Direct Answer
Audit your SaaS stack at year end in six steps: build one inventory from accounting exports, your identity provider, and a team survey; measure real usage through last-login and SSO logs; give every tool a verdict of cut, downgrade, consolidate, or keep; check for orphaned accounts, missing MFA, and stale OAuth grants; renegotiate renewals using active seat counts; then assign one owner per tool. Time it to your budget cycle so notice periods do not expire unnoticed. Tying license changes to automated on- and offboarding, as deeploi does through your HR system, keeps the stack clean between audits.
Key Takeaways
Start from your identity provider and accounting data, not memory; shadow IT only surfaces when you cross-reference at least three sources.
Every tool in your inventory needs a verdict (cut, downgrade, consolidate, keep) and a single named owner before renewal season hits.
Tie license provisioning and deactivation to your onboarding and offboarding process so the audit you run today does not need repeating from scratch next year.
Check notice periods now; a 90-day window you miss costs more than the entire audit.
Summary
Year end is the single best window to audit your SaaS stack. Renewal clusters in December and January, budget planning for the coming fiscal year, and auto-renewal clauses that quietly lock you in for another 12 months all converge in the same few weeks. This guide walks you through six steps: building a complete inventory, measuring real usage, deciding what to cut or keep, running the security half of the audit, negotiating renewals, and assigning ownership so your stack stays clean. The payoff is lower costs, fewer orphaned accounts, and a software portfolio you can actually defend in the next budget meeting.
Why year end is the right time to audit your SaaS stack
A large share of SaaS contracts are signed at the start of the calendar or fiscal year, which puts their renewal, and therefore their notice period, in the final weeks of the year. Miss a 90-day cancellation window in October and you are locked in (and paying) for another full year. Budget planning amplifies the pressure: finance wants a clean software line item for next year, and you cannot give them one if nobody knows what you are actually running.
Auto-renewals make this worse. Vendors design them to trigger silently, often with a built-in price escalation. If you treat renewal dates as someone else's problem, your IT cost reduction efforts start behind before the new year even begins.
What you need before you start
You do not need a dedicated SaaS management platform to run this audit. You need three data sources and a simple spreadsheet.
Accounting or credit card exports: Pull 12 months of transactions and filter for recurring charges. This catches tools paid monthly, quarterly, and annually.
Your identity provider: Export the app catalog from Entra ID, Google Workspace, or whichever IdP you use. This reveals centrally provisioned tools but misses anything purchased outside IT.
A short team survey: Ask each department lead: "What software does your team use daily or weekly that IT did not set up?" Shadow IT surfaces here, not in your accounting data.
You will also need admin access to the consoles of your major tools so you can pull seat counts and login data in the steps that follow.
Step 1: Build a complete SaaS inventory
Merge the results from all three sources into one list. Duplicates will appear immediately: the same tool showing up on a credit card statement and in your IdP under a slightly different name. Shadow subscriptions will surface too, often tools a team signed up for on a free trial that quietly converted to a paid plan.
For each tool on the list, capture five data points:
Owner: The person or team responsible for the tool.
Annual cost: Convert monthly charges to annual totals so you can compare apples to apples.
Seats paid vs. seats active: How many licenses you are billed for versus how many people actually log in.
Renewal date and notice period: The exact day the contract renews and how far in advance you must notify the vendor to cancel or change terms.
Admin access holders: Who can modify settings, add users, or export data.
One source most audits forget is the devices themselves. Your accounting export tells you what you pay for and your IdP tells you what you provisioned, but neither tells you what actually landed on a laptop. In deeploi, every device page has a Software tab listing the apps from that device's bundle and whether each one is installed, with the date it landed. You can search for a single app instead of scrolling, and re-trigger the bundle installation on that device if something did not apply. Cross-checking that against your billing list is how you find the license you renewed for a tool nobody ever got. This inventory is the foundation for every step that follows.
Step 2: Measure actual usage per tool
Cost data tells you what you pay. Usage data tells you what you actually use. You need both before making any decisions.
Start with the easiest signals:
Last-login timestamps: Most admin consoles show when each user last signed in. Accounts with no activity in 60 or more days are strong candidates for removal.
SSO sign-in logs: If a tool is connected to your IdP, pull authentication logs to see frequency, not just recency.
Admin console reports: Some tools (particularly project management and CRM platforms) offer built-in usage dashboards showing feature adoption, not just logins.
What about tools with no usage reporting? This happens more often than you'd expect. In that case, fall back on proxy signals. Check whether files or records were created recently, or run a quick five-question survey asking the team: "When did you last use this tool, and for what?" If nobody can answer confidently, you have your signal. Keeping solid IT documentation makes this kind of check faster every cycle.
Step 3: Apply the cut, downgrade, consolidate, or keep framework
With inventory and usage data in hand, score every tool against four options:
Cut: No meaningful usage, no unique function. Cancel before the next renewal.
Downgrade: The tool is used, but most users only touch basic features. Move to a lower tier.
Consolidate: Two or three tools serve the same purpose (project management, e-signatures, file storage). Pick one and migrate. Standardizing the toolset per team, rather than per person, is what stops the overlap from growing back – this is how role-based software bundles work.
Keep: Actively used, properly tiered, no overlap. Renew, but still negotiate.
Overlap detection is the highest-value move here. It is common for marketing to run one project management tool, engineering another, and operations a third. Three subscriptions, three admin burdens, three sets of data that never connect. The same pattern appears with e-signature tools, analytics platforms, and note-taking apps.
This step is a decision step, not an analysis step. Every line in your inventory should end with a clear verdict and the name of the person responsible for executing it.
Step 4: Run the security side of the audit
Cost savings get the headlines, but the security findings from a SaaS audit are often more urgent. Three things to hunt for:
Orphaned accounts from former employees. When someone leaves and their accounts are not deactivated, those credentials remain live entry points into your systems. Roughly 91% of ex-employees retain access to at least one company file or application after they leave, and 31% of companies have had a former employee actually reach assets stored in a SaaS application after their departure (Security Magazine). This is not a theoretical risk; it is a measured one.
Tools without SSO or MFA. Any application that sits outside your identity provider and lacks multi-factor authentication is a weak link. If the tool holds customer data, internal documents, or financial records, that weak link is a liability. A team password manager paired with enforced MFA closes this gap for tools that do not support SSO natively.
Unapproved OAuth app grants. Employees routinely authorize third-party apps (especially AI tools) to access their Google Workspace or Microsoft 365 account. These grants persist long after the employee forgets about them. SaaS security is now a high priority for 86% of organizations, with 76% increasing budgets for threat detection and SaaS security posture management (Cloud Security Alliance).
Offboarding gaps almost always surface here rather than in the cost review. Tying license deactivation to your offboarding workflow closes the loop: when HR marks someone as leaving, their accounts and access are revoked on schedule, not weeks later when someone remembers. deeploi, the All-in-One IT Management Platform, connects directly to Personio, HiBob, BambooHR or other HR tools, so a leaving date schedules the entire exit. Workspace access is suspended automatically on the day you choose, and the employee's SaaS accounts and the licenses behind them are deactivated in the same flow. Configuring one exit takes two to five minutes instead of the two to three hours it takes to work through every tool by hand, which is why orphaned accounts stop appearing in your audit in the first place.
Step 5: Negotiate renewals and cancel properly
Armed with real seat counts and usage data, you are in a much stronger position at the negotiation table. Here is how to use that advantage:
Lead with active seat counts. If you pay for 50 seats but only 30 are active, your renewal quote should reflect 30 (plus a small buffer for growth). Vendors rarely volunteer this adjustment.
Request data exports before cancellation. Once you cancel, some vendors restrict access to historical data immediately. Export everything you might need before you hit the cancel button.
Watch notice-period traps. A 90-day notice window on an annual contract means you must act three months before renewal, not three weeks. Put calendar reminders at 120 days out for every contract.
Negotiate at quarter end. Sales teams facing quota pressure in March, June, September, and December are more flexible on pricing and terms.
If you have already missed a notice period, you are not powerless. Contact the vendor and negotiate a shorter renewal term or a reduced seat count for the interim year. Many will agree, especially if you frame it as a retention conversation rather than a complaint.
Step 6: Assign ownership so the stack stays clean
An audit only delivers lasting value if you prevent the stack from drifting back to its pre-audit state. Three things make that happen:
One owner per tool. Every application should have a named person who justifies continued spend and manages the license count. If nobody claims ownership, that tool is a strong candidate for removal.
A lightweight request and approval path. Before anyone adds a new subscription, they check whether an existing tool already covers the use case. This single step prevents the overlap problem from recurring.
License changes tied to onboarding and offboarding. When a new hire joins, they receive exactly the app bundle their role requires. When someone leaves, those accounts and licenses are closed out as part of the exit. deeploi handles this by syncing with your HRIS: a new employee record triggers provisioning from the role bundle you defined once, and a leaving date schedules the deactivation, so your license count stays accurate without anyone chasing it tool by tool.
Without ongoing governance, SaaS sprawl returns within months. A quarterly check on seat counts and new subscriptions, layered on top of the full annual audit, keeps the problem manageable. Building strong cybersecurity practices and IT security foundations into this rhythm means you catch both cost and risk issues before they compound.
Troubleshooting common issues
Tool with no admin console or usage data. Fall back on SSO sign-in logs. If the tool is not connected to your IdP, run a quick team poll asking when each person last used it and for what purpose. If nobody can recall, treat that as evidence of non-use.
Vendor refuses to share seat usage. Escalate to your account manager or check the billing portal directly. Most billing dashboards show at least login counts or active user numbers, even if the main admin console does not surface them.
Missed a notice period. Contact the vendor immediately. Negotiate a shorter renewal term (six months instead of twelve) or a reduced seat count for the interim period. Frame the conversation around future retention: vendors would rather adjust terms than lose you entirely at the next window.
FAQ
How often should we audit our SaaS stack?
Run a full audit once a year, ideally timed to your budget cycle so findings translate directly into next year's plan. Layer a lighter quarterly check on top: review seat counts, flag new subscriptions that appeared since the last check, and verify that offboarding actually deactivated accounts as expected.
What if we have no SSO or identity provider?
Use credit card and invoice exports as your primary source and supplement with a team-by-team survey. The gap itself is a finding: without centralized identity management, you cannot reliably track who has access to what. Treat the audit as motivation to adopt an IdP, which will make every future audit faster and more accurate.
How much can a year-end SaaS audit realistically save?
Savings depend on how long it has been since your last review, so treat any single benchmark with caution. Structured license management alone typically cuts software spending by up to 30%, and most of that comes from three places: licenses nobody uses, tiers that are higher than the work requires, and two tools doing one job. Cutting unused subscriptions is usually the fastest win. Downgrades, consolidation, and renegotiated renewals then compound on top of it.
Who should own the SaaS audit process?
The best results come from a small cross-functional group: someone from IT or operations who understands the tools, someone from finance who sees the spend, and a department lead who knows what teams actually use day to day. In smaller companies where one person wears all three hats, that person is the natural owner.
.png)









