← All articles

Your cloud bill is a licence audit in disguise

Most SMBs we look at are paying for seats belonging to people who left, and premium tiers nobody uses a feature of.

A manager studying a rising cloud spend chart on screen, surrounded by invoices and leftover staff access badges

The short version

  • Cloud spend creeps because purchasing is easy and reviewing is not.
  • A half-day audit — user list, payroll, last sign-in, card statements — finds most of it.
  • Every dormant account is also a security exposure, not just a line item.
  • The saving only holds if offboarding and renewal dates get an owner.

Cloud spend creeps because nobody owns it. Someone adds a seat for a new starter and nobody removes it when they go. A department buys a tool on a card because it was faster than asking. Two years later the monthly total looks like a fact of life rather than a decision.

The industry numbers are worse than most owners expect. Gartner puts around a quarter of SaaS budgets into unused entitlements and overlapping tools; Zylo's SaaS Management Index reports that roughly half of licences go unused in any given month, and that spend per employee is still climbing. Those figures come from larger organisations, but the mechanism is identical in a thirty-person company — it just has fewer zeros.

The half-day version

You do not need a management platform to do the first pass. You need four exports and a spreadsheet.

  1. Export your user list from Microsoft 365, Google Workspace or whatever your identity provider is. Include last sign-in date and assigned licence.
  2. Compare it against payroll. Every account that does not map to a current employee, contractor or shared function is a question. Most of them will be leavers.
  3. Sort by last sign-in. Ninety days of no activity on a paid seat is a candidate for removal or downgrade. Check before cutting: some are legitimate service accounts, and those should be labelled as such so this exercise is faster next time.
  4. Pull twelve months of card and bank statements and list every recurring software charge. Anything that appears there but not in your identity provider is shadow IT — usually harmless, occasionally holding customer data nobody knows about.
  5. Map duplicates by category. Storage, chat, video calls, project tracking, e-signature, note-taking. Pick one canonical tool per category and give the others a decision date.

In one recent audit, the leaver accounts alone accounted for eleven percent of the monthly bill. Downgrading two premium tiers nobody used a feature of added a little more.

Savings from tidying licences often cover a good part of a managed IT retainer. That is a fair way to judge one.

What we usually find, in rough order of size

FindingWhy it happensTypical fix
Seats for people who leftOffboarding stops at email and door accessA checklist that covers every paid tool, not just the obvious two
Premium tiers used as standardBought during a project, never reviewedDowngrade the majority, keep premium for the few who need it
Duplicate toolsDepartments bought independentlyOne canonical tool per category, migrate the rest
Growth seats never filledNegotiated for a headcount that did not arriveRight-size at renewal, in writing, before auto-renewal fires
Forgotten infrastructureA test VM, an old backup bucket, a staging environmentTag everything with an owner; delete what has no owner

The part that is not about money

An account for someone who left in 2024 is not merely a wasted seat. It is a valid credential, usually with a password that has never been rotated, frequently without multi-factor authentication, and — critically — nobody is watching it, because nobody expects it to be used. Attackers look for exactly this.

That is the same access hygiene problem that sits underneath the invoice fraud case we wrote up in this article. A licence audit and an access review are the same exercise looked at from two directions, which is why we do them together.

While you are in there, note which accounts hold personal data. Under the Data Protection Act 2017 you are expected to be able to describe your processing and to hold data no longer than needed — a tool nobody has opened in a year, still full of customer records, is a compliance question as well as a cost one.

Making the saving stick

Most companies do this exercise once, cut thirty seats, and are back where they started eighteen months later, because nothing changed in how tools get bought and how people get offboarded. Three things make it durable:

What not to cut

Two cautions, because we have seen enthusiastic tidying cause real damage. Do not cut backup, endpoint protection or multi-factor authentication licences to make the number look better — those are the ones you are paying for precisely because you cannot see them working. And do not downgrade a tier without checking which feature the finance or compliance team actually relies on; audit logs and retention policies frequently live in the higher tier for exactly that reason.

One local note: most of these bills are denominated in US dollars or euros. A stable-looking subscription can grow eight or nine percent in rupee terms without anyone changing anything, so review the rupee figure, not the vendor's number.

Frequently asked questions

How long does the first audit take?

Half a day for a business under fifty people, assuming the exports are available. The follow-up quarterly review is under an hour.

Will the vendor refund unused seats?

Rarely mid-term, commonly at renewal. That is why the sixty-day reminder matters — the conversation is much easier before the renewal date than after it.

Should we buy a SaaS management platform?

Not below a few hundred employees. The spreadsheet and the identity provider export will find nearly all of it, and the platform's cost is often a meaningful share of the waste you are trying to remove.

Do you do this as part of a retainer?

Yes — at onboarding, then once a quarter, with the figures in the monthly report so you can see whether the tidying held. Book a call and the first audit is free.

Sources

  • Zylo, SaaS Management Index (2025 and 2026 editions) — unused licence rates and spend per employee.
  • Gartner analysis on unused entitlements and overlapping SaaS tools, as reported in industry summaries, 2025.
  • Data Protection Act 2017 (Mauritius), retention and accountability obligations — Data Protection Office.

Recognise your own setup in this?

The free audit takes an hour and you keep the write-up.

Book a call

Keep reading