The defining feature of the software-as-a-service era was that buying it required almost nothing. A department head with a corporate card could adopt a tool on Tuesday and have the team using it by Friday, without a procurement cycle, a security review or a line in anyone's budget beyond their own.

That property is what made the category enormous, and it is what produced the situation most large companies are now working through: portfolios of hundreds of applications, assembled by people acting sensibly in isolation, that nobody ever evaluated as a whole.

The audit nobody wanted to run

The first discovery in any consolidation exercise is that the inventory is wrong. Companies routinely find substantially more active subscriptions than their systems record, because the purchases that bypassed procurement also bypassed the asset register. Duplicate categories are the norm: several project trackers, multiple video tools, overlapping analytics.

The waste is real but smaller than the headline numbers suggest, and honest programs say so. Unused licenses and abandoned tools are the easy recovery, and they are largely one-time. The durable savings come from consolidating overlapping categories onto single vendors with negotiated enterprise agreements, which is slower, requires migrating people off tools they like, and generates the political friction that made departmental purchasing attractive in the first place.

Integration cost is the part that surprises finance. Each additional tool in a portfolio carries an obligation beyond its subscription: an identity integration, a data flow, a security review, an offboarding checklist. Those costs live in engineering and IT budgets rather than the software line, which is why a portfolio can look affordable in one spreadsheet while consuming disproportionate staff time in another. The same API infrastructure that made tools easy to connect also made the connections easy to accumulate without counting.

Security has been the effective forcing function. A sprawling portfolio is a sprawling attack surface, and every application holding company data is a vendor whose own security posture becomes the company's problem. Cyber insurance questionnaires now ask for application inventories, and being unable to produce one is itself an underwriting signal.

What is genuinely different this cycle is who is running the effort. Software consolidation used to be an IT initiative that departments resisted successfully. It is now typically owned by procurement or finance, with an explicit savings target, and it is being pursued alongside the same scrutiny being applied to cloud spending. Both are symptoms of one shift: technology costs that grew during a period when nobody had to justify them are being examined by people whose job is justification.

Identity is where the sprawl bites hardest, since every application is another integration to secure and another place a credential lives, which is part of why passkey rollouts move slowly in portfolios nobody has inventoried.

The overcorrection is predictable and already visible in places. Reimposing full procurement review on every software purchase reintroduces the exact delay that departmental buying routed around, and the teams affected will route around it again. The organizations getting this right are setting a threshold, below which purchasing stays fast and above which review is real, and accepting that some duplication is the price of a company that can adopt a tool in a week.

Topics technologysoftwareprocurementIT spendingcost

Technology Correspondent

Priya Natarajan

Priya Natarajan reports on artificial intelligence, enterprise software and the infrastructure behind the modern internet. Her work focuses on how technical decisions become business decisions.