The defensible way to reduce SaaS spend is to reconcile what the organisation pays for, what it is contractually committed to, and what people actually use. There is no universal 40% saving and no honest 90-day guarantee. The available opportunity depends on contract timing, paid quantities, product usage, migration cost and whether overlapping tools can genuinely replace one another.
This guide replaces unsupported industry averages with an evidence-led audit. It explains how to build the inventory, interpret usage without deleting business-critical access, calculate realised savings and decide whether specialist software is justified.
Quick Verdict
Start with the ledger, not a savings target. Match every recurring charge to a contract, owner, paid quantity, usage signal and decision date. Remove or downgrade only after checking business need, data ownership and retention. Count savings when committed spend falls.
- Find: invoices, card charges, expenses, contracts and non-SSO applications
- Test: meaningful activity, tier fit, duplicate capability and migration cost
- Control: renewal notice dates, joiner/mover/leaver access and purchase approval
Method and Evidence Standard
This is a documentation-led operating guide, not a claim that we have audited a representative set of customer estates. We checked current Microsoft and Google administration documentation, UK National Cyber Security Centre guidance and current vendor product pages. Vendor descriptions establish what a product says it can do; they do not prove savings or return on investment.
For each optimisation decision, retain four forms of evidence: the commercial commitment, the paid quantity and tier, an appropriate usage signal, and the approved action. A finance charge proves spend but not adoption. An identity-provider login proves authentication but not valuable use. An admin report may show activity but not whether the work is business-critical.
Evidence Sources at a Glance
| Source | What it establishes | What it can miss | Primary owner |
|---|---|---|---|
| Accounts payable, cards and expenses | Charges, payee, amount and payment route | Free tools, bundled products and contract terms | Finance |
| Contract repository | Term, quantity, renewal and notice provisions | Card purchases and amendments stored elsewhere | Procurement or Legal |
| Identity provider | Assigned access and authentication events | Apps outside SSO and in-product feature use | IT or Security |
| Vendor admin report or API | Licence assignment and product-specific activity | Offline work, shared accounts and business context | Application owner |
| Owner interview and workflow map | Criticality, dependencies and replacement risk | Unrecorded shadow use and optimistic estimates | Business owner |
| Approved decision log | Who authorised removal, downgrade or renewal | Whether the expected saving reached the ledger | FinOps or Finance |
Step 1: Build the Spend and Contract Ledger
Pull at least one complete renewal cycle of accounts-payable transactions, corporate-card charges, approved expenses and procurement records. Normalise vendor names so that resellers, marketplace purchases and regional billing entities roll up to the same product. Do not assume the identity-provider catalogue is the inventory: it cannot see every card purchase or app outside SSO.
Each ledger row should include:
- vendor, product, billing entity and internal owner
- currency, tax treatment, billing frequency and committed annual cost
- term, renewal date, notice deadline and cancellation route
- paid seats or consumption commitment, assigned quantity and available usage source
- data owner, integration dependencies and exit requirements
Mark missing contracts and unknown owners as control failures, not automatic savings. A product without an owner may still run a critical integration. The ledger is complete when every material recurring charge has an accountable decision-maker and a dated next action.
Step 2: Test Licence Usage Safely
Use the strongest product-specific signal available. Microsoft documents that its 365 admin reports show assigned and unassigned licences, active users and service-level usage; reports can be exported, but Microsoft also warns that there is no single report listing every service used by one user. Google's Admin Reports API returns Workspace service-usage data and supports last-login reporting, with a documented maximum reporting period of 450 days. These are useful inputs, not universal definitions of value.
Classify each paid seat as retain, downgrade, reassign, remove after confirmation or exception. Set an inactivity window appropriate to the job: a payroll administrator, quarterly board user and daily support agent should not share one threshold.
Before removing access, check record ownership, automation credentials, legal or contractual retention, export needs and the reinstatement path. The NCSC cloud security guidance recommends access that is visible, granular and easy to remove when unused. That supports disciplined rightsizing, but it does not justify deleting data or identities without review.
Step 3: Test Overlap and Migration Cost
Two products in the same category are not necessarily duplicates. Compare the actual workflows: required integrations, permissions, data residency, auditability, automation, external collaboration, file formats and accessibility. Interview the teams that use the exceptional capability, not only the budget owner.
For each consolidation candidate, estimate export and migration work, retraining, parallel-running time, integration rebuilding, records that cannot be transferred and the risk of reverting. A cheaper renewal can still be a worse economic decision if switching costs exceed the avoidable commitment.
Run a representative pilot before cancelling the incumbent product. Our Notion vs Obsidian comparison, for example, treats collaboration and local-first control as different requirements rather than interchangeable checkboxes.
Step 4: Work Backwards from Notice Dates
Read the executed contract and amendments. Record the renewal mechanism, notice method, notice address, deadline, committed quantity, price-change language and any minimum term. The previous article asserted that most contracts use a 30-day clause and that vendors are most flexible 60–90 days before renewal; neither is safe as a universal rule.
Instead, set an internal decision date far enough ahead of the contractual notice deadline to collect usage, run a replacement pilot and obtain approvals. Submit any cancellation or non-renewal through the method the contract requires, retain evidence of delivery and confirm the vendor's acknowledgement.
Negotiate the complete commercial package: quantity bands, lower-cost roles, consumption commitment, support, implementation, price caps, data export, renewal structure and termination assistance. A headline discount is not a saving if the buyer accepts excess quantity or a longer commitment that it cannot use.
Calculate Realised Savings
Keep opportunity, approved action and realised saving separate:
- Gross annual opportunity = removable licences + tier reductions + avoidable duplicate commitments + negotiated price reduction
- Net expected benefit = gross opportunity − migration − implementation − consulting − new platform cost
- Realised annual saving = old committed run rate − new committed run rate − recurring replacement cost
Example: 20 seats at £30 per month look like a £7,200 annual opportunity. If ten seats can be removed and five downgraded to £10, the gross annual opportunity is £4,200. If migration and implementation cost £1,500 once, the first-year expected benefit is £2,700; the recurring run-rate reduction is £4,200. The saving becomes realised only when billing or the executed renewal reflects the change.
Use our SaaS spend calculator for the baseline and scenario arithmetic, but preserve the contract and approval evidence outside the calculator.
When a SaaS Management Platform Helps
Do not use an arbitrary threshold such as 50 subscriptions or £100,000 of spend. Consider specialist software when the manual process cannot reliably discover purchases, join financial and identity data, collect product usage, track notice dates or execute access workflows.
Current vendor pages illustrate the category. Torii describes discovery from identity, finance, HR, direct integrations and browser-level signals, plus licence and renewal workflows. CloudEagle describes discovery inside and outside SSO, feature-level usage, licence workflows, a contract repository and renewal alerts. These are vendor claims; test data coverage, permissions, implementation work, pricing and export before buying.
A business case should compare the platform's full annual cost with measured labour saved, realised licence reduction, avoided renewal leakage and security or audit value. Run a proof of concept against a known sample and verify false positives as well as discoveries.
A 30-Day Control Plan
- Days 1–5: collect financial transactions, contracts and identity-provider application lists; normalise vendors.
- Days 6–10: assign an owner and decision date to every material product; flag missing contracts and card purchases.
- Days 11–17: obtain admin usage reports and classify seats for retention, downgrade, reassignment, removal or exception.
- Days 18–24: test overlap, migration cost and renewal options with business owners.
- Days 25–30: approve actions, send any contractually valid notices, update access and record the expected financial effect.
After the initial audit, make new purchases identify the owner, data classification, approval, renewal terms and exit path. Tie joiner/mover/leaver events to application access, and review material contracts according to their decision dates. The cadence should follow risk and change rate rather than a universal quarterly rule.
Primary Sources Checked
- Microsoft 365 admin activity reports: licence, active-user, service-usage and privacy behaviour
- Google Workspace Reports API: user usage, covering available usage and last-login reporting
- NCSC Cloud Security Principle 9: visible, granular access and removal of unused permissions
- Torii platform: vendor-described discovery, usage and workflow inputs
- CloudEagle SaaS management: vendor-described discovery, licence, contract and renewal features
Sources checked 12 August 2026. Product features, administration reports and contract terms can change. Verify the applicable documentation and executed agreement before acting.
Frequently Asked Questions
How much can a SaaS audit save?
There is no defensible universal percentage. Calculate gross opportunities from removable seats, lower tiers, duplicate contracts and negotiated reductions, then subtract migration, implementation and management costs. Report savings only after committed spend actually falls.
What counts as an unused SaaS licence?
A licence is a candidate for review when reliable product or admin data shows no meaningful use during a period appropriate to the role. A login alone is weak evidence, and inactivity should not trigger automatic deletion without checking ownership, retention and business need.
How often should SaaS subscriptions be reviewed?
Use the contract calendar to set the cadence. Review material contracts before their notice deadlines, monitor joiners and leavers continuously, and choose a portfolio review interval that matches the organisation's rate of change.
When is a SaaS management platform worth considering?
Consider one when manual inventory, usage collection, renewal tracking or access workflows no longer operate reliably. Build a business case using measurable annual benefit, implementation effort, recurring platform cost and risk reduction rather than an arbitrary app-count or spend threshold.
Can SaaS contracts be renegotiated mid-term?
Only if the contract and vendor permit it. Expansion, scope changes or a commercial amendment can create an opening, but buyers should not assume a vendor must reprice an active commitment.
What is the first step in reducing SaaS costs?
Create a ledger from accounts payable, cards, expenses and procurement records, then attach an owner, contract, renewal date, paid quantity and available usage evidence to every recurring software charge.