Your cloud bill is a licence audit in disguise
Most SMBs we look at are paying for seats belonging to people who left, and premium tiers nobody uses a feature of.
The short version
- Cloud spend creeps because purchasing is easy and reviewing is not.
- A half-day audit — user list, payroll, last sign-in, card statements — finds most of it.
- Every dormant account is also a security exposure, not just a line item.
- The saving only holds if offboarding and renewal dates get an owner.
Cloud spend creeps because nobody owns it. Someone adds a seat for a new starter and nobody removes it when they go. A department buys a tool on a card because it was faster than asking. Two years later the monthly total looks like a fact of life rather than a decision.
The industry numbers are worse than most owners expect. Gartner puts around a quarter of SaaS budgets into unused entitlements and overlapping tools; Zylo's SaaS Management Index reports that roughly half of licences go unused in any given month, and that spend per employee is still climbing. Those figures come from larger organisations, but the mechanism is identical in a thirty-person company — it just has fewer zeros.
The half-day version
You do not need a management platform to do the first pass. You need four exports and a spreadsheet.
- Export your user list from Microsoft 365, Google Workspace or whatever your identity provider is. Include last sign-in date and assigned licence.
- Compare it against payroll. Every account that does not map to a current employee, contractor or shared function is a question. Most of them will be leavers.
- Sort by last sign-in. Ninety days of no activity on a paid seat is a candidate for removal or downgrade. Check before cutting: some are legitimate service accounts, and those should be labelled as such so this exercise is faster next time.
- Pull twelve months of card and bank statements and list every recurring software charge. Anything that appears there but not in your identity provider is shadow IT — usually harmless, occasionally holding customer data nobody knows about.
- Map duplicates by category. Storage, chat, video calls, project tracking, e-signature, note-taking. Pick one canonical tool per category and give the others a decision date.
In one recent audit, the leaver accounts alone accounted for eleven percent of the monthly bill. Downgrading two premium tiers nobody used a feature of added a little more.
Savings from tidying licences often cover a good part of a managed IT retainer. That is a fair way to judge one.
What we usually find, in rough order of size
| Finding | Why it happens | Typical fix |
|---|---|---|
| Seats for people who left | Offboarding stops at email and door access | A checklist that covers every paid tool, not just the obvious two |
| Premium tiers used as standard | Bought during a project, never reviewed | Downgrade the majority, keep premium for the few who need it |
| Duplicate tools | Departments bought independently | One canonical tool per category, migrate the rest |
| Growth seats never filled | Negotiated for a headcount that did not arrive | Right-size at renewal, in writing, before auto-renewal fires |
| Forgotten infrastructure | A test VM, an old backup bucket, a staging environment | Tag everything with an owner; delete what has no owner |
The part that is not about money
An account for someone who left in 2024 is not merely a wasted seat. It is a valid credential, usually with a password that has never been rotated, frequently without multi-factor authentication, and — critically — nobody is watching it, because nobody expects it to be used. Attackers look for exactly this.
That is the same access hygiene problem that sits underneath the invoice fraud case we wrote up in this article. A licence audit and an access review are the same exercise looked at from two directions, which is why we do them together.
While you are in there, note which accounts hold personal data. Under the Data Protection Act 2017 you are expected to be able to describe your processing and to hold data no longer than needed — a tool nobody has opened in a year, still full of customer records, is a compliance question as well as a cost one.
Making the saving stick
Most companies do this exercise once, cut thirty seats, and are back where they started eighteen months later, because nothing changed in how tools get bought and how people get offboarded. Three things make it durable:
- One named owner for software spend. Not a committee. Someone whose job includes saying no.
- Offboarding that names every system. Written down, and run the same day the person leaves. If it takes more than fifteen minutes, it is not detailed enough yet.
- A renewal calendar with reminders 60 days out. Auto-renewal is where negotiating power goes to die. Sixty days is enough time to right-size or move; two weeks is not.
What not to cut
Two cautions, because we have seen enthusiastic tidying cause real damage. Do not cut backup, endpoint protection or multi-factor authentication licences to make the number look better — those are the ones you are paying for precisely because you cannot see them working. And do not downgrade a tier without checking which feature the finance or compliance team actually relies on; audit logs and retention policies frequently live in the higher tier for exactly that reason.
One local note: most of these bills are denominated in US dollars or euros. A stable-looking subscription can grow eight or nine percent in rupee terms without anyone changing anything, so review the rupee figure, not the vendor's number.
Frequently asked questions
How long does the first audit take?
Half a day for a business under fifty people, assuming the exports are available. The follow-up quarterly review is under an hour.
Will the vendor refund unused seats?
Rarely mid-term, commonly at renewal. That is why the sixty-day reminder matters — the conversation is much easier before the renewal date than after it.
Should we buy a SaaS management platform?
Not below a few hundred employees. The spreadsheet and the identity provider export will find nearly all of it, and the platform's cost is often a meaningful share of the waste you are trying to remove.
Do you do this as part of a retainer?
Yes — at onboarding, then once a quarter, with the figures in the monthly report so you can see whether the tidying held. Book a call and the first audit is free.
Sources
- Zylo, SaaS Management Index (2025 and 2026 editions) — unused licence rates and spend per employee.
- Gartner analysis on unused entitlements and overlapping SaaS tools, as reported in industry summaries, 2025.
- Data Protection Act 2017 (Mauritius), retention and accountability obligations — Data Protection Office.
