Safeguard
Compliance

Every SaaS Tool Nobody Approved Still Has Access

Someone signed up with a company card, connected it with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed. The integration did not. Adopting a tool costs nothing; removing one requires someone to remember it exists.

Marina Petrov
Compliance Analyst
5 min read

Someone on your team signed up for a SaaS tool with a company credit card eighteen months ago, connected it to your source repository and your customer data platform with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed or the trial expired. The integration did not.

Nobody in security knew it existed, because nobody needed to ask permission to try it. That is the entire problem, in one sentence: adopting a tool costs nothing and requires no approval, while removing one requires someone to remember it exists.

This post is about the tools your company uses that nobody approved and nobody is tracking. For whoever is trying to answer "what do we actually use."

Why the inventory is always wrong

Every method of building one misses something, which is why the honest answer to "how many SaaS tools do we use" is usually a range rather than a number.

Asking people misses whatever they forgot they set up, which is most of it after a year.

Reading expense reports misses free tiers, tools paid for personally and expensed, and anything bought on a shared card nobody reconciles by vendor.

Checking your identity provider's app catalogue misses anything that was never wired to single sign-on, which for a tool adopted casually is most of them, because SSO integration is exactly the step people skip when trying something quickly.

Reviewing OAuth grants into your core platforms catches connected apps specifically, and it is usually the most productive single source, because it is where the actual access lives regardless of who remembers signing up.

None of these alone is complete. Together they produce a list, and the gaps between what each method finds are informative on their own.

What accumulates, specifically

Dormant integrations with live access. A tool nobody uses that still holds an OAuth grant into your repository, your calendar, or your customer data. The subscription ending does not revoke the grant; those are two separate systems that do not talk to each other.

Shadow adoption of overlapping tools. Three teams independently pick three different project trackers, each holding a slice of company information, none reviewed, because nobody knew the others existed to consolidate around one.

Free-tier accounts with real data. A free plan often has the weakest security posture of any tier a vendor offers, since it is not the plan they invest in retention or support for, and it is exactly the plan most likely to hold real customer data from someone testing a tool with production content because that was faster than making up examples.

Personally-owned company accounts. A tool signed up for with a personal email address, used for company work, that leaves with the employee, taking whatever access and data it held with them, with nothing in your offboarding checklist that would ever surface it.

Browser extensions with broad permissions. Installed by individuals, invisible to any inventory that looks at accounts or subscriptions, and frequently holding the ability to read everything a browser tab displays.

Why this is a security problem, not just a spend problem

Finance cares about sprawl because of the wasted subscription cost. Security should care for a different reason: each of these tools is a place your company's data can be, that is not in your data map, not covered by your vendor review process, and not included when someone asks where customer data lives.

An abandoned tool with a live OAuth grant is a standing access path that nobody is watching, held by a vendor whose security posture was never assessed, whose breach would not appear on anyone's list of things to check, because nothing connects that vendor to your company in any system anyone consults.

Building the inventory that stays current

Start with the OAuth and API grant review, across your identity provider, your source host, your email platform, and any other system with an integrations page. This alone surfaces the highest-risk category, because it shows live access rather than historical spend.

Cross-reference against active subscriptions. Anything with a grant and no active subscription is a dormant integration: revoke it immediately, because there is no legitimate reason for a cancelled tool to retain access.

Require a lightweight registration for new tools, genuinely lightweight: a name, an owner, what it connects to, what data it touches. The bar has to be low enough that people actually clear it, or they will route around it exactly as they routed around asking permission in the first place.

Review quarterly, against the same three sources. New tools appear between reviews regardless of process, so the value is in the cadence catching them within a quarter rather than a year.

Fold it into offboarding. When someone leaves, check what they connected, not just what accounts they held in your directory. A departing employee's personal-email SaaS signups are invisible to every standard offboarding checklist.

The concession

A registration requirement, however lightweight, adds friction to trying a new tool, and the entire reason casual adoption works is that it has none. Some teams will experience even a two-minute form as an obstacle worth avoiding, and a process that is resented gets circumvented.

The trade worth making is between friction and visibility, not between friction and none. A lightweight process that catches most new tools within a quarter is worth far more than a strict one that gets bypassed entirely, so calibrate toward the version people will actually use.

The implication

Every SaaS tool adopted outside a process is a place your data can live that nothing tracks, and the OAuth grant it holds usually outlives everyone's memory that the tool was ever tried.

Pull the connected-apps list from your identity provider and your source host today, and look at the ones you do not recognise. Those are the tools currently holding access to something, unreviewed, unrevoked, and unrelated to anything on your subscription list.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.