A single reclamation sweep works because it has a deadline and an owner for that one moment: someone is told to clean up the stack before a renewal, so they do. The problem is what happens the week after. New hires get provisioned. Employees change roles and keep their old tool access on top of new access. Projects wind down and nobody remembers to cancel the seat. Contractors roll off engagements without an offboarding trigger. None of that stops because a spreadsheet audit happened in March.
Zylo's 2026 SaaS Management Index found that the average organization uses only 54 percent of its provisioned software licenses, meaning close to half of what companies pay for sits idle at any given time. That number does not represent a one-time backlog. It represents a steady state that most companies regenerate every year because nothing structural changed after the last cleanup. Gartner estimates that global enterprises spent more than $300 billion on SaaS in 2025, and that roughly a quarter of that spend goes to unused or underused software, a waste figure in the $60 billion to $100 billion range across the market.
For a mid-market company, the pattern is the same at a smaller scale. A company spending $2 million a year on vendor software that sits at Zylo's average utilization rate is carrying $900,000 or more in idle licenses at any point in the year. A one-time audit might recover a third of that in a single push. Without a process to keep it recovered, most of it comes back within twelve months, because the underlying causes (unmanaged provisioning, silent offboarding gaps, and no standing review cadence) were never addressed.
A reclamation process that survives past the first quarter needs four things a single cleanup does not: a named owner for every application, thresholds that are applied automatically rather than judged case by case, a fixed review cadence, and a way to measure whether it is actually working. Skip any one of these and the process degrades back into an occasional manual effort.
The rest of this guide walks through how to build each piece.
The most common reason reclamation stalls is that no single person is accountable for a given tool's utilization. IT manages provisioning and access, but IT rarely has visibility into whether a marketing tool or a sales tool is being used productively. The business unit that requested the tool usually does have that visibility, but has no formal role in license governance.
Assign a named business owner to every application above a minimum spend threshold, commonly $5,000 to $10,000 a year for mid-market companies. That owner is responsible for confirming utilization at each review cycle, approving or rejecting reclamation candidates flagged by the process, and signing off before a seat reduction goes to the vendor. IT or finance owns the mechanics (pulling usage data, tracking the calendar, executing the reduction), but the business owner owns the judgment call on whether a flagged seat is genuinely unused or serves a purpose the usage data does not capture, such as a board member with infrequent logins or an integration account.
Without this split, reclamation efforts either stall waiting for business input that never arrives, or IT removes access unilaterally and creates friction when a legitimately low-frequency user gets locked out.
A process needs a rule, not a judgment call made fresh each quarter. The standard threshold used across SaaS management platforms is 90 days with no login for full reclamation review, and 60 days with a login but no meaningful feature engagement for a downgrade or utilization review. Applying these thresholds consistently, rather than deciding case by case what counts as "inactive," is what makes the process repeatable and defensible when a business owner pushes back on a specific removal.
Document the thresholds once, in writing, and apply them the same way for every application and every review cycle. Build in a documented exception process for accounts that are expected to be low-activity but still legitimate: seasonal staff, board members, backup admins, and service or integration accounts that do not log in through normal channels. Flagging those accounts once and marking them as permanent exceptions prevents the same conversation from repeating every quarter.
A concrete example: a 300-person company running the 90-day threshold across its top 15 applications by spend finds that of 2,400 total provisioned seats, 620 have had zero logins in the last 90 days. After exceptions (40 seats confirmed as legitimate low-frequency users), 580 seats, or roughly 24 percent of the total, are confirmed reclamation candidates. At an average cost of $45 per seat per month across the portfolio, that is just over $313,000 in annual recoverable spend from one review cycle, before any tier-downgrade savings on the accounts that stay active.
Employee offboarding is the single largest source of license waste that a quarterly review alone will not catch fast enough. Research from Beyond Identity on employee offboarding found that 89 percent of departing employees retain access to at least one work application after they leave, and separate industry surveys on offboarding practices have found that roughly a third of organizations take more than seven days to fully deprovision a departing employee across their full application stack. That gap is not just wasted spend, it is a security exposure: the same body of research found that a majority of organizations that experienced a data breach involving a former employee traced it back to incomplete offboarding.
A quarterly reclamation review will eventually catch an ex-employee's dormant license, but "eventually" might mean three months of paid, unused, unmonitored access. The fix is to make license deprovisioning a mandatory line item in the offboarding checklist HR and IT already run, not a separate process that depends on someone remembering to run a report later.
The practical version: when HR marks an employee as terminated, that event should automatically generate a checklist covering every application the employee had access to, based on the same identity and SSO data used for the quarterly review. Access removal (for security) and license removal (for cost) should happen in the same step, not two separate processes running on different timelines. Companies without single sign-on covering their full stack will need a manual cross-reference between the HR system and each application's active user list, which is exactly the step most informal reclamation efforts skip because it is tedious to do by hand every time someone leaves.
Reclamation tied only to renewal dates catches waste roughly once a year, per contract, which is too slow given how quickly team composition changes at a mid-market company. A quarterly cadence for the top applications by spend, independent of renewal timing, catches waste closer to when it happens and prevents a large backlog from building up before the next renewal conversation.
Monthly reviews are usually impractical at mid-market scale: the operational overhead of reviewing every application every month outweighs the marginal waste caught between quarters for most tools. The exception is the small number of highest-spend applications (typically the top five to ten by annual cost), where even a small percentage of waste represents a meaningful dollar figure and a monthly or continuous automated check is worth the effort.
A practical cadence: automated weekly or monthly detection for the top ten applications by spend, feeding into a quarterly business review where flagged seats are confirmed or exempted by the application owner, with the reclamation executed before the next billing cycle closes. This keeps the manual review burden concentrated on judgment calls rather than data-gathering, which is the part that should be automated in the first place.
The data-gathering half of reclamation (pulling login activity, cross-referencing against HR records, flagging seats past the inactivity threshold) is mechanical and should not depend on a person remembering to run it. Whether through a dedicated SaaS management platform or a lighter internal script pulling from your identity provider's login logs, automating detection is what turns a quarterly scramble into a standing report that is simply reviewed, not generated from scratch each time.
What should stay manual is the judgment layer: confirming that a flagged seat is genuinely unused, handling exceptions, and making the call on tier downgrades versus full removal for accounts with partial usage. Automating the judgment layer too aggressively (auto-removing access the moment a threshold is crossed, with no human review) creates the opposite failure mode: legitimate but infrequent users lose access without warning, which erodes trust in the process and invites business teams to route around it.
A process without visible output tends to lose institutional support after the person who built it moves to another project. Track and report, at minimum: total provisioned seats versus active seats by application, seats reclaimed per quarter, and dollars recovered per quarter, cumulative for the year. Put this in front of finance leadership on the same cadence as the review itself.
This does two things. It gives finance a concrete, recurring number to point to when justifying the operational cost of running the process, and it creates institutional memory that survives staff turnover on the team responsible for reclamation. A process that only exists in one person's head or one person's spreadsheet does not survive that person leaving the company.
Most mid-market companies that have never formalized reclamation sit in the ad hoc or reactive tiers. Moving from reactive to managed, the highest-leverage single step, typically comes from adding a fixed quarterly cadence and a named owner per application, before any tooling investment is required.
For a mid-market company relying on existing admin dashboards and manual HR cross-referencing, the direct cost is primarily staff time: typically 4 to 8 hours per quarter per major application during the first two review cycles, dropping as the process stabilizes. Dedicated SaaS management platforms that automate detection typically run $3 to $8 per managed user per month, which for a 300-person company is roughly $11,000 to $29,000 a year, an investment that usually pays for itself several times over given average waste rates above 30 percent for companies with no formal process.
A renewal-triggered audit catches waste once per contract, once a year at best, and only for that specific vendor. A standing process catches waste continuously across the whole portfolio, independent of any single renewal date, and closes the gap between when an employee leaves or a project ends and when the license actually gets reclaimed. Renewal-only audits also tend to disappear the year staff turnover disrupts institutional memory of who was supposed to run them.
Ninety days with zero logins is the standard threshold used across SaaS management platforms and is conservative enough to avoid flagging legitimate low-frequency users. Sixty days is a reasonable secondary threshold for flagging accounts with logins but no meaningful feature engagement, which are downgrade candidates rather than removal candidates. Apply the threshold the same way across every application rather than setting a different bar for each tool.
Neither should own it alone. IT typically owns the technical mechanics of pulling usage data and executing access changes, and finance typically owns tracking the dollar impact and reporting it upward, but the judgment call on whether a specific flagged seat is truly unused belongs to the business owner who requested that application in the first place. Splitting ownership this way is what prevents the process from stalling on missing context or creating friction from unilateral removals.
It generally strengthens it. Vendors negotiate more seriously with buyers who show up with documented, current usage data rather than the contracted seat count, because it removes the ambiguity around what the buyer actually needs. A standing reclamation process means that data is already current at any point in the year, rather than something assembled hastily in the weeks before a renewal deadline.
Procr
See what Procr does with your real vendor portfolio.