Turn clients’ SaaS sprawl into recurring revenue

A practical service blueprint for helping clients reduce waste, govern access and control shadow AI.

SaaS Sprawl

Ask an SMB client to inventory its cloud applications and the first list will probably include Microsoft 365, its line-of-business software and a few collaboration tools. The bigger issue is what will not appear – AI assistants, project platforms, design tools and other services employees adopted without a formal review.

That visibility gap is more than an IT inconvenience. It creates unnecessary spending, unmanaged access and compliance exposure. For MSPs, it also creates an opportunity to build a recurring service around a problem most clients are not equipped to solve alone.

What this article covers:

  • Why SaaS sprawl and shadow AI have outgrown what RMM and MDM tools can see.
  • A See-Secure-Save framework for packaging a SaaS governance service.
  • Pricing models, from one-time projects to shared-savings arrangements.
  • A 90-day plan for piloting and launching the service.

The SaaS blind spot hiding in plain sight

The problem is measurable. JumpCloud’s 2025 SME IT Trends Report found that 66% of IT professionals struggle to discover the SaaS applications employees are using. Purchasing has moved beyond IT: department managers buy applications on corporate cards, employees start free trials with work email addresses and users connect third-party AI tools to company data.

Waste follows quickly. Zylo’s 2026 SaaS Management Index found that organizations leave an average of 36% of their SaaS licenses unused. Although Zylo’s dataset reflects organizations managing SaaS at scale, the underlying causes are familiar in smaller businesses – employees change roles, projects end, duplicate tools accumulate and subscriptions renew without an owner reviewing them.

The same Zylo index shows why shadow AI has become the sharper edge of this problem: business units now control 81% of SaaS spend versus 15% managed directly by IT, and spending on AI-native applications is up 108% year over year. That combination – decentralized buying and fast-growing AI tools – is exactly what makes an inventory built from device and identity data alone incomplete.

Why RMM and MDM leave a visibility gap

Most MSPs already manage client endpoints through remote monitoring and management (RMM) and mobile device management (MDM) platforms. Those tools are effective at tracking device health, installed software and security configuration. They generally cannot tell an MSP that a sales representative connected an inbox to an unsanctioned AI service or that marketing is sharing customer information through a personal SaaS account.

Closing that gap requires combining approved data sources such as identity and single sign-on systems, accounting and expense records, OAuth connections and network or browser telemetry. No single feed will reveal everything. The value of the service comes from assembling those signals, validating the findings and turning them into action.

Build the service around three outcomes

Rather than sell clients another dashboard, package the offering around a simple See–Secure–Save framework.

See. Create and maintain an application inventory that records the owner, business purpose, users, subscription tier, spending and renewal date for each service. The goal is centralized visibility across connected systems – not an unrealistic promise that one scan will discover every application.

Secure. Classify applications by the data they handle, the permissions they request and their importance to the business. Require an accountable owner, apply single sign-on and multifactor authentication where supported, review high-risk integrations and establish provisioning and deprovisioning workflows. When someone leaves, the process should address access across connected SaaS applications – not only the primary identity provider.

Save. Identify inactive licenses, overlapping applications, unnecessary premium tiers and subscriptions approaching automatic renewal. Separate realized savings from cost avoidance, document client approval before canceling anything and report the results during each quarterly business review (QBR). That turns the QBR from a ticket recap into a conversation about measurable business outcomes.

Price the service around measurable value

MSPs can package the service in several ways. A one-time discovery and remediation project offers a low-risk entry point. An ongoing base fee combined with a user or application tier supports continuous monitoring and governance. A hybrid model can add a performance fee based on documented savings during an initial optimization period.

Avoid copying a per-user price without understanding the economics. Model the platform cost, integration and onboarding labor, monthly review time, client reporting, advisory work and target gross margin. Define which data sources and applications are included, how often they are reviewed and what remains the client’s responsibility.

Shared-savings arrangements need even tighter definitions. The statement of work should establish the original spending baseline, eligible savings, exclusions, measurement period and approval process. A renewal that does not increase is cost avoidance; a canceled unused license is realized savings. Clients should understand the difference.

Connect savings to security and compliance

Cost reduction may open the door, but risk management makes the service strategic. The Cloud Security Alliance’s 2025 State of SaaS Security Report found that 56% of surveyed organizations had employees uploading sensitive data to unauthorized SaaS applications. The same study found that 54% lacked automated identity lifecycle management.

A managed SaaS program can give clients stronger evidence for access reviews, employee offboarding, vendor-risk assessments and data-governance requirements. It does not make a client compliant by itself. It creates repeatable controls and documentation that support the broader compliance program – while giving the MSP a natural path into identity, data loss prevention and virtual CIO services.

The first 90 days – from pilot to service launch

Days 1–30: Establish the baseline. Select one cooperative client, obtain written authorization and agree on the data sources, access permissions and retention rules. Record the applications discovered, percentage with assigned owners, inactive licenses, orphaned accounts, high-risk integrations and renewals due within 120 days.

Days 31–60: Prove the outcome. Remediate a manageable group of findings. Validate license usage before removing seats, assign owners, close abandoned accounts and tighten risky access. Use the results to document a standard operating procedure, responsibility matrix and exception process.

Days 61–90: Package and repeat. Finalize the scope, pricing and client-facing dashboard. Present the before-and-after results during the QBR and propose ongoing monitoring. Once delivery is repeatable, introduce the service to two or three additional clients rather than attempting a portfolio-wide rollout immediately.

Clients do not need another tool generating alerts nobody owns. They need someone to translate SaaS usage into decisions about spending, access and risk. MSPs that help clients see, secure and save across their SaaS environments can create measurable value – and a service clients have a reason to renew.


×