Ask any mid-market company a simple question: how many software subscriptions are you paying for right now?

You will get three different answers from three different people. None of them will match the credit card statement.

That is the problem. Not the tools. The fact that nobody owns the list.

## How it happens

It never starts as a strategy. It starts as a credit card.

Marketing needs a scheduling tool, so somebody signs up for the $29 plan. Sales finds a prospecting app and puts it on their card. HR grabs an onboarding checklist during open enrollment. Nobody asks IT, because IT takes two weeks and the free trial ends Friday.

A year later you are paying for 40, 50, sometimes 80 recurring charges. Half the logins belong to people who quit two years ago. Three teams are paying for the same thing under different names. The bill grows every month and nobody is watching it.

I have audited companies where the real software spend was a third higher than anyone thought. Not because of one big purchase. Because of forty small ones nobody reviewed.

## What it actually costs

The obvious cost is money. The quieter costs are worse.

Every tool is a data silo. Customer info in one system, tickets in another, contracts in a third. When something breaks, nobody can reconstruct the full picture, because the picture is scattered across logins nobody remembers.

Every tool is a security exposure. Each subscription is another set of credentials, another integration with your email, another vendor with access to your data. You cannot secure accounts you do not know exist. And the ex-employee whose login still works? That is not a billing problem. That is a breach with a calendar date on it.

Every tool is a dependency. When the vendor raises prices, changes terms, or shuts down, you find out when the invoice bounces or the app goes dark. No contract on file. No backup plan. Just a surprise.

## The 30-minute audit

Here is the part you can do this week. Pull the last three months of every corporate card and bank statement. Highlight every recurring software charge. Put them in one spreadsheet with four columns: what it is, who signed up, who uses it now, and what it costs per year.

Then ask three questions about each line.

One, do we still use this? Two, is someone else here paying for something that does the same thing? Three, who is the owner, by name, who renews or cancels it?

You will cancel 10 to 20 percent of the list on the spot. You will consolidate another chunk. And you will find at least one account still active for someone who left the company. Every time. I have never run this exercise without finding a ghost login.

Then assign one person as the owner of the list. Not a committee. One name. Every new subscription goes through them before the card gets charged. That is the whole governance model. It fits on an index card.

## The bigger point

SaaS sprawl is not a technology problem. It is a discipline problem. The same company that requires three signatures to buy a printer lets anyone with a corporate card commit the company to a vendor relationship for years.

The fix is not a procurement bureaucracy. It is one list, one owner, and a review once a quarter. Thirty minutes of attention saves thousands of dollars and closes security holes you did not know were open.

You cannot govern what you cannot see. Start by seeing the list.

---
Not sure where your IT really stands? [Start with a Clarity Audit](https://clearstackadvisory.com/clarityaudit): a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.
---
**About the author:** [Chris McGlasson](https://clearstackadvisory.com/aboutus) is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.