GlossarySecurity awareness

SaaS management

Short answer

SaaS management is the practice of discovering, controlling and reviewing the cloud applications employees use, including who has access to each one and what data they hold. It reduces shadow IT and makes sure access is removed when people leave.

The problem it solves

Teams sign up for SaaS tools with a work email and a card, often without IT knowing. Over time the company ends up with dozens or hundreds of applications holding company data, with accounts that stay active after people leave and permissions nobody reviews. This is often called shadow IT.

What SaaS management covers

Discovering which applications are in use, who has access to each one, what data and permissions they hold, and whether they are approved. It also covers removing access during offboarding and reviewing access periodically.

SaaS management vs SSPM

SaaS management focuses on inventory, access and usage. SSPM (SaaS Security Posture Management) focuses on the security configuration of each application, such as sharing settings and MFA enforcement.

Where it shows up in compliance

It supports asset inventory, access review and supplier controls in ISO 27001 and SOC 2, and gives evidence that former employees no longer have access.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub