The average Perth SMB is paying for more software than it uses. SaaS (Software as a Service) subscriptions accumulate quickly - someone signs up for a trial, it converts to paid, nobody notices. Staff leave and their licences keep billing. Three different tools end up doing the same job. A proper SaaS audit typically saves a Perth business 15–30% of its annual software spend.
What Is SaaS Sprawl?
SaaS sprawl is what happens when software subscriptions accumulate without central oversight. It creates two distinct problems:
- Financial waste - unused licences, duplicate tools, and auto-renewed annual subscriptions nobody reviews
- Security risk - unmanaged SaaS apps connected to company data via OAuth tokens, staff using personal credit cards for work software (invisible to IT), and no visibility of where company data actually lives
Both problems are common in Perth businesses that have grown organically - each team or manager adopted what they needed without a central approval or review process.
The SaaS Audit - What to Look For
Step 1: Find everything
Most businesses cannot list every SaaS tool they pay for. Start by:
- Reviewing credit card and bank statements for the past 12 months - look for recurring charges from software vendors
- Checking your Microsoft 365 admin centre → Apps → Connected apps to see every third-party app with access to your Microsoft 365 tenant
- Asking each department what software they use day to day
- Reviewing your accounts payable for software invoices
Most Perth businesses are surprised by what they find - tools they forgot existed, trials that converted to paid plans, and duplicates across departments.
Step 2: Classify each tool
For each SaaS application found, answer:
- Is it still being used? Log in and check last active date, or ask IT to pull sign-in logs
- Does it duplicate another tool? Common duplicates: two project management tools, two file storage platforms, two video conferencing apps
- Does it have access to company data? If yes, is that access still needed, and is the vendor trustworthy?
- Who approved it? Shadow IT (tools adopted by staff without IT approval) is a security risk because nobody has assessed the vendor's data handling
Step 3: Right-size licences
Many SaaS contracts are over-provisioned. A business with 15 staff paying for 20 Microsoft 365 licences is paying for five unused seats. Review every subscription and match licence count to active users. Do this annually - staff numbers change, and licence counts rarely shrink automatically.
Common SaaS Waste in Perth Businesses
- Dropbox + OneDrive - paying for Dropbox Business while also having OneDrive included in Microsoft 365. Migrate to OneDrive and cancel Dropbox.
- Zoom + Microsoft Teams - both are video conferencing platforms. Most Microsoft 365 businesses can use Teams exclusively.
- Multiple project management tools - Trello, Monday.com, Asana, and Jira being used by different teams with no consolidation
- Adobe Creative Cloud seats for infrequent users - an expensive licence ($80+/month) kept active for a staff member who uses it occasionally. Consider a shared seat or lower tier.
- Legacy accounting software + Xero - paying for both during a transition that never completed
SaaS Security - The Overlooked Risk
Every SaaS app connected to your Microsoft 365 or Google Workspace via OAuth has access to some portion of your data. When a staff member clicks "Sign in with Microsoft" in a third-party app, they grant that app permissions - often broader than necessary.
Key security controls:
- Audit connected apps regularly - in the Microsoft 365 admin centre, review and revoke OAuth permissions for apps that are no longer used or that you didn't approve
- Require IT approval for new SaaS tools - a simple process where staff request new software and IT checks the vendor's security posture and data handling before approving
- Offboard SaaS apps when staff leave - revoke access to all SaaS tools as part of the offboarding process, not just email and Microsoft 365
- Use single sign-on (SSO) - Microsoft Entra ID SSO lets staff log into third-party apps with their work credentials, centralising access control and making offboarding cleaner
How Often to Review
Run a full SaaS audit annually - ideally tied to your financial year-end review. Do a lighter review quarterly to catch trials converting to paid, departing staff's licences, and any new tools adopted without approval.
Build a simple register: a spreadsheet or SharePoint list with every SaaS tool, the monthly/annual cost, the number of licences, the licence renewal date, and the owner (the person responsible for the tool). This single document transforms SaaS chaos into something manageable.
Frequently Asked Questions
How do I find out what SaaS tools our business is actually paying for?
Start with 12 months of credit card and bank statements and look for recurring software charges, then check the connected apps list in your Microsoft 365 admin centre for anything with access to your tenant. Most businesses are surprised by what turns up, including forgotten trials that quietly converted to paid plans.
What's shadow IT and why does it matter?
Shadow IT is software staff sign up for and use without IT ever approving or reviewing it, often paid for on a personal card. It matters because nobody has checked how that vendor handles your data or how securely the app is built, so it can become an access point into your business that IT doesn't even know exists.
How often should we review our software subscriptions?
A full audit once a year, ideally around your financial year-end, plus a lighter quarterly check-in to catch trials that converted to paid, licences left active after staff leave, and any new tools that crept in without approval. Licence counts rarely shrink on their own, so it has to be an active review rather than something you assume is fine.
Is it worth using single sign-on for SaaS apps?
Generally yes, for most small and medium businesses. Single sign-on through Microsoft Entra ID lets staff log into third-party apps with their existing work credentials, which centralises access control and makes offboarding far cleaner, since disabling one account can cut off access to everything connected to it.
We conduct SaaS and licence audits for Perth businesses as part of our IT consulting and managed IT services - identifying waste and security gaps.
IT Consulting →Want to know what your Perth business is actually spending on software?
Call 0433 087 091 - we'll audit your SaaS stack, identify waste and security risks, and give you a clear picture of what to keep, consolidate, and cancel.
Book a Software AuditFor related reading, see our guides to Hybrid Work IT Setup for Perth Businesses, Remote Work IT Setup for Perth Businesses, and Third-Party Vendor Risk.