Skip to content

SaaS discovery outside SSO

How to find SaaS accounts your SSO directory does not show

No single source proves the full software stack. Use an evidence ladder to find likely direct logins, invited accounts, OAuth grants, and subscriptions that sit outside central assignment.

Why the SSO list is incomplete

Central assignment is evidence—not the entire account universe

An account can be created with a direct password, a Google OAuth grant, a vendor invitation, a secondary email address, or an API credential. A company can also keep paying for software after the original identity relationship changes.

  • The vendor never supported your identity provider.
  • A user chose Sign in with Google without a centrally assigned SSO application.
  • The account uses an alias, personal address, or contractor domain.
  • The subscription is visible in billing records but not in identity administration.

Evidence ladder

Use several lawful business sources and keep their claims separate

Work only with records your organization is authorized to inspect. Each source answers a different question, so label whether it shows current access, historical activity, ownership, or merely a paid subscription.

  1. 01

    Export or review centrally assigned SSO applications and current Google-connected grants.

  2. 02

    Compare them with the maintained software inventory and named application owners.

  3. 03

    Review approved password-manager collections, procurement records, and administrator lists.

  4. 04

    Match software invoices and finance records to vendors missing from the identity view.

  5. 05

    Ask the employee and application owners to resolve remaining likely or unknown records.

Reconciliation

Classify the result instead of forcing false certainty

A useful discovery record separates confirmed access, likely access, historical evidence, paid subscription without user attribution, ruled out, and unknown. This makes it possible to investigate gaps without claiming a coverage level the evidence cannot support.

What not to infer

Absence from one source is not proof of absence

No OAuth token does not mean no password account. No current invoice does not mean no free account. A card charge proves spend, not which person can log in. A recent audit event proves activity at that time, not necessarily current access.

From checklist to maintained record

Keep offboarding evidence attached to the software record.

Billproof early access is being built to reconcile Workspace application evidence, known software, ownership, and billing records into one reviewable offboarding view.

See the offboarding workflow

Sources and scope

Primary references

These sources support the Google Workspace capability statements. Operational checklist items should still be adapted to your contracts, roles, retention rules, and local law.

  1. Google Workspace Admin SDK — user tokens list ↗current token grants
  2. Google Workspace Reports API — token audit activity ↗recent grant activity