Why Browser Extensions and SSO Discovery Miss the Real SaaS Problem


Most SaaS discovery methods can only find what they were built to look for: a login, a browser session, a device check-in. Financial discovery for SaaS works from a different signal entirely: the money itself.
By mapping SaaS and AI purchases through spend channels, financial discovery catches applications that browser extensions and SSO have no way of finding.
According to Zylo's data, an average of 51% of software purchases aren't properly categorized as software within expense platforms and other financial systems. Half of all buying activity most organizations track is abstracted from view, which is where shadow IT lives, and increasingly, where shadow AI lives too.
Without financial discovery closing that gap, spend simply can't be managed as one holistic picture. It stays scattered across whichever tool happens to notice each piece.
The Market Has Settled on "Combine Everything" — and Stopped There
SaaS discovery vendors largely agree on one point in 2026: no single method sees the whole picture, so you need to combine several. Where they disagree is what should anchor that combination.
Some platforms treat SSO, browser telemetry, CASB traffic, and expense data as roughly equal, interchangeable sensors feeding one dashboard. Others go further and treat financial data as a secondary check—a way to backfill whatever an identity- or usage-based method missed, rather than the starting point.
Both positions get the ‘combine multiple sources’ part right.
Where they fall short is treating every source equally, as if each one covers the same share of the total picture, when in reality, some sources only ever see a narrow slice of activity.
SSO, browser, and CASB data all share one limitation: they only see an application if it touches something IT already controls, like an identity provider, a managed browser, or a monitored network.
Financial data doesn't share that limitation, and that difference matters more every year as SaaS and AI purchasing spreads further from IT's direct control.
What SSO-Based Discovery Actually Sees (and Doesn't)
Single sign-on (SSO) discovery connects to an identity provider (IdP), like Okta, Microsoft Entra ID, and Google Workspace, to pull a catalog of configured applications, their assigned users, and login activity.
What SSO Discovery Is Good For
SSO data provides a strong foundation for identity governance. Access reviews, MFA posture checks, and employee offboarding all depend on SSO records being accurate and current.
Where SSO Discovery Falls Short
The shortfall of SSO is that it shows only what IT has approved and connected. And most organizations have just 21% of applications behind it—per Zylo’s 2026 SaaS Management Index.
That means SSO doesn't show what the business has actually bought, which includes:
- Free-tier tools and trials signed up with a work email but never connected to SSO
- Apps purchased with personal credentials or a personal email address
- Tenants inherited through M&A that haven't been consolidated into the corporate IdP
- AI tools adopted informally by a team, since most start as an unmanaged sign-up rather than an IT-provisioned app

What Browser Extension Discovery Actually Sees (and Doesn't)
Browser extension discovery installs a lightweight extension on managed browsers to log which SaaS domains employees visit, how often, and for how long.
What Browser Extension Discovery Is Good For
Where SSO shows configuration, browser telemetry shows real usage. That makes it valuable for spotting unsanctioned tools employees have adopted on their own, beyond whatever IT already knows about.
Where Browser Extension Discovery Falls Short
Browser telemetry can only answer what people are doing on the browsers it monitors. It has nothing to say about a subscription bought on a personal card and used through a desktop client.
A few gaps follow from that:
- Personal devices and unmanaged browsers are invisible by design.
- Native desktop apps, mobile apps, and API-only integrations never generate browser traffic.
- Rolling an extension out across every operating system, browser, and remote employee is a real deployment lift, and privacy concerns slow adoption further.
Beyond its technical shortcomings, browser extensions may feel invasive to employees and not sit well with privacy and security teams. In our podcast interview with Shravya Ravi, Manager, Asset Management at LinkedIn, she shared that “tracking people’s browser histories, I’m sure, is something privacy will frown upon.”
What Both Methods Miss: How SaaS and Shadow AI Actually Get Bought
Because of the limitations of SSO and browser extension discovery, organizations are left with large blind spots in their software inventory.
SaaS spend moves through accounts payable invoices, employee expense reports, corporate and personal cards, and procurement run by individual business units. None of that requires an IdP connection or a monitored browser session, so none of it shows up in either method.
How Shadow IT and Shadow AI Spend Enters Through Expense Channels
Shadow IT and shadow AI spend are a result of decentralized purchasing across the business, typically through corporate credit cards and expense reimbursements. Financial discovery was built to catch this rogue spend, while app-first methods usually miss it.
According to Zylo’s 2026 SaaS Management Index, expensed software makes up 45% of applications but just 3.7% of total SaaS spend. That gap between application count and dollar share explains why app-first discovery struggles: most of the tools in use are individually low-cost and easy to overlook one at a time.

Meanwhile, the AI-native purchases sitting alongside them are growing far faster than everything else. In 2025, spend on AI-native applications rose 108% on average, reaching $1.2M per organization; for enterprises, that growth hit 393%, averaging $4.7M. Tools like ChatGPT, Anthropic's Claude, and OpenAI API consistently rank among the most-expensed applications industry-wide.
Allowing that blind spot to persist creates serious financial implications and compliance risks.
The Risks of Not Prioritizing Financial Discovery
Leaving financial data as an afterthought rather than the foundation carries real, compounding costs. A few show up consistently across organizations that rely primarily on SSO and browser-based discovery:
- Incomplete risk and compliance pictures. Security reviews built on SSO and browser data alone exclude every expensed tool by definition, leaving unassessed vendors handling company data with no one aware they exist.
- Unbudgeted spend surfacing at the worst time. Purchases that never reach financial discovery tend to surface later, during an audit, a renewal dispute, or an M&A due-diligence review, when there's far less room to negotiate or unwind them.
- Duplicate and overlapping tools going unnoticed. Without a spend-based inventory, teams keep paying for redundant applications that a financial view would have flagged immediately.
- AI governance built on a fraction of real usage. Policies written around the AI tools IT already knows about miss the expensed tools driving most of the recent spend growth, which undermines the policy before it's even enforced. According to Zylo’s 2026 SaaS Management Index, 77% of IT leaders say they’ve discovered AI-powered features or applications operating without their team’s awareness.
Ravi illustrated the risk of duplicate spending, as she’s seen in her extensive career as a software asset management consultant and practitioner. "App owners know what they're spending money on, but there might be three other app owners spending the same money on the same thing. We just need to get that visibility throughout the organization."
"Combine All the Signals" Isn't the Same as Getting the Order Right
Combining SSO, browser, CASB, and financial data is good practice. No single discovery method should be a company's only method. But there's a meaningful difference between treating financial data as one equally-weighted sensor among several and treating it as the anchor the other signals get reconciled against.
Financial data deserves that anchor position for a structural reason, not a matter of preference: it's the only method indifferent to how a purchase happened. Each method depends on a different condition being met before a purchase becomes visible at all:
- SSO needs the app connected to an identity provider
- Browser extensions need the purchase to route through a monitored browser
- CASB needs traffic to cross a monitored network
- Financial discovery needs only one thing: that money changed hands
By following the money, you can identify the applications in your inventory regardless of which team bought the tool, what device they used, or whether IT ever knew it existed.
That doesn't make SSO or browser data less useful. It makes them better suited to a narrower question: who is using what, among the tools we already know about. Financial data answers the broader, prior question: what have we actually bought.
Holistic spend management has to start here, because every later step—governance, renewals, cost control—inherits whatever the starting inventory missed.
What Spend-First Discovery Looks Like in Practice
Making financial data the foundation of your spend management program changes the sequence of discovery. Spend-first discovery starts by ingesting accounts payable, expense report, and corporate card data. SSO and usage signals get reconciled against that baseline afterward, adding identity and engagement context to applications already confirmed to exist.
That sequencing supports a few things app-first discovery struggles to deliver on its own:
- A true inventory baseline. Every application with a dollar attached to it is in scope from day one, whether or not it's ever touched an IdP.
- Renewal and contract visibility. Financial records carry contract terms and renewal dates that SSO and browser data never capture, which matters given that 38% of contracts are multi-year on average, per Zylo's 2026 SaaS Management Index.
- A governance conversation grounded in dollars, not just headcount. Security and finance teams can prioritize which unsanctioned tools to address first based on actual spend, not just user count.
Zylo's financial discovery engine applies AI to automatically classify and reconcile this financial data as it's ingested, turning raw AP and expense records into a structured application inventory rather than leaving that classification work to manual review.
Build a Complete Financial System of Record for SaaS and AI
A financial system of record centralizes every application, contract, and renewal an organization has actually paid for. Spend data forms the base layer, and SSO, usage, and access context get layered on top as that data becomes available.
It's the natural end state of spend-first discovery: one continuously updated source of truth that IT, procurement, and finance can all work from, instead of three separate partial views that never quite reconcile.
Zylo built its Discovery Engine on this model, ingesting financial data as the foundation of SaaS and AI spend management. To date, it has processed and classified more than $75B in SaaS and Cloud spend. SurveyMonkey used this approach to move off manual spreadsheets and into proactive renewal management—one example of what spend-first discovery unlocks in practice.
The result? A system of record built to match how SaaS and AI actually get purchased in 2026, not just how IT wishes they did.
Request a demo to see how Zylo's financial discovery works.









