What the Numbers Show
Every January, SaaS management vendor Zylo publishes its SaaS Management Index, built from actual usage and spend data pulled out of the software portfolios of large organizations it works with. The 2026 edition, released January 29, found the average organization now runs 305 separate SaaS applications, with a median portfolio size of 240. Average annual SaaS spend came in at $55.7 million, up 8% year over year, with a median spend per employee of $9,455.
The visibility number is the one worth sitting with. According to the index, business units now control 81% of SaaS spend, while IT directly manages just 15%. That means for every dollar a company spends on software, roughly 81 cents is being decided, purchased, and renewed by someone outside the department whose job is to track, secure, and consolidate that software. IT isn’t being slow to catch up here; it structurally doesn’t have the visibility to catch up, because the buying decisions are happening somewhere else entirely.
That decentralization shows up directly in waste. Zylo found organizations leave an average of 36% of their SaaS licenses unused, measured against industry-recommended utilization benchmarks, meaning more than a third of what companies pay for every month is licensed to nobody or to accounts nobody is opening. The report also flagged a sharper trend underneath the sprawl: expense-based SaaS spend, tools employees put on a company card or expense report rather than run through procurement, grew 267% year over year, with ChatGPT now the single most expensed application in the data set.
None of this requires a breach or an attacker to become a real problem. It’s simply what happens when purchasing outpaces oversight: money spent on software nobody uses, and applications holding company data that IT never signed off on, never inventoried, and in many cases doesn’t know exist.
Why This Matters If You’re Not a Big Company
It’s tempting to read “305 apps” and “$55.7 million” and assume this is an enterprise-scale problem that doesn’t apply below a certain headcount. But the mechanism driving the sprawl, individual employees and departments signing up for tools on their own because it’s faster than asking IT, doesn’t require a large company to happen. A 30-person business with a marketing team using its own expensed tools, a sales team on a CRM add-on nobody centrally approved, and a handful of free-tier signups from six months ago is running the exact same pattern at a smaller scale, just without anyone tracking it at all.
Smaller businesses are actually more exposed to the downstream risk, not less, because they’re less likely to have any SaaS inventory process in the first place. A large enterprise with a fraction of its apps unmanaged still has an IT or security team reviewing what it can see. A small business where nobody owns the question “what software are we actually paying for and who still has access to it” has no visibility into any of it, which means unused licenses just quietly renew and former employees’ accounts into tools IT never provisioned just sit there, active, indefinitely.
What Businesses Should Do Instead
The fix isn’t a big procurement overhaul; it’s a periodic inventory, done on purpose rather than left to happen by accident. Start with your expense reports and credit card statements going back twelve months and list every recurring software charge you find, not just the tools IT set up. Cross-reference that list against your current employee roster: any account tied to someone who no longer works there gets shut off immediately, not queued for “eventually.”
From there, the ongoing habit that actually prevents this from rebuilding itself is making software requests go through one visible channel, even a simple one like a shared form or a Slack request, so new tools get logged instead of just expensed. It doesn’t need to be restrictive enough to slow people down; it just needs to exist, so six months from now there’s a list to check instead of a guess.
Security Checklist for Your Business
Run a twelve-month expense audit. Pull every recurring software charge from expense reports and card statements, not just what IT provisioned directly.
Cross-check active accounts against current staff. Any account still tied to a former employee gets disabled the same day it’s found, not scheduled for later.
Centralize new software requests. A single visible intake channel, even an informal one, turns invisible expensed purchases into a list someone can actually review.
Review license counts against actual usage at renewal time, not just cost. An unused seat renewing automatically is money and access both going unmonitored.
Software sprawl doesn’t announce itself with an alert; it just quietly accumulates until nobody can say with confidence what’s running or who still has access. MSP Today’s trusted tech partner is JK Computer Solutions. If you want a second set of eyes on your setup, get in touch.
Source: Zylo, “Zylo’s 2026 SaaS Management Index Finds AI-Native App Adoption Is Surging, with ChatGPT Now the Most Expensed App”.



