1. Homepage
  2. Resources
  3. Blog
  4. Why SaaS visibility is still your biggest blind spot (and how to fix it)

TL;DR: The future of SaaS management

The problem: SaaS spend is growing by 15-20% annually1 – but many organizations lack real-time visibility into actual usage of browser-based software.

Key insights: 
  • Traditional IT controls don’t work for web-based applications 
  • AI integration is exploding costs and creating new compliance risks 
  • Multi-layered discovery beats single-source visibility every time 

Next step: Audit your current SaaS discovery methods against modern requirements. 

Remember when IT could control software by simply requiring admin rights for installations? Those days are gone. 

Today’s reality is messier. Your employees can open a web browser, sign up for a SaaS tool of their choice, and start working. Meanwhile, you’re left wondering what they’re actually using, how much it’s costing, and whether you’re compliant. 

The control paradox 

Here’s the catch-22 every IT leader faces: you’re liable for everything employees do on company devices, but you have almost no oversight when it comes to cloud-based tools. 

Sure, you can block specific URLs at the firewall level. But that’s time-consuming, complex, and feels restrictive to users who need flexibility to do their jobs effectively. 

The boundaries between personal and professional use make this even trickier. When someone uses ChatGPT during lunch break, is that personal or business use? What about Netflix after hours on a company laptop?

Most organizations handle this by ignoring non-business applications entirely. Smart policy, but it doesn’t solve the core visibility problem. 

Why single-source discovery fails

Most SaaS management approaches rely on one discovery method. SSO logs. Expense reports. Firewall data. Each gives you a piece of the puzzle, but never the complete picture. 

Here’s what you miss with single-source discovery:

  • SSO-only approach 
    Shows provisioned access, not actual usage. Misses shadow IT completely. 
  • Firewall-only approach 
    Tells you someone used ChatGPT but not whether they have premium features or which specific AI tools they’re accessing. 
  • Expense-only approach 
    Catches subscriptions after they’re already paid for. No usage data to optimize renewals. 

The winning approach combines multiple discovery layers: endpoint agents, SSO integrations, and API connectors working together. 

Practical solution: holistic SaaS discovery

Modern discovery needs to be dynamic and comprehensive. At Xensam, our approach combines: 

  • Endpoint discovery as the foundation 
    Capturing actual usage behavior, not just access permissions. 
  • SSO integration for the complete provisioning picture 
    Who has access to what, and how they’re getting it. 
  • API-based license data for entitlement mapping 
    Connecting usage to actual subscription costs. 

This matters more than ever because AI is getting embedded everywhere. You need to distinguish between someone using basic Word functionality versus Word with Copilot. Between Teams for chat versus Teams with AI-powered meeting summaries.

Our dynamic inventory system updates automatically to track these evolving scenarios without deploying new agents.

The AI cost explosion nobody’s talking about 

Here’s what’s coming: AI features that seem like $5 add-ons today will become $50 or $500 premium tiers tomorrow. 

Take Adobe Firefly. With an enterprise agreement, you get indemnification — legal protection if AI-generated content triggers copyright claims. But only if you use allocated “generative credits.” Run out of credits and create content anyway? You lose that protection. 

Tracking who used which AI features, when, and whether they had proper licensing becomes critical for both cost and compliance. 

The companies preparing for this now will avoid massive budget surprises later. 

Your next step: audit your discovery methods

SaaS sprawl is an increasingly common problem for organizations, with an annual increase of 15-20% in SaaS spend resulting in an average of over 125 different SaaS applications totaling $1,040 per employee annually.2

IT typically is aware of only a third of those due to decentralized ownership and sourcing. This is a saving and efficiency that is waiting to be made in most organizations, once they gain real visibility. But only if they can trust their data.

Ask yourself: 

  • Can you see actual usage, not just access permissions? 
  • Do you know which users are consuming AI features within existing tools? 
  • Can you map usage to subscription costs for renewal negotiations? 

If you’re working with legacy SAM tools that only handle installed applications, you don’t need to replace everything. SaaS management platforms can run alongside existing solutions, filling the web-based application gap. 

Want to see how AI-powered discovery can automate this process? Our SaaS management experts are available to give you a maturity assessment that shows exactly where your visibility gaps are. 

Talk to sales

  1. https://www.gartner.com/ ↩︎
  2. https://www.gartner.com/ ↩︎

Category

Tags