Building a SaaS inventory: what's actually running in your business?
The average SMB has 47 active SaaS subscriptions. Half of them fly completely under the radar. Without an inventory, access management is impossible — you can't check the doors if you don't know they exist.
Access management without an inventory is a losing battle. You can only review who has access to what once you know what "what" actually exists.
\n \nHow to put together a working list
\n-
\n
- Start with your credit card and bank statements. Filter for recurring charges from SaaS vendors. This covers your known subscriptions. \n
- Ask every department head. "Which tools does your team use that weren't set up through IT?" Brace yourself for the answers. \n
- Check your DNS logs (or use Cloudflare). Which domains are visited most often from company devices? *.slack.com, *.notion.so, *.hubspot.com … \n
- SSO logs. If you use Microsoft 365 or Google Workspace as your SSO provider, all connected apps are listed in the admin console. \n
- Map out your shadow IT. Tools people bought with personal accounts and personal email addresses — you'll want to either formalise or replace these. \n
What to record for each SaaS tool
\n-
\n
- Name + URL \n
- Business purpose (in 1 sentence) \n
- Data classification: what sensitive data does it hold? \n
- Number of users + €/month \n
- Owner (internal responsible party) \n
- Admin account: where are the credentials stored? \n
- MFA: on / off / per-user \n
- SSO: yes / no / possible-but-not-enabled \n
- Contract end date \n
Frequency: update every quarter
\nTie this to your access review. One review moment, two goals: check existing access and bring your inventory up to date.
\n \nSave money while you tidy up
\nEvery time you run an inventory round, you'll find 2–5 subscriptions you can cancel or scale back. That more than pays for the effort.
\n \nSee also: cleaning up shadow IT for the human side of the story (colleagues don't love it when you take away their favourite tool).
Volledige gids: Control de accesos para pymes: la guía completa (2026)
Dit artikel is onderdeel van onze uitgebreide Toegangsbeheer-gids. Lees de pillar voor het complete plaatje.
Lees de pillar →