Skip to content
Asset Register

Register  ·  Discovery

Discovery Methods, Ranked

Five sources, each seeing a different slice. None sees everything, and the combination that works depends on what your organisation already has.

Reference  ·  707 words

No single source reveals your SaaS estate. Each sees a different subset, and knowing which subset is the difference between a useful inventory and a confident partial one.

Identity provider

What it sees: every application configured for single sign-on, with authentication events and therefore real usage.

Strengths: clean data, real user lists, real last-login dates. The best source you have, and usually the easiest to obtain.

Blind spots: anything not federated. Free tiers, card purchases, personal accounts, applications with local passwords.

Coverage in a typical organisation: the applications IT already knew about, plus a few surprises.

Expense and card data

What it sees: every recurring charge.

Strengths: catches departmental purchases invisible to IT. Gives you cost immediately.

Blind spots: free tiers, anything paid annually by invoice through accounts payable rather than by card, and charges with unrecognisable merchant descriptors.

The reconciliation problem is real here. Merchant names rarely match application names, and one vendor may appear under three descriptors.

OAuth grants

What it sees: third-party applications that users have granted access to your email, files, calendar and chat platforms.

Strengths: finds applications nothing else sees, because no money changed hands and no SSO was configured. Also finds the ones with the highest data exposure, since the grant is precisely a data access permission.

Blind spots: applications that do not integrate with your major platforms.

This is the most under-used source and frequently the most alarming.

Endpoint and browser telemetry

What it sees: what people actually open.

Strengths: catches personal accounts and web applications with no other footprint.

Blind spots: unmanaged devices, and it raises employee monitoring questions that need answering before deployment.

Weigh the privacy position deliberately. Browsing telemetry from employee devices is monitoring, with obligations in several jurisdictions.

Asking people

What it sees: whatever they tell you.

Strengths: finds things no automated source can, particularly personal accounts and tools used by one team.

Blind spots: memory, and reluctance where declaring produces trouble.

Works far better with an amnesty and a stated purpose.

The combination that works

Identity provider plus expense data plus OAuth grants covers most estates and requires no agents and no monitoring.

Add a survey once, with amnesty, to catch the rest.

Add endpoint telemetry only if the first three leave a gap you can articulate, and only after settling the monitoring question.

Reconcile them, which has its own note and is where the effort actually goes.

Measuring your coverage

Take twenty applications you know exist and check which sources found each.

The result tells you where the gaps are, by category rather than in the abstract.

Repeat after adding a source, to see whether it earned its place.

A source that adds nothing your existing ones did not find is a source to drop, and that judgement is only available if you measure.

Measuring what each source contributes

After a few months, work out which sources are earning their place.

For each known application, record which sources found it. A simple matrix, applications down the side, sources across the top.

Count unique finds per source — applications that only one source detected.

A source with no unique finds is redundant, and dropping it saves effort with no loss.

A source with many unique finds is carrying the programme and deserves better integration.

Expect OAuth grants and expense data to have the most unique finds, and expect them to be the two most often skipped.

Repeat annually, because the estate changes and so does what each source can see.

The monitoring question

Endpoint and browser telemetry is the most complete discovery source and the one with obligations attached.

It is employee monitoring, whatever it is called internally, and several jurisdictions treat it as such.

Settle the position before deploying: what is collected, retained how long, who can see it, and for what purposes it may be used.

Tell people, specifically, rather than relying on a clause in a policy signed at induction.

Restrict the purpose in writing. Data collected for application discovery being used for performance assessment is the failure that destroys trust permanently.

Consider whether the other three sources are sufficient, which for most organisations they are. Telemetry closes a real gap and it is not free, and the cost is not financial.