Tenant inventoryKnow which SaaS environments exist and who owns them.
Start with an inventory of sanctioned SaaS applications and tenants, their business owner, technical administrator, identity source, authentication method, privileged roles, sensitive data classes, external sharing capability, integrations, logging path, backup/export options, and contract owner. Include enterprise platforms and smaller applications purchased directly by departments.
Shadow SaaS is partly an identity problem and partly a procurement problem. Use expense data, SSO discovery, browser or CASB telemetry where available, vendor-management records, and interviews to find applications that bypass the normal onboarding path. The objective is not to ban every unsanctioned tool; it is to establish ownership and decide whether the risk is acceptable.
Classify applications by consequence so governance is proportional. A low-risk survey tool should not receive the same review burden as a platform containing regulated records, source code, privileged infrastructure access, financial data, or enterprise communications.