spikes in sign-ins to lesser-known apps.
- From departments: recurring reimbursements or card charges tied to a team.
Use a lightweight risk-tiering rubric (so you act consistently)
When a new app appears, tier it quickly to determine how hard you need to lean in.
- Tier 1 (High risk): stores PII, client data, financial data, credentials, or has admin-level integrations.
- Tier 2 (Medium risk): collaboration or productivity tools with internal documents but limited regulated data.
- Tier 3 (Lower risk): niche utilities, design helpers, scheduling add-ons with minimal data.
Assign one accountable app owner (and define what “owner” means)
App ownership isn’t “the person who likes the tool.” It’s a role with responsibilities.
- Business owner (accountable): decides if the app stays, budget owner, approves seat counts.
- Technical owner (responsible): manages access method (SSO/MFA), admin settings, and offboarding.
- Backup owner: ensures continuity when the primary owner leaves.

The 60-minute close agenda (what happens in the meeting)
A tight agenda that produces decisions
Keep the meeting focused on deltas and actions.
- 10 minutes: Review new vendors/new apps since last close; assign owner + risk tier.
- 20 minutes: License drift review for top-spend apps; approve removals/downgrades.
- 15 minutes: Upcoming renewals in the next 60 days; confirm owner and seat plan.
- 10 minutes: Security/SSO gaps for Tier 1–2 apps; decide SSO/MFA requirements.
- 5 minutes: Confirm action log, owners, and due dates.
What “done” looks like each month
You’re done when each item has an owner and a next step.
- New apps: owner assigned + tier set + next review date
- Drift items: specific removals/downgrades queued
- Renewals: seat count decision + budget confirmation
When it’s worth buying a SaaS-management platform (clear stop/go criteria)
A decision tree you can apply after 2–3 closes
Start lightweight, then graduate when the process is working but the manual work becomes the bottleneck.
- Stay manual for now if you have:
- fewer than ~50–70 paid SaaS vendors
- a manageable number of billing sources (one or two cards + AP)
- SSO coverage for the majority of Tier 1 apps
- a close that consistently finishes with actions
- Consider a SaaS spend/management tool if you hit two or more:
- billing is fragmented across many cards/entities and you can’t trace owners reliably
- you have frequent M&A, rapid hiring, or high churn driving constant drift
- you need automated usage data across many vendors to justify seat cuts
- contract terms/renewals are being missed and causing surprise renewals
- security requires continuous discovery beyond finance + SSO signals
What to demand if you do buy
If you graduate to a platform, buy for outcomes, not dashboards.
- accurate vendor normalization and contract/renewal tracking
- usage + last-active signals that map to real users
- workflow: approvals, owner assignment, deprovisioning triggers
- integrations that match your stack (Entra, finance, HR)

Key Takeaways
- A monthly SaaS close turns “SaaS chaos” into a repeatable operating rhythm with owners, actions, and renewal control.
- You can start with Entra ID + finance exports + HR changes—no dedicated platform required.
- License drift is mostly an HR-to-access reconciliation problem; set thresholds so it doesn’t become a debate.
- Risk-tier new apps quickly and assign a single accountable owner to prevent shadow IT from becoming permanent.
- Buy a SaaS-management platform when manual reconciliation becomes the bottleneck—not as a substitute for process.
Frequently Asked Questions
How do we handle apps that don’t support SSO or aren’t connected to Entra ID?
Track them as a visibility gap in your register and require the app owner to provide an admin user list monthly (or quarterly for low-risk tools). For Tier 1 apps, consider making SSO/MFA a requirement to keep the tool.
What if departments resist naming an “owner” because the app is shared?
Treat shared use as the reason you need an owner, not a reason you can’t have one. Assign the owner to the budget holder (or department lead) and allow a technical owner to handle admin tasks.
How do we avoid disrupting teams when reclaiming licenses?
Use a two-step approach: first identify inactive or duplicate seats, then send owners a short confirmation window before removal. Keep a documented rollback plan (reassign seat within 24 hours) for business-critical apps.
How long until we see savings or risk reduction?
Most SMBs see quick wins after the first or second close because leavers and unused seats are easy to spot. The bigger value compounds over time as renewals become intentional and new apps get captured early.
Who should run this—Finance, IT, or an MSP?
It works best when IT/MSP facilitates (because access and risk live there) and Finance anchors spend reality. The app owners drive the business decisions.
Take the Next Step
Want a monthly SaaS close your team can actually maintain?
Your Expert Tech can help you set up the register, define risk tiers and thresholds, and run the first 1–2 closes so your team has a sustainable rhythm—without buying new tooling prematurely.
Consultation CTA
If you’re ready to get clear on what you pay for, who owns it, and where license drift is hiding, request a consultation and we’ll map a 90‑minute close process to your current Entra, finance, and HR setup.

