How to Get Your Business's SaaS Subscriptions Under Control
The average mid-market organization now runs 164 SaaS applications. That number jumped 41% in a single year, according to BetterCloud's 2026 State of SaaS report. And 44% of those apps are running without IT's knowledge or approval.
Most businesses with 40 to 150 employees did not set out to build a 164-app stack. It grew on department credit cards, on trial accounts that became annual contracts, on tools someone bought for a project three years ago that nobody canceled. The stack expanded faster than anyone tracked it.
That creates three real problems: wasted spend, security exposure, and compliance gaps. This post covers how to get ahead of all three.
The Scale of the Problem Is Probably Bigger Than You Think
Zylo's 2026 SaaS Management Index puts the average organization's license utilization at 54%. Organizations waste roughly $19.8M annually on unused licenses. That number is calculated from large enterprise data, but the underlying dynamic holds at any size. A 60-person firm paying for 75 Zoom licenses when 40 people use it regularly, a project management tool with 45 seats when the team standardized on something else six months ago, a design app that one person bought and nobody uses anymore. These line items add up quietly.
The same index found that organizations average 211 SaaS renewals per year. That is more than four per week. Most of them auto-renew. Payhawk's data shows 89% of SaaS contracts include auto-renewal clauses. Miss the cancellation window and you are locked in for another year.
For a growing business in Hoboken or Parsippany without a dedicated IT procurement function, that renewal calendar is invisible until the invoice arrives.
Cost Is Only Part of It
Wasted spend is the easiest thing to point at. But the access management problem is the one that keeps IT partners up at night.
BetterCloud's 2026 data found that 18% of organizations experienced a data breach caused by a former employee who still had access to company tools after departure. Not a sophisticated attack. Just an account that never got closed.
Think about how that happens at a 50-person business. Someone in sales uses four tools: Salesforce, Gong, a LinkedIn automation platform, and a proposal tool. They leave. IT disables their Microsoft 365 account. The other four apps? Each one requires a separate login to an admin panel to remove access. If nobody owns that checklist, the accounts sit open.
Multiply that across 164 apps. You have 44% of them that IT did not approve and may not even know about. When that employee leaves, the unsanctioned apps definitely do not get closed.
BetterCloud also found that 18% of organizations experienced data leaks originating directly from AI tools and chatbots. Employees are feeding documents, customer data, and financial information into tools that were never reviewed by legal or IT. The tools are free, so they slid under procurement. But the data went somewhere.
What a SaaS Audit Actually Covers
A SaaS audit sounds more formal than it needs to be. At its core it answers four questions for every tool in the stack:
Who owns it? Not which team uses it. A named person who is responsible for the renewal decision.
Is it actually being used? License counts versus active users. An app with 30 seats and 8 monthly active users has a clear answer.
When does it renew, and when is the real decision deadline? The renewal date is not the deadline. A 90-day notice clause on a March 1 renewal means the decision needs to happen by December. And December is exactly when nobody is reviewing vendor contracts.
What data does it touch? Any tool that handles customer data, financial records, or employee information needs a basic security and compliance review before it ends up on the approved list.
The discovery process is the tedious part. Run a full pass across corporate credit card statements, expense reports, and AP records. Then cross-reference against SSO logs if you use one. The mismatch between what finance knows about and what SSO shows is usually where the shadow IT lives.
Flexera's 2026 State of ITAM report found that only 36% of organizations have complete visibility into their IT estate. The other 64% are guessing.
Getting Ahead of Renewals
The goal is never to cancel subscriptions reactively. By the time you realize you do not want to renew something, the window is often already closed.
A few things that actually move the needle:
Build the renewal calendar backward from the notice deadline, not the contract date. For each tool, calculate: renewal date minus cancellation notice period minus however long your internal review actually takes. That is the date someone needs to make a decision. Put it in a calendar with a named owner.
Review usage 90 days before each renewal. Pull the active user count, compare to licensed seats, and ask the tool owner whether the business still needs it at current scale. This is where most of the quick savings come from. Not canceling tools you hate, but rightsizing tools you like.
Tag every new app acquisition with an owner on day one. When that person leaves the company, their SaaS tools should be on the offboarding checklist. This is the single most effective way to close the departed-employee access gap.
Standardize the approval process for new tools. It does not need to be a six-week procurement cycle for a $30/month app. But someone should check whether the business already has a tool that does the same thing before approving.
Who Should Own This
This is where it gets real for most growing businesses. Who has time to manage a 164-app stack?
The answer most businesses land on: nobody, which is why the stack got to 164 apps with 44% of it invisible to IT.
The businesses that actually get control either dedicate internal resources to it (rare below 200 employees) or bring in an IT partner who does it as part of ongoing account management. The value is not running the audit once. It is maintaining the ownership list, catching the renewals before they auto-fire, and closing the access loop when someone leaves.
A managed IT relationship provides the continuous layer. Monthly active user checks, renewal calendar management, offboarding checklists that cover every tool. It is not glamorous work. But 18% of organizations finding out they had a breach from a former employee's still-active account is a very unglamorous outcome.
FAQ
What is SaaS sprawl and why does it happen? SaaS sprawl is the unmanaged growth of software subscriptions across a business without central oversight. It happens because SaaS tools are easy to buy on a company card, trial-to-paid conversions are automatic, and individual teams make tool decisions without coordinating with IT or finance. Most growing businesses do not realize how large their stack is until they run a full audit.
How many SaaS apps does the average business use? According to BetterCloud's 2026 State of SaaS report, mid-market organizations now average 164 SaaS applications, up 41% year over year. A meaningful portion of those apps operate outside IT's oversight.
What is shadow IT in the context of SaaS? Shadow IT refers to software tools that employees use for work without formal IT approval or oversight. In the SaaS context, this typically means apps purchased on department credit cards or personal accounts, often without security review, data handling agreements, or access management. BetterCloud's 2026 data found that 44% of apps in use at mid-market organizations are outside IT's approval.
How do you reduce SaaS costs without cutting tools people actually need? The most effective approach is rightsizing before canceling. Review license counts against actual usage for each tool and reduce seats to match real headcount. Zylo's data suggests organizations use only 54% of their licensed seats, which means significant cost reduction is available without eliminating anything. The second lever is consolidation: where multiple tools serve overlapping purposes, standardizing on one and exiting the others.
How often should a business audit its SaaS subscriptions? A full audit at least annually, with quarterly reviews of the renewal calendar and active user counts for higher-spend tools. The auto-renewal problem makes quarterly cadence important: contracts with 90-day notice periods need to be on the radar well before the renewal date.
Managing a growing SaaS stack is one of those problems that compounds quietly until it bites. If you want a structured review of what your business is running, what it is costing, and where the access gaps are, get in touch.