SaaS Sprawl: What Your Tool Stack Really Costs
SaaS sprawl costs more than licenses: wasted seats, integration upkeep, security exposure, and attention. A practical audit method to find the real number.
Ask a finance lead what the company spends on software and you'll get a number. Ask them how many tools the company actually uses and you'll get a guess — and industry surveys of IT asset managers consistently find those guesses run 2–3x low once someone pulls the credit card statements, the expense reports, and the single-sign-on logs. The marketing team's $49/month scheduling tool, the design contractor's file-sharing plan, the project tracker one team adopted during a crunch two years ago and never canceled: none of it shows up until someone goes looking.
That's sprawl. And the subscription fees are the smallest part of what it costs. The real bill is paid in four currencies — licenses, integration labor, attention, and risk — and only the first one appears on an invoice. This post walks through all four, then gives you a one-week audit method to put an actual number on your stack.
The Four Ledgers of Tool Cost
Every tool in your stack runs up charges on four separate ledgers:
| Ledger | What it contains | Who pays it | Shows up in accounting? |
|---|---|---|---|
| Licenses | Seats, tiers, overlapping subscriptions | Finance | Yes, scattered |
| Integration | Connecting, syncing, maintaining, working around | IT + whoever "owns" each tool | No — buried in salaries |
| Attention | Switching, searching, re-finding context, duplicate updates | Every employee, daily | Never |
| Risk | Access sprawl, unvetted vendors, offboarding gaps, audit scope | Security, legal, eventually everyone | Only after an incident |
Most cost-cutting exercises only ever touch the first ledger, which is why they disappoint: trimming 15% of seats while leaving 30 tools in place saves money without making anything better. The audit at the end of this post measures all four. First, what actually lives in each.
Ledger One: License Waste
License waste isn't one problem. It's five distinct problems, and they respond to different fixes.
1. Unused seats
The classic. Someone left the company, changed roles, or tried the tool for a week in 2024. Their seat renews annually anyway. In stack audits, it is routine to find 20–40% of paid seats with no logins in the last 90 days, and the pattern is worst in tools bought by one team but billed centrally, because the buyer and the payer never compare notes.
Illustrative math for a 60-person company: 8 tools averaging $12/user/month, provisioned to everyone, with 30% of seats inactive. That's 60 × 8 × $12 × 12 = $69,120/year of licensing, of which roughly $20,700 buys nothing at all.
2. Tier waste
You're on the Business plan for a feature two people use, or that someone needed once for an export. Tier decisions are made at purchase time under sales pressure and almost never revisited. The gap between adjacent tiers is commonly 50–100% of the price.
3. Duplicate tools
Two teams solving the same problem with different products: marketing on one project tracker, engineering on another; three different whiteboard tools across four departments; both a wiki and a docs tool and a shared-drive folder all claiming to be "where documentation lives." Each duplicate doubles license cost and — worse — splits the company's information into silos that don't search each other.
4. Feature-overlap waste
Subtler than duplication: you pay for a full product whose job is already covered by 20% of another product you also pay for. A standalone survey tool when your workspace platform has polls. A standalone status-page-for-the-team tool when your project tracker has dashboards. Individually defensible, collectively absurd. This is the category consolidation targets, and it's usually the largest.
5. Zombie subscriptions
Nobody uses it. Nobody remembers buying it. It renews on a personal card that gets expensed, so no procurement review ever sees it. Zombies are small individually — $30 to $300 a month — but a 100-person company typically hosts a dozen of them.
The five types matter because the fix differs: unused seats need a deprovisioning habit, tier waste needs a renewal-time review, duplicates need a decision about which team changes tools, overlap waste needs consolidation, and zombies just need a cancellation email. Lumping them together as "software spend" is why they survive.
The one metric worth computing per tool
If you compute nothing else, compute cost per weekly active user: annual spend divided by the number of people who used the tool in a typical week. It reframes every conversation. A $15/user/month tool that everyone opens daily costs $180 per active user per year — cheap. A $6/user/month tool provisioned to 80 people that 9 people actually open costs $640 per active user — expensive, despite the smaller sticker. Sort your inventory by this metric and the shrink-and-kill candidates identify themselves. It's also the number that makes renewal negotiations concrete: walking into a renewal with "we pay for 80, we use 9" either cuts the seat count or cuts the price, and vendors know it.
Ledger Two: Integration Overhead
Every tool you add doesn't just cost its own price — it costs a connection to some subset of the tools you already have. The connections are where the quiet money goes.
Count the forms this takes:
- Initial integration setup. Someone configures the sync between the CRM and the project tracker, the tracker and chat, chat and the calendar. Each is a half-day to a week of somebody's time, usually IT or the most technical person on the buying team.
- Automation middleware. When native integrations don't exist, teams build chains in automation tools. These chains are software: they have bugs, they break when either vendor changes an API, and they have an unofficial maintainer whose departure is a small incident. Teams that go down this road far enough end up with a part-time job nobody applied for. We've written about that trap in Integration Fatigue: When Connecting Tools Becomes the Job.
- Sync-failure cleanup. Two systems both claim to hold the truth about a task, a contact, a date. They drift. A human reconciles them. This cost recurs weekly and is completely invisible because it looks like normal work.
- The human API. The most common integration in most companies is a person copying information from one tool and pasting it into another — status from the tracker into the update doc, numbers from the dashboard into the slide deck, decisions from the meeting notes into the tickets. If a weekly ritual on your team involves re-typing information that already exists somewhere else, you are paying an integration cost in salary.
A useful mental model: with n tools, the number of potential pairwise connections grows with n², while your team's capacity to maintain connections grows, at best, linearly. Ten tools have 45 possible pairings. You'll integrate maybe eight of them, badly, and the other 37 gaps get bridged by humans or not at all. This quadratic-connections problem is the strongest structural argument for fewer tools rather than better glue.
Ledger Three: The Attention Bill
The attention ledger is the one your team feels most and measures least. Every additional tool adds:
- Another inbox. Notifications, badges, digests, and @mentions in each product, each with its own settings, each demanding a check "just in case." Eight tools with even modest notification volume means an interruption every few minutes across the day.
- Another place to search. "Where's the doc about the pricing change?" now has six possible answers. Studies of knowledge work have repeatedly found that a meaningful slice of the workday — commonly estimated around a fifth — goes to searching for and re-gathering information, and fragmentation is a direct driver.
- Another context to reload. Task-switching research is unambiguous: switching carries a reorientation cost, and residue from the previous context degrades performance on the next one. When your workflow forces a tool hop every few minutes — check chat, update the board, find the doc, answer the comment — you pay that toll dozens of times a day. We put numbers and citations on this in Context Switching: The Tax Nobody Budgets For, but the short version: for a 50-person company, plausible assumptions put the annual attention bill in the hundreds of thousands of dollars, an order of magnitude above the license line.
- Duplicate narration. The same update posted in chat, summarized in the status doc, and re-explained in the standup — because the people who need it live in different tools. Sprawl doesn't just fragment information; it multiplies the work of publishing it.
You cannot capture this ledger precisely, and you don't need to. In the audit below you'll estimate it with one honest survey question, which is enough to rank it against the license line — and it will rank above it.
Ledger Four: Security and Compliance Surface
Every tool is a door. Sprawl means doors nobody is watching:
- Offboarding gaps. When someone leaves, IT deactivates the accounts it knows about. The tools bought on a team card, outside SSO, keep the departed employee's access until someone notices. Ask your IT lead how confident they are that a leaver's access to all tools is revoked within a day. The pause tells you the ledger balance.
- Unvetted vendors holding real data. That free tier the team adopted in an afternoon has your customer list, your roadmap, or your unreleased designs — and never went through security review, so nobody has read its data-processing terms. Sprawl and shadow IT are the same phenomenon seen from different desks.
- Access-review scope. SOC 2, ISO 27001, and most enterprise-customer questionnaires require you to enumerate systems and review access. Every tool multiplies that work. Compliance teams routinely find that cutting the tool count is cheaper than automating reviews across a long tail of small vendors.
- Attack surface. More vendors means more places credentials live, more OAuth grants with broad scopes, more breach-notification emails to triage. None of this is hypothetical; it's the standard mechanics of how small-vendor breaches turn into your incident.
The risk ledger rarely drives a consolidation decision on its own, but it consistently breaks ties — and it's the ledger your board will ask about after the fact.
The Audit: One Week, One Spreadsheet
You don't need a software-asset-management platform to get 90% of the value. You need a spreadsheet, five days of part-time effort, and the willingness to send two slightly awkward emails. Here's the method.
Day 1: Build the inventory
Create a sheet with one row per tool and these columns:
| Column | Where it comes from |
|---|---|
| Tool name | — |
| What job it does (one phrase) | You / the owner |
| Owner (a person, not a team) | Ask around; blank is a finding |
| Annual cost | Finance |
| Billing route (invoice / card / expensed) | Finance |
| Paid seats | Admin console |
| Active seats, last 90 days | Admin console or SSO logs |
| Renewal date | Contract or card statement |
| Holds sensitive data? (Y/N) | Owner + security |
| In SSO? (Y/N) | IT |
| Overlaps with (other rows) | Filled in Day 3 |
Populate it from four sources, in this order: the finance system's vendor list, 12 months of corporate-card statements, a search of expense reports for common SaaS vendors, and your SSO or Google Workspace third-party-app report. The fourth source is where the surprises live.
Day 2: Send the amnesty email
You will not find everything from records, because some tools are on personal cards or free tiers. Send the whole company a short note:
"We're doing a tool inventory — not a crackdown. If you or your team uses any app for work that isn't on this list, reply and tell me what it does for you. Nothing gets canceled without talking to the people who use it."
The amnesty framing matters. If people expect their tool to be confiscated, they'll stay quiet and you'll inventory a fiction. Expect the list to grow 30–50% from this step, mostly free tiers — which cost no money and still charge the attention and risk ledgers.
Day 3: Map the overlaps
For each row, fill in the "overlaps with" column by job, not by category. The question is not "are these both project tools?" but "could the job in column two be done, today, by another tool we already pay for?" Be concrete: "team polls — covered by workspace platform," "video review — covered by proofing feature," "status reporting — covered by dashboard widgets." You are building the raw material for a consolidation decision, and honest overlap mapping is the whole game. (The follow-through — sequencing migrations, managing the change — is its own discipline; see The Tool Consolidation Playbook.)
Day 4: Estimate the invisible ledgers
Two quick instruments:
- Integration census. List every integration and automation chain you know of, plus every recurring copy-paste ritual anyone can name. For each, estimate hours per month of setup amortization, maintenance, and reconciliation. Multiply by a loaded hourly rate. Rough is fine; you're establishing magnitude.
- One survey question. Ask everyone: "In a normal day, how many different work apps do you open, and how much time do you lose to hopping between them and hunting for things across them — under 15 minutes, 15–45, or over 45?" Take the midpoints, multiply by headcount, working days, and loaded rate. It's an estimate built from self-report, and it will still be the biggest number in the audit.
Day 5: Total the ledgers and write the one-pager
Sum four numbers: annual license spend (with the waste share highlighted), estimated integration hours in dollars, the attention estimate, and a count-based risk summary (tools outside SSO, tools holding sensitive data without review, tools with no owner). Put them side by side on one page. In almost every audit we've seen or run, the ordering is: attention > integration > licenses > (unpriced) risk — the exact inverse of where organizations aim their cost-cutting.
Reading the Results: Kill, Shrink, Consolidate, Keep
Every row in your inventory lands in one of four buckets:
- Kill. Zombies, tools with no owner and no active users, free tiers holding company data with no job. Cancel, export data, revoke OAuth grants. This bucket needs no meetings — just a two-week notice window in case the amnesty missed someone.
- Shrink. Real tools, wrong size. Cut inactive seats, drop a tier, move from everyone-provisioned to request-based provisioning. Do this at renewal for contract tools, immediately for monthly ones. This is the fastest money: most teams recover 15–25% of license spend from this bucket alone without changing anyone's workflow.
- Consolidate. The overlap clusters from Day 3 — typically chat + social feed + project tracking + docs + wiki + whiteboard + surveys scattered across five to eight products whose jobs one platform can cover. This bucket is where the attention and integration ledgers actually improve, because killing a tool kills its inbox, its search silo, and its sync chains all at once. It's also the bucket that requires real change management, so it gets a project, not an email. This is the problem Openbook exists for: rooms cover the feed, boards, docs, wiki, whiteboard, Q&A, and check-in jobs in one searchable workspace, so a typical consolidation cluster maps onto one tool instead of a smaller number of several. The compare pages walk through the specific tool-by-tool mappings.
- Keep. Tools doing a specialized job well, with active usage, an owner, and no meaningful overlap. Your accounting system, your code host, your design tool. Write their names down with their jobs — the keep list is as valuable as the kill list, because it defines what "our stack" officially means.
Sequence the buckets in that order. Kill and shrink fund the effort and build credibility ("this audit already saved $40k") before you ask anyone to change tools.
Keeping Sprawl From Growing Back
Sprawl is a ratchet: every tool arrives with an advocate, and every removal requires a project. Without a countervailing mechanism, your stack in 18 months will look like your stack today plus six tools. Three mechanisms, none heavier than the problem deserves:
- A tool ledger with an owner. The audit spreadsheet becomes a living document. Every tool has a named owner, a job description, and a renewal date. New tools don't get expensed until they have a row. This is a 10-minute-a-month habit, not a procurement bureaucracy.
- A "what does this replace?" rule. Any new tool request must name either the tool it replaces or the currently-unmet job it does. "It's better than what we have" must answer "then which rows does it delete?" Most sprawl comes from additions that were never asked this question.
- A renewal calendar with a 60-day alarm. Tier waste and unused seats survive because renewals auto-fire silently. A calendar reminder 60 days before each renewal, assigned to the tool's owner, with three questions — active seats? right tier? still no overlap? — catches almost everything the annual audit would.
And re-run the light version of the audit yearly. Day 1 and Day 3 only, one afternoon, against the ledger you already have.
Next Steps
The whole method, compressed:
- Pull the vendor list, card statements, and SSO app report into one spreadsheet this week.
- Send the amnesty email. You're not cracking down; you're counting.
- Map overlaps by job, not category.
- Estimate the integration and attention ledgers — rough numbers beat no numbers.
- Sort every row into kill / shrink / consolidate / keep, and execute in that order.
- Install the ratchet-breakers: tool ledger, replacement rule, renewal alarms.
The license line you can see is real money. The three ledgers you can't see are bigger. An audit that takes one person a week routinely surfaces five figures of direct waste and a consolidation case worth several times that — which is a better return than almost anything else on your ops backlog.
When you get to the consolidate bucket and start mapping five or six overlapping tools onto one workspace, that's exactly the job Openbook was built for — 18 room types covering feeds, boards, docs, wikis, whiteboards, check-ins, and more, so your team assembles what it needs and cancels the rest. It's free to start, and the audit spreadsheet will tell you precisely which subscriptions pay for it.