3 Ways to Discover Every SaaS App Your Organisation Uses
Guide
All articles
21 June 2026 6 min read0 comments

3 Ways to Discover Every SaaS App Your Organisation Uses

Browser extensions, SSO audit logs, and spend analytics each reveal a different slice of your shadow IT problem.

No single discovery method captures your complete SaaS estate. Each approach has different coverage, different privacy implications, and different data quality. The most complete picture comes from combining at least two.

Method 1: SSO Audit Log Analysis

If you use Microsoft Entra ID, Okta, or Google Workspace as your identity provider, you have a log of every "Sign in with [Provider]" authentication event — including the application that initiated it. This is the highest-fidelity discovery source because it captures actual authentication, not just visit data. Pull the last 90 days of OAuth consent events and you'll have a list of every SaaS app where employees have connected their corporate identity.

Method 2: Financial Data Analysis

Expense reports and corporate card statements reveal tools that employees are paying for personally and expensing, or that are being purchased on department cards outside of IT procurement. Work with Finance to export all vendor payments and expenses with software-related categories, then cross-reference against your known tool list.

Method 3: Browser Extension or Network Monitoring

Browser-based discovery agents can identify every web application an employee visits, including tools they access via saved passwords or shared credentials that don't use SSO. This gives the highest coverage but requires the most careful privacy-by-design implementation — employees should be aware that work device browsing is monitored for IT governance purposes.

Combining Methods for Complete Coverage

Each method has coverage gaps that the others fill. SSO log analysis misses tools accessed without corporate SSO — tools where employees use personal email to sign up, or where SSO isn't available. Financial data misses free-tier tools that cost nothing and are therefore invisible to accounts payable. Browser data misses tools used on personal devices or mobile apps. Combining all three typically achieves 85–95% coverage of the actual SaaS estate.

Start with SSO log analysis (highest fidelity, lowest privacy concern) and financial data (high fidelity for paid tools, already available from Finance). Add browser-based discovery selectively — for devices enrolled in your MDM, with clear employee communication about what is and isn't monitored. Layer the three data sources in your SaaS management platform and reconcile against your known tool list to produce a gap list of previously unknown applications.

Classifying Discovered Apps

Discovery produces a raw list of applications; classification makes it actionable. For each discovered app not already in your sanctioned inventory, classify it on: data sensitivity (what company data does it touch?), adoption breadth (how many employees use it?), and functional overlap (do you have a sanctioned alternative?). Tools that are high-adoption and low-overlap should be fast-tracked into your formal approval process. Tools with high data sensitivity should be flagged for immediate security and legal review regardless of adoption level.

Build a workflow for handling discovered apps systematically — a discovery queue where each new app is assigned to a reviewer, assessed against the classification criteria, and either approved (and added to the sanctioned inventory) or flagged for action (blocked, restricted, or an employee notification sent). This prevents discovery from becoming a list of findings that nobody acts on.

Making Discovery Continuous

A one-time discovery exercise reveals the current state of your shadow IT problem; continuous discovery keeps pace with new tool adoption. Configure automated alerts in your SSO provider for new OAuth connections to previously unseen applications. Set up quarterly financial data reviews. For browser-based discovery, ensure the agent updates its app detection library regularly to capture new SaaS products as they emerge.

The goal of continuous discovery is to reduce the time between a tool being adopted and IT knowing about it. In organisations with mature continuous discovery programmes, new shadow IT typically surfaces within days of adoption rather than months or years — which dramatically reduces the compliance and security exposure window.

Share X / Twitter LinkedIn

See Liceo in action

Track every licence, cut waste, and automate renewals — in one platform.

Discussion

Comments are moderated before appearing publicly.

No comments yet. Be the first to share your thoughts.

Leave a comment

Not published. Used for moderation only.

0/3000 characters

Ronke

Liceo product guide · AI assistant

Hi, I'm Ronke, Liceo's product guide. I can help you understand how we bring licence, vendor, and spend visibility together, or walk through plans and integrations. What are you trying to solve today?

Ronke shares verified product info only. For custom quotes or contracts, book a demo.