惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
博客园 - 三生石上(FineUI控件)
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园_首页
Last Week in AI
Last Week in AI
美团技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
WordPress大学
WordPress大学
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - Franky
The Cloudflare Blog
罗磊的独立博客
月光博客
月光博客
N
Netflix TechBlog - Medium
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Microsoft Azure Blog
Microsoft Azure Blog
IT之家
IT之家
Jina AI
Jina AI
J
Java Code Geeks

Blog on 1Password Blog

Why secure-by-design is an incentives problem, with Bob Lord | 1Password NIST and AI agents: 1Password’s approach to agent identity | 1Password Go beyond device health with External Checks in 1Password Device Trust | 1Password Natoma and 1Password help enterprises scale AI securely with governed agent access | 1Password New integrations between 1Password SaaS Manager and EPM | 1Password A first step toward post-quantum security | 1Password RSA 2026: Leading the way to secure agentic AI | 1Password How 1Password is Building a Culture of AI Fluency Through AI Champions | 1Password 1Password vs. Keeper Security: A comparison | 1Password 1Password vs. LastPass: Which is right for you? | 1Password Secure MCP credentials with 1Password and Runlayer | 1Password The next layer of AI security | 1Password Building the next chapter of Go-to-Market in EMEA | 1Password Automating SOC workflows with 1Password Enterprise Password Manager | 1Password Automated Provisioning hosted by 1Password: A Simpler, Smarter Way to Manage Access | 1Password Introducing 1Password® Unified Access: Identity Security for Humans and Their AI Agents | 1Password Next-generation automated provisioning, without compromising zero-knowledge security | 1Password Bitwarden vs. 1Password: Which password manager is right for you? | 1Password Password Manager for Families, Enterprise & Business | 1Password | 1Password How to wrangle SaaS contract renewals | 1Password Stop trusting consumer browsers with work credentials | 1Password IAM stops at sign-in. Your credentials do not. | 1Password Your digital pit crew: a 10-minute pre-race security checklist | 1Password 1Password Device Trust is coming to EMEA | 1Password The identity transformation: Analyst and CIO insights | 1Password Why now is the moment to join 1Password Go-To-Market | 1Password Identity and Accountability in the Age of AI Agents | 1Password How 1Password secures agent architectures | 1Password 1Password becomes the first global partner to transact through Express Private Offers in AWS Marketplace | 1Password Start Learning on 1Password Academy | 1Password
Solving the unsanctioned SaaS problem | 1Password
info@1password.com (Dominic Garcia) · 2026-02-02 · via Blog on 1Password Blog

Unsanctioned SaaS and shadow IT are problems every organization deals with. When procuring a new SaaS tool is a few clicks, an email, and a credit card away, it’s never been easier for unsanctioned apps to increase across the business. Often, this is outside IT’s line of sight, outside security controls, and outside standard provisioning/deprovisioning processes.

Watch: Stop managing SaaS in the dark

Our on-demand webinar shows how IT teams use SaaS Manager to continuously discover unsanctioned apps, automate offboarding, and close the access gaps that manual audits miss.

This isn’t driven by bad intent. Employees and business units are bringing new tools into the business to increase their productivity, and it’s helping the business move forward. Unfortunately, modern work is happening faster than traditional controls were designed to handle. And that gap is where risk, wasted spend, and compliance issues emerge.

Why uncovering unsanctioned SaaS matters

Unsanctioned SaaS tools create three distinct problems for organizations:

Security risks. Apps that aren’t connected to SSO or IAM can store sensitive company data. Since these tools aren’t incorporated into standard identity and security processes, access to these applications often persist after employees leave, ultimately expanding the attack surface. When applications live outside of IT’s visibility and control, it becomes difficult to manage and revoke access.

Wasted spend. When you don’t have visibility into the SaaS apps being used, employees could be using redundant applications.  As a result, the company could be paying for overlapping tools for the same job. Over time, SaaS spend grows because no one has a full picture, not necessarily because the business actually needs more software.

Compliance concerns. Most deprovisioning processes rely on HRIS or IdP triggers. That works for apps that are managed by IT that are behind SSO. But unsanctioned SaaS falls through the cracks, creating access risks and compliance gaps. 

The big problem is that unsanctioned SaaS isn’t an edge case, it’s become the default state of modern work environments.

Why is it so hard to discover unsanctioned SaaS?

Shadow IT is one of those problems that just seems to perpetuate and never quite go away. That’s not because IT is failing, it’s because the tools many IT teams rely on weren’t built to address this reality.

IAM and SSO were designed for managed apps. They’re great for applications that IT already knows about, but they don’t discover new apps that employees and business units signed up for without IT’s knowledge. While these tools are great for removing access to tools being SSO, they often don’t remove the licenses themselves, leading to overspending.

SaaS ownership is decentralized. Ownership of individual tools are spread across teams and budgets. Finance sees spend, but not utilization; security sees risk, but not context; and IT is stuck trying to connect the dots across all of it.

Manual processes don’t scale. Point-in-time audits go stale the moment they’re finished. Spreadsheets can’t keep up with joiners, leavers, contractors, and AI tools appearing every week. The environment changes faster than humans can track it.

Fundamentally, you can’t tackle a continuous problem with point-in-time or manual solutions. 

How 1Password SaaS Manager uncovers unsanctioned SaaS tools

1Password SaaS Manager helps IT teams regain control of their SaaS ecosystem, without adding friction for employees.

  • Continuously uncover new SaaS apps used across the business, automatically. This provides IT with an always-updated inventory of apps, users, and licenses. No manual audits required.

  • Extend governance beyond SSO and support automated joiner and leaver workflows. 1Password SaaS Manager ensures access is revoked and licenses are reclaimed, even for apps that aren’t connected to your IdP. 

  • Reduce risk and spend at the same time by surfacing unused licenses and redundant tools. 1Password SaaS Manager helps IT and Finance make better decisions by providing up-to-date visibility at renewal time.

Most importantly, 1Password SaaS Manager closes the gap between how people actually work and how access is governed. Employees keep the flexibility they need, and IT regains the visibility and control it’s responsible for.

Take control of SaaS sprawl

Shadow IT, unmanaged access, and wasted licenses add up fast. See how 1Password SaaS Manager helps teams discover SaaS usage, reduce access risk, and bring spend back under control.