< BACK

The App Nobody Remembers Approving

SaaS sprawl Emerge Managed IT Services Greater Cincinnati NKY

Key Takeaways

  • Mid-market companies typically run well over a hundred SaaS applications—creating potential for SaaS sprawl—and that number is climbing again after a couple of years of deliberate consolidation.
  • AI-powered tools are the biggest driver of the renewed growth, with mid-market organizations seeing the sharpest jump of any company size segment in the past year.
  • A meaningful share of licenses across the industry go unused or significantly underutilized, which is a direct, recoverable cost.
  • Sprawl is a security question as much as a budget one. Every app nobody’s reviewing is a login nobody’s auditing.
  • A periodic SaaS audit, not a one-time cleanup, is what keeps the sprawl from quietly rebuilding itself.

How it Happens, One Good Decision at a Time

Nobody sets out to create SaaS sprawl. It happens through a long series of individually reasonable choices. Marketing needs a design tool, so someone signs up for a free trial that becomes a paid plan nobody revisits. Sales prefers a different CRM interface than the one IT standardized on, so a second one quietly takes root. A department discovers a slicker project management app and migrates over without telling anyone. Each decision made sense in isolation. A year or two later, the company is running well over a hundred applications, and no single person could name all of them.

The Number is Bigger than Most Leaders Assume

This isn’t a fringe issue. BetterCloud’s 2026 State of SaaS survey of 525 IT and security professionals found that after a couple of years of companies deliberately consolidating their SaaS footprint, the average application count is climbing again, up meaningfully year over year. The reason is almost entirely AI. Organizations now run an average of 27 AI-powered applications on top of everything else, and mid-market companies saw the fastest growth of any segment, with the average count jumping sharply in a single year.

Every new AI tool that gets adopted, often by an individual employee rather than through a formal purchase, adds to a portfolio that was already hard to track before AI tools entered the picture.

The Cost Hiding in Plain Sight

Sprawl shows up on the budget line first. Unused and underutilized licenses are common across the industry, and they represent pure waste: a subscription renewing automatically for a tool three people used once and forgot about. For a mid-market company juggling dozens of SaaS contracts with different renewal dates, different payment terms, and different point-of-contact turnover, catching these before the annual renewal fires is more of an accounting exercise than anyone has time for.

Security costs are less visible and arguably more serious. Every application in that sprawling portfolio represents a login, a data-sharing agreement, and a permissions structure that somebody must keep current. When IT doesn’t know an app exists, nobody reviews who still has access to it, whether it’s connected to other systems via an integration, or whether its security posture has changed since it was first approved. A departing employee’s access to the well-known systems gets revoked as a matter of routine. Their access to the app three people signed up for during a product launch two years ago rarely crosses anyone’s mind.

Why This Keeps Happening Even After a Cleanup

Companies that do run a SaaS audit often treat it as a one-time project: inventory everything, cut what’s unused, feel good about the savings, move on. The sprawl comes back anyway, because the underlying behavior that created it—individual teams solving their own problems with the fastest available tool—never went away. A cleanup without an ongoing process is a diet without a maintenance plan.

What Actually Keeps SaaS Sprawl Under Control

Companies that keep their SaaS footprint steady tend to treat it as a recurring discipline rather than a project. That means a regular review, not annual, closer to quarterly, of what’s actually being used versus what’s simply renewing. It means a lightweight approval step for new SaaS purchases that’s fast enough that teams don’t feel compelled to route around it, similar to the balance that works for shadow AI. And it means centralizing visibility into one place, since spreadsheet tracking reliably falls behind the pace at which new tools get adopted.

This is unglamorous, recurring work, exactly the kind that’s easy to deprioritize when a small IT team is fighting fires. It’s also where a co-managed partner adds clean, measurable value: ongoing visibility into the SaaS portfolio, regular reviews that happen on schedule, and a security posture that doesn’t quietly erode one forgotten app at a time.

Scroll to Top