# SaaS Management

Published articles for SaaS Management.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## 5 ways to optimize AI costs and reduce wasted AI spend

DevFeed: [5 ways to optimize AI costs and reduce wasted AI spend](<https://devfeed.tech/articles/5-ways-to-optimize-ai-costs-and-reduce-wasted-ai-spend-1889.md>)

Original publisher: [Read original article](<https://1password.com/blog/5-ways-to-optimize-ai-costs>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [ai-models](<https://devfeed.tech/tags/ai-models.md>), [cost](<https://devfeed.tech/tags/cost.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article outlines ways businesses can reduce AI spending, including choosing less expensive models, overseeing AI agents, and identifying shadow AI.

### Source excerpt

The tokenmaxxing era has left companies grappling with an uncomfortable reality. Now that AI vendors have switched to usage-based billing models, businesses are facing sky-high bills, and IT and finance teams are under pressure to rein in spending without slowing down innovation. The logical first step is to locate areas where that spend is going to waste, but even getting visibility into usage can be overwhelming when it's spread across departments, users, models, vendors, and agents. If you're trying to track down wasted AI spend and find opportunities to optimize your tokens, it helps to start with some of the primary reasons why AI bills may balloon past your company's budget. Top ways to optimize your company's AI costs So IT and Finance teams can know where to focus their efforts, here are five of the most common sources of unexpected AI spend. 1. Stop defaulting to the most expensive model For businesses to optimize spend, they need a way of overseeing and enforcing which models are being used for what tasks. Different AI models can vary wildly both in their abilities and their cost, and many users default to flagship AI models without realizing that there are more affordable options that can accomplish their goals at a fraction of the cost. For instance, in a recent experiment run by Cursor, building a web browser from scratch cost $10,565 when using a top-tier flagship model, and $1,339 when using a mix of models, even though the end results were comparable in terms of quality. 2. Stop letting agents run without oversight As the Stanford Digital Economy Lab reported, AI agents are "uniquely expensive, consuming 1000x more tokens than code reasoning and code chat." Meanwhile, data from OpenRouter shows that the majority of tokens spent overall are being used by agents. Here's a scenario that's becoming familiar to many AI developers and builders: An agent is instructed to perform a certain task, but it fails. So it tries again, and fails. With each loop, it

## When AI adoption outpaces IT visibility

DevFeed: [When AI adoption outpaces IT visibility](<https://devfeed.tech/articles/when-ai-adoption-outpaces-it-visibility-1973.md>)

Original publisher: [Read original article](<https://1password.com/blog/when-ai-adoption-outpaces-it-visibility>)

Author: info@1password.com (Stephanie Torto)

Published: 2026-08-27T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Responsibility & Safety](<https://devfeed.tech/topics/responsibility-safety.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [ai-governance](<https://devfeed.tech/tags/ai-governance.md>), [cost](<https://devfeed.tech/tags/cost.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [models](<https://devfeed.tech/tags/models.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

1Password describes how fragmented vendor dashboards and consumption-based AI pricing made it difficult for IT to understand AI spending. It argues that IT should provide visibility and context for business and engineering leaders making budget and model decisions.

### Source excerpt

At 1Password, we started expanding our use of AI with a familiar IT playbook. We identified the problems we wanted to solve and the tools that could help us achieve those goals. The plan was straightforward: enable teams, move quickly, learn what worked, and build the visibility needed to manage the cost. Then the operating model changed. AI vendors introduced consumption-based pricing faster than our processes could keep up, leaving us with a distributed system of vendor-specific dashboards to track and manage our AI use. For IT, that created a new kind of chaos when it came to understanding how much we were spending on AI and where that budget was being used throughout the company. We had data spread across systems, but we didn't yet have a clear, shared answer. How IT teams can govern AI use IT teams are close to the tools and access patterns that shape AI usage. That gives IT an important role in AI spend decisions, and is no small part of why AI governance can become framed as an IT mandate. Budget and model decisions belong with the leaders who set business and engineering priorities, while IT's role is to provide the context those leaders need. In the face of the changing nature of AI governance, IT teams should focus on finding ways to make AI spend explainable, to give the company a more useful basis for making decisions. Visibility changes the conversation Previously, 1Password's IT team could see activity in individual vendor consoles, but each view covered only part of the picture. We spent too much time moving between systems and interpreting different definitions. By the time we exported data from one tool and combined it with another, the result was already out of date. When we started using AI Spend and Consumption Management in 1Password SaaS Manager, it felt like a breath of fresh air. We now had a shared view of AI usage and spend across vendors and teams, with detailed insights on users and models, meaning that we could better understand our budg

## How to survive the AI spend hangover

DevFeed: [How to survive the AI spend hangover](<https://devfeed.tech/articles/how-to-survive-the-ai-spend-hangover-1930.md>)

Original publisher: [Read original article](<https://1password.com/blog/how-to-survive-the-ai-spend-hangover>)

Author: info@1password.com (Jason Meller)

Published: 2026-08-06T00:00:00Z

Content type: opinion

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [AI, ML & Data Engineering](<https://devfeed.tech/topics/ai-ml-data-engineering.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [business](<https://devfeed.tech/tags/business.md>), [coding](<https://devfeed.tech/tags/coding.md>), [developers](<https://devfeed.tech/tags/developers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [llms](<https://devfeed.tech/tags/llms.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>)

### AI overview

The article argues that organizations need to control and measure AI and LLM spending, connecting token use to projects and return on investment. It also cautions that coding agents still require knowledgeable human direction and expert review.

### Source excerpt

It's 6:30am and you hear the door of the nightclub you've spent the last 8 hours inside shriek as it closes behind you. You watch bleary-eyed as an overly bright sunrise illuminates the business-suited people as they glide effortlessly along the sidewalk, their obnoxiously well-rested faces talking about work on their fully charged phones. You wonder, "Where did all the fun people go? And what happened to my wallet?" This feeling is what many CFOs, CTOs, CEOs, and AI program managers will imminently be experiencing in their board rooms, as they finally wake up to the realities that unrestricted and unmoderated AI use has wrought on their bottom lines and the stability of their core technical assets. You can already feel the party ending and the hangover setting in. The first warning sign came when Uber's engineering org burned through its annual AI budget by April, and then capped its engineers at $1,500 a month per tool. At Meta, an internal leaderboard nicknamed "Claudeonomics" turned token spend into a status game. The company was on pace to spend billions, and the CTO's eventual memo had to spell out that token usage on its own measures nothing. Two of the most sophisticated engineering organizations on the planet have arrived a half step ahead of where we will all be soon: facing down a shocking bill and scrambling to tie it to any real ROI. Worse, many organizations would be hard pressed even to say which teams spent their tokens, on which models, and on what projects. Tokens spent wisely on complex problems, and tokens burned writing personalized fanfic all look the same on an invoice. But untangling them just became an urgent priority for everyone who shares responsibility for their company's AI bill. Like any hangover, this one is going to hurt. But we don't have to wait for the club to close down to start sobering up. There are already lessons to be learned about the differences between the companies using AI responsibly and the ones that have just been pa

## Productiv shutdown: Switch to 1Password for durable AI and SaaS Management

DevFeed: [Productiv shutdown: Switch to 1Password for durable AI and SaaS Management](<https://devfeed.tech/articles/productiv-shutdown-switch-to-1password-for-durable-ai-and-saas-management-1947.md>)

Original publisher: [Read original article](<https://1password.com/blog/productiv-shutdown-switch-to-1password-for-durable-ai-and-saas-management>)

Author: info@1password.com (Evan Sandhu)

Published: 2026-08-05T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [SaaS Management](<https://devfeed.tech/topics/saas-management.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [shadow AI](<https://devfeed.tech/topics/shadow-ai.md>), [Unified Access](<https://devfeed.tech/topics/unified-access.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Extension](<https://devfeed.tech/topics/extension.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [automation](<https://devfeed.tech/tags/automation.md>), [browser](<https://devfeed.tech/tags/browser.md>), [extensions](<https://devfeed.tech/tags/extensions.md>), [policy](<https://devfeed.tech/tags/policy.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

Productiv is shutting down its SaaS management platform, prompting customers to move app inventory, spend, and usage data. The article presents 1Password SaaS Manager as an alternative with AI spend and consumption tracking, SaaS discovery beyond SSO, access governance, and lifecycle automation.

### Source excerpt

On August 2, 2026, Productiv told customers its SaaS management platform was shutting down on August 6, with account data deleted once access ended. Four days is not much time to pull years of app inventory, spend, and usage data out of a system you've come to depend on, especially with AI tools now adding a fast-moving new layer of spend and access to track on top of everything else. If you're facing that deadline, or just taking stock of what you'd do if your own platform disappeared tomorrow, here's why 1Password SaaS Manager is the strongest place to land. A Leader you can build on 1Password SaaS Manager is a Leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms, for both Completeness of Vision and Ability to Execute. That recognition reflects work we've been doing deliberately since acquiring Trelica in 2025. We've brought AI and SaaS discovery into our broader Unified Access platform, alongside the credentials, identities, and access controls that secure every application in a portfolio. Built for how AI and SaaS actually get used today We recently launched AI Spend and Consumption Management inside SaaS Manager, giving IT and finance teams a normalized view of AI token usage by vendor, team, and model, with burn-rate alerts before prepaid budgets run out. AI is quickly becoming the least governed, fastest-growing corner of the software portfolio, and we built that governance directly into SaaS Manager rather than bolting it on as a separate tool. It's one of several capabilities that set SaaS Manager apart: Discovery that goes beyond SSO: SaaS Manager continuously discovers apps across identity providers, SSO logs, finance systems, browser extensions, and 1Password Enterprise Password Manager vaults, surfacing the unmanaged SaaS and shadow AI tools that SSO-only discovery misses. Governance you can act on: Discovery is anchored to credentials and sign-ins, so IT can revoke access and enforce strong authentication even for apps outside SSO,

## How CFOs can manage AI costs and prove business value

DevFeed: [How CFOs can manage AI costs and prove business value](<https://devfeed.tech/articles/how-cfos-can-manage-ai-costs-and-prove-business-value-1928.md>)

Original publisher: [Read original article](<https://1password.com/blog/how-cfos-manage-ai-costs>)

Author: info@1password.com (Greg Henry)

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Strategy](<https://devfeed.tech/topics/ai-strategy.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-adoption](<https://devfeed.tech/tags/ai-adoption.md>), [billing](<https://devfeed.tech/tags/billing.md>), [business](<https://devfeed.tech/tags/business.md>), [business-value](<https://devfeed.tech/tags/business-value.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [finance](<https://devfeed.tech/tags/finance.md>), [management](<https://devfeed.tech/tags/management.md>), [real-time](<https://devfeed.tech/tags/real-time.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>)

### AI overview

The article explains how CFOs and Finance teams can manage unpredictable AI spending by gaining earlier visibility into usage, forecasting budget risk, assigning ownership, and connecting AI investments to measurable business outcomes. It highlights consumption-based pricing, changing model costs, and delayed reporting from IT and vendor dashboards as key challenges.

### Source excerpt

Earlier this year, a bill arrived from one of 1Password's AI vendors for 5x the value of the original contract. The initial agreement came in below a certain threshold, so it never reached the right approvers for review. By the time it did, we had a much clearer understanding of how quickly AI costs can add up. This unpleasant surprise revealed a structural gap between IT, Finance, and end users when it came to AI billing and consumption. Although Finance was accountable for the budget, it had no way to see what was being spent on AI until it was already spent. Other CFOs are seeing the same pattern of a bill arriving that no one can explain. Now, as leaders grapple with soaring and unpredictable token costs, what was considered a budget line item just a few months ago has become a board-level topic. Managing AI costs requires Finance and IT to share visibility into consumption before the invoice arrives. Organizations need a way to track usage, forecast budget risk, assign ownership, and connect AI investments to measurable business outcomes. Why AI costs are harder for Finance to forecast Effective Finance and IT are built on predictability: per-seat SaaS contracts, annual budget cycles, and predictable renewal dates. Contracts with AI vendors are fundamentally different. They're based on consumption pricing, which scales with usage, not headcount. As AI usage grows across a team or department, the bill can literally grow overnight. The closest comparison is cloud, which also uses consumption pricing. Cloud sprawl took years to bring under control, but Finance eventually learned to model it. With AI, there is no time for a learning curve. Pricing tiers change constantly, new models ship overnight, and AI adoption continues to accelerate. Why Finance sees AI overspend too late While Finance is responsible for AI spend management, the tools Finance relies on weren't designed to provide real-time visibility. Getting a complete picture requires going through the IT te

## The tokenmaxxing bill is due: Take control of AI spend with SaaS Manager

DevFeed: [The tokenmaxxing bill is due: Take control of AI spend with SaaS Manager](<https://devfeed.tech/articles/the-tokenmaxxing-bill-is-due-take-control-of-ai-spend-with-saas-manager-1962.md>)

Original publisher: [Read original article](<https://1password.com/blog/take-control-of-ai-spend-with-saas-manager>)

Author: info@1password.com (Evan Sandhu)

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [App](<https://devfeed.tech/topics/app.md>), [Software](<https://devfeed.tech/topics/software.md>), [coding](<https://devfeed.tech/topics/coding.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [coding](<https://devfeed.tech/tags/coding.md>), [cost](<https://devfeed.tech/tags/cost.md>), [pricing](<https://devfeed.tech/tags/pricing.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

The article examines how consumption-based AI pricing can cause unexpected token costs, making AI spending difficult for finance, IT, and AI program leaders to monitor and control. It contrasts AI usage with traditional per-seat SaaS pricing and highlights risks such as expensive model changes, unsupervised coding agents, and unmonitored agentic workflows.

### Source excerpt

A nasty shock is hitting finance leaders across every industry right now: AI token bills that run ten, twenty, even a hundred times over what they forecasted, blowing holes straight through quarterly budgets. These leaders are all asking the same questions: How could this happen if they didn't approve it? Why didn't any of their systems alert them to the spike? And most importantly, what can they do now? Yes, your company's leaders told your engineering team to use AI. They told everyone to use AI, for everything. Build faster, ship more, and become "AI-native." The workforce did exactly that, and somewhere over the past three months, a few teams multiplied their token usage, a default model got swapped for a pricier frontier one, and a prepaid balance meant to last the year was gone by the first quarter. This is what happens when tokenmaxxing catches up to you. For the past two years, AI tools have largely operated on an unspoken unlimited plan: experiment freely, burn tokens, figure out ROI later. That's starting to change, because the bill is coming due in a way traditional software never required. AI tools don't behave like the SaaS apps that came before them. A traditional app is priced per seat, so your headcount tells you your bill. AI is increasingly priced by consumption: every prompt, model call, automated workflow, and autonomous agent, all add to the meter. This leaves IT, finance, and AI program leaders asking three questions they often can't answer with any confidence: How much are we spending on AI? Who is driving the cost? How can I make my runway last? The unique challenges of managing AI budgets AI spend is uniquely difficult to see and control, in ways that even seasoned procurement and FinOps teams haven't had to manage before. Usage compounds fast and often silently. A vendor can quietly shift your default model to a more expensive tier in the middle of a billing cycle, and unless someone happens to notice, every request from that point on costs

## 1Password is a Leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms

DevFeed: [1Password is a Leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms](<https://devfeed.tech/articles/1password-is-a-leader-in-the-2026-gartner-magic-quadranttm-for-saas-management-platforms-1921.md>)

Original publisher: [Read original article](<https://1password.com/blog/gartner-leader-saas-manager>)

Author: info@1password.com (1Password)

Published: 2026-06-23T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [SaaS Management](<https://devfeed.tech/topics/saas-management.md>), [shadow AI](<https://devfeed.tech/topics/shadow-ai.md>), [MCP Server](<https://devfeed.tech/topics/mcp-server.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [mcp-server](<https://devfeed.tech/tags/mcp-server.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [security](<https://devfeed.tech/tags/security.md>), [shadow-ai](<https://devfeed.tech/tags/shadow-ai.md>)

### AI overview

1Password announces that it has been recognized as a leader in the 2026 Gartner Magic Quadrant for SaaS Management Platforms. The article presents SaaS Manager as a way for IT and security teams to discover unapproved AI use, monitor applications and spending, identify token-budget overruns, govern access outside SSO, and automate governance workflows through an MCP Server.

### Source excerpt

Recognized for Completeness of Vision and Ability to Execute 1Password has been recognized as a leader in the 2026 Gartner® Magic Quadrant™ for SaaS Management Platforms. SaaS Manager gives IT and security teams visibility into unapproved AI use and every app, AI tool, and dollar spent across their organization. This foundation lets teams identify real-time AI token overruns before mid-year budget surprises hit, cut wasted license spend, and reduce friction for employees requesting access. The platform closes the access gaps that happen outside of SSO, governing human access across the full employee lifecycle and enabling AI agents to automate governance workflows through an MCP Server. We believe our placement in the Gartner® Magic Quadrant™ reflects our vision that with the right controls, SaaS management can help a business move faster. Get the full analysis [Read the Gartner® Magic Quadrant™ for SaaS Management Platforms](https://1password.com/resources/gartner-magic-quadrant-saas-management-platforms-2026) Identity Access Management doesn't show the full picture of AI token consumption and SaaS access Employees aren't waiting for IT approval to adopt AI. The 1Password Access-Trust Gap Report found that 27% of knowledge workers were using AI-based applications that their employer didn't approve. Coding assistants, productivity tools, and AI platforms are being connected to work accounts, granted API access, and signed in with corporate credentials, often through a single "sign in with Google" OAuth token that leaves no trace in the identity provider. IT has no record of these AI tools, no visibility into what data enters the AI's context window, and no way to revoke access. When those tools run on consumption-based pricing, annual AI token budgets are being depleted within months, with no signal to finance until the allocation is nearly gone. SaaS sprawl has been a known cybersecurity problem for years, and until recently, traditional identity management was suf

## The unmanaged stack: Governing SaaS apps and AI tools outside SSO

DevFeed: [The unmanaged stack: Governing SaaS apps and AI tools outside SSO](<https://devfeed.tech/articles/the-unmanaged-stack-governing-saas-apps-and-ai-tools-outside-sso-1967.md>)

Original publisher: [Read original article](<https://1password.com/blog/the-unmanaged-stack-governing-saas>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-05-29T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [IAM](<https://devfeed.tech/topics/iam.md>), [Security](<https://devfeed.tech/topics/security.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Claude](<https://devfeed.tech/topics/claude.md>), [cursor](<https://devfeed.tech/topics/cursor.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-tools](<https://devfeed.tech/tags/ai-tools.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [iam](<https://devfeed.tech/tags/iam.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>)

### AI overview

This article recaps a 1Password webinar about governing SaaS applications and AI tools that operate outside traditional SSO and IAM controls. It describes the unmanaged stack, its governance and supply-chain risks, and 1Password integrations intended to help teams discover, review, and govern high-risk accounts and usage.

### Source excerpt

Note: This blog is a recap of 1Password's recent webinar, "The unmanaged stack: Governing SaaS apps and AI tools outside SSO." Head here to watch the complete webinar recording. In the constantly evolving world of enterprise tech, there's one thing that IT and security teams have always been able to count on: users won't follow policy if they think it's standing in the way of their productivity. Case in point: 1Password's most recent annual report found that 52% of employees have downloaded apps without IT approval. These shadow IT apps typically sit outside a company's SSO provider, and introduce both unmanaged risk and cost. That governance gap has become more pressing with the growing adoption of AI tools and agents, which introduce new and worsening threats. This issue was the focus of 1Password's recent webinar, "The unmanaged stack: Governing SaaS apps and AI tools outside SSO." What is the unmanaged stack? It refers to all of the SaaS apps and AI-based tools that can't be managed by traditional IAM tools, whether that's due to software constraints or the infamous "SSO tax." During the webinar, Evan Sandhu, 1Password Product Marketing Specialist, and Ethan Stoler, Senior Demo Engineer, explored how 1Password's solutions can help IT and security teams secure and govern these unapproved or unmanaged access points. Key takeaways from the webinar: SaaS and AI tools outside SSO create governance blind spots and can introduce supply chain risk. 1Password SaaS Manager helps discover unmanaged SaaS and AI usage, and help IT teams centralize provisioning, auditing, and lifecycle management. New integrations within 1Password support governance for ChatGPT, Claude, Cursor, and Gemini. Read on for an in-depth recap of the webinar's key themes. New integration features to manage high-risk SaaS and AI IT and security teams need solutions to manage those apps that fall outside the purview of SSO. Thankfully, new integrations between 1Password Enterprise Password Manager (EPM

## How to protect against OAuth-based supply chain breaches and credential sprawl

DevFeed: [How to protect against OAuth-based supply chain breaches and credential sprawl](<https://devfeed.tech/articles/how-to-protect-against-oauth-based-supply-chain-breaches-and-credential-sprawl-1949.md>)

Original publisher: [Read original article](<https://1password.com/blog/protect-against-oauth-supply-chain-breaches>)

Author: info@1password.com (Sanjay Ramnath)

Published: 2026-04-23T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Authorization](<https://devfeed.tech/topics/authorization.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [breach](<https://devfeed.tech/tags/breach.md>), [google](<https://devfeed.tech/tags/google.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [unified-access](<https://devfeed.tech/tags/unified-access.md>)

### AI overview

The article explains how credential sprawl and overpermissioned OAuth connections can create supply-chain risk. It outlines an attack chain in which a compromised third-party service exposes a valid OAuth token that an attacker can use to access internal systems, then calls for visibility into connections, just-in-time access, and usage records.

### Source excerpt

For security teams, credential sprawl is like dust; you don't notice it until it has accumulated. Over time, access spreads across SaaS apps, developer tools, automation workflows, and now AI agents. People sign up for tools to get work done and connect accounts using OAuth because it is fast and familiar. Credentials get reused across scripts, stored in environment variables, or passed between systems that were never meant to share a common control layer. The problem only becomes visible when you zoom out and realize that all these individual decisions have created a network of external dependencies that now sit on top of your internal access model. That is where credential sprawl turns into a supply chain risk. Add enough overpermissioned OAuth connections and suddenly, access to your internal systems is at the mercy of the security posture of every third-party service that has been granted access along the way. What is the attack chain for an OAuth-based supply chain brief? Recent incidents have shown how this access pattern can turn into a breach. Here's how it has played out: An employee connects a third-party tool using Google Workspace OAuth. The permissions are granted through a standard consent flow. At some point later, that third-party service is compromised. The attacker obtains the token and uses it to access internal systems. There is no need for the attacker to bypass authentication, because the token is valid. There is also no need to escalate privileges, because the permissions are already in place. What makes this type of attack so insidious is that, from the perspective of most security systems, the hacker's activity does not appear anomalous. The requests are authenticated, the client is recognized, and there are no failed login attempts or obvious indicators of abuse. The attacker is operating within the boundaries that have already been approved. The issue here is that trusted access has been extended into an environment that sits outside of di

## New integrations between 1Password SaaS Manager and EPM

DevFeed: [New integrations between 1Password SaaS Manager and EPM](<https://devfeed.tech/articles/new-integrations-between-1password-saas-manager-and-epm-1939.md>)

Original publisher: [Read original article](<https://1password.com/blog/new-integrations-between-1password-saas-manager-and-epm>)

Author: info@1password.com (1Password)

Published: 2026-03-31T00:00:00Z

Content type: news

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Software as a service](<https://devfeed.tech/topics/saas.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [Zero Trust](<https://devfeed.tech/topics/zero-trust.md>), [Extension](<https://devfeed.tech/topics/extension.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [App](<https://devfeed.tech/topics/app.md>), [SOC](<https://devfeed.tech/topics/soc.md>)

Tags: [app](<https://devfeed.tech/tags/app.md>), [browser](<https://devfeed.tech/tags/browser.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [extension](<https://devfeed.tech/tags/extension.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [saas](<https://devfeed.tech/tags/saas.md>), [saas-management](<https://devfeed.tech/tags/saas-management.md>), [soc](<https://devfeed.tech/tags/soc.md>), [zero-trust](<https://devfeed.tech/tags/zero-trust.md>)

### AI overview

1Password announces integrations between Enterprise Password Manager and SaaS Manager to help IT teams discover, assess, and govern shared and sensitive non-SSO accounts. The features include vault and browser insights, account risk reporting, and transferring account control to IT, extending access governance beyond SSO.

### Source excerpt

Most organizations can tell you which apps sit behind SSO. Far fewer can tell you what other apps teams are using, or who has access to the credentials. Shared and sensitive non-SSO logins remain some of the hardest access paths to govern. Credentials are often tied to individuals, scattered across vaults and browsers, and difficult to rotate or revoke when roles change. For many teams, this creates a gap in their Zero Trust strategy. For the last several months, we've been hard at work connecting 1Password Enterprise Password Manager and SaaS Manager to help close that gap. Today, we're announcing several integrated features that help IT admins discover and govern shared and sensitive logins. EPM and SaaS Manager integration demo Want to see how these integrations work in action? Check out our self-guided, interactive demo. Try the demo Extending governance beyond SSO For more than a decade, 1Password Enterprise Password Manager (EPM) has helped thousands of businesses securely store and manage credentials and secrets. More recently, SaaS Manager has helped organizations discover shadow IT, manage employee access, and control SaaS spending. Now, we're bringing these solutions together. When customers use Enterprise Password Manager and SaaS Manager together, they gain new capabilities: Vault insights: Discover SaaS accounts from 1Password vault credentials for better IT visibility into sensitive and shared app use. Browser insights: Reveal login activity from the 1Password browser extension to show app usage, even when credentials aren't saved in a company vault. Account risk report: Identify high-risk accounts based on access risk, data sensitivity, privileges, and attack patterns. Account governance: Transfer control of sensitive accounts to IT to enable secure access control and auditability without exposing passwords. Together, these capabilities extend Zero Trust governance beyond SSO and ensure that organizations can discover and secure credential-based acces