We'll be at Xerocon Denver 2026, on August 19 - 20. See you there!

Blog

Find Every Saving: How to Audit a Client’s Software Stack

Arun Kiran|

If you manage software spend for clients — as an MSP, IT consultant, or fractional procurement lead — you already know the pattern: every client insists their SaaS stack is “under control,” and every audit proves otherwise. Between shadow IT, forgotten renewals, and duplicate tools bought by different departments, the average software audit turns up savings nobody expected. Here’s a repeatable process for finding every one of them.

Step 1: Build a Complete Application Catalog

You can’t manage spend on what you can’t see. Start by building a full application catalog — every piece of software the client is paying for, not just what’s in the finance system.

Three sources typically surface the full picture:

  • Expense and card data — pull 12 months of transactions and flag anything recurring
  • SSO and identity logs — apps connected via Google Workspace, Okta, or Microsoft Entra reveal tools employees log into but finance never approved
  • Browser extension and network traffic scans — this is where you’ll catch true shadow IT

This last step matters more than most audits admit. Studies consistently show that unsanctioned tools make up a large share of a company’s real software footprint. Defining shadow IT simply as “software used without IT’s knowledge or approval” undersells the risk — it’s not just a visibility gap, it’s an unmanaged attack surface and a compliance liability. Modern shadow IT risks extend to shadow AI too: employees quietly connecting free-tier AI tools to company data, invisible to any license management software you’ve deployed.

Step 2: Reconcile Licenses Against Actual Usage

Once you have the catalog, the real savings hunt begins. For every tool, answer one question: how many licenses are being paid for versus how many are actually used?

This is where software asset management tools and SAM/ITAM practices earn their keep. Pull login and activity data for each application and compare it against seat counts. In almost every audit, you’ll find:

  • Licenses assigned to employees who left the company
  • Seats bought in bulk “for growth” that never got assigned
  • Duplicate tools solving the same problem in different departments (two design tools, three project management platforms)

A dedicated SaaS management platform automates this reconciliation instead of forcing you through spreadsheets and export files — which matters when you’re auditing multiple clients and need it to scale.

Step 3: Audit Contracts, Not Just Costs

SaaS contract management is where the biggest single-line savings usually hide. Pull every contract and check for:

  • Auto-renewal dates — flag anything renewing in the next 90 days
  • Tiered pricing thresholds — clients often pay for a tier above what usage requires
  • Vendor group buying power — many spend management platforms and reseller software programs negotiate volume discounts clients aren’t aware they qualify for
  • Redundant overlapping contracts — the same capability purchased twice under different vendor names

This is also the moment to build a SaaS renewal playbook for the client going forward: a simple calendar of renewal dates, notice periods, and the person responsible for the renew/cancel decision. Without one, the client falls right back into the same sprawl within a year.

Step 4: Rationalize the Application Portfolio

With usage and contract data in hand, run application rationalization: rank every tool by cost, usage, and business criticality, then sort into keep, consolidate, or cut.

Application rationalization benefits go beyond the obvious cost cuts. Consolidating overlapping tools also reduces the attack surface, simplifies onboarding/offboarding, and gives IT a single source of truth instead of a dozen semi-used platforms. This step is where SaaS operations management shifts from reactive cleanup to an ongoing discipline — SaaS ops isn’t a one-time project, it’s a function.

Step 5: Set Up Chargeback or Showback

Once the stack is rationalized, the audit’s value compounds if the client adopts chargeback or showback going forward. The chargeback vs showback decision comes down to accountability style:

  • Showback reports departmental software costs without billing them internally — good for building awareness
  • Chargeback actually bills the cost back to the owning department or cost center — good for driving behavior change

Either model, layered on top of a SaaS management system, keeps future sprawl from creeping back in. It also gives you, as the auditor, an easy way to prove ongoing ROI in every subsequent review.

Step 6: Report the Savings — and the Risk

Close the audit with a report that separates two categories clearly:

  1. Hard savings — unused licenses, downgraded tiers, cancelled duplicate tools, renegotiated contracts
  2. Risk reduction — shadow IT eliminated, compliance gaps closed, license management centralized

Clients remember the dollar figure, but the risk reduction is often what keeps them coming back for the next audit cycle. A software stack audit isn’t a one-time engagement — it’s the first pass of an ongoing SaaS spend optimization relationship.


The takeaway: every software stack audit follows the same shape — see everything, reconcile usage, scrutinize contracts, rationalize the portfolio, and put accountability structures in place so the savings stick. Do this consistently across clients, and the audit itself becomes a repeatable, sellable service rather than a one-off favor.