Last updated: October 8, 2026
Application rationalization is the exercise of listing every application you pay for, measuring who actually opens it, naming an owner, and putting a renewal date beside it, then deciding what to keep. Four columns. Not a maturity model, not a framework, and not something you need a consulting deck to start. The hard part is the usage column, because that is the one everybody fills in from memory.
I asked a controller at a $310M food and beverage manufacturer to export twelve months of corporate card charges and vendor payments, filtered to anything that looked like software. One afternoon of work. She came back with 61 vendors.
IT’s list had 23 on it.
Nobody was lying. The IT list was the list of applications IT had bought, which is a completely different list from the applications the company was paying for, and the 38-item gap in between was marketing buying its own analytics tool, three departments each buying a different project tracker, and one scheduling product billing $1,400 a month whose internal champion left in 2024. Her total came to just over $1.2M a year. The budget line said $740K.
That is where this always starts. Not with strategy.
Quick bias disclosure, since you are about to read a page telling you to consolidate. I run a consulting group that gets paid to build unified tech stacks, so of course I think your eleven overlapping tools should be four. You are also reading this on a staffing firm’s site, where KORE1’s IT staffing services group, and specifically its business systems consolidation and data migration staffing desk, gets paid when the project turns into open reqs. Both of those things are true and neither one changes what is in your card export.

What Application Rationalization Actually Is
Application rationalization is the process of inventorying every business application an organization pays for, measuring real usage against licensed seats, assigning a single accountable owner, and sequencing keep, consolidate, retire, or re-platform decisions against contract dates. The output is a dated decision list, not a software inventory.
Deciding an application should go is a different project from making it actually stop. We broke down the decommissioning work that follows rationalization, including the consumer inventory, the retention rules, and who should own the kill date.
Read that last sentence twice, because most of these projects produce the inventory and then stop. An inventory is a document. A decision list has names and dates on it, which means somebody has to defend a position, which is exactly why the inventory version is more popular.
Mid-market is a different problem from enterprise, and the advice written for enterprise will actively hurt you here. A company running 600 applications needs a program, a portfolio taxonomy, and a team that does nothing else. You are running 40 to 80. You can fit the whole thing on one page. What you do not have is a person whose job it is to look at the page, and that is the real gap, not the tooling.
Four Columns, and Only One Is Hard
Here is the entire instrument.
| Column | Where the answer actually comes from | Why it is on the page |
|---|---|---|
| The application | AP vendor history and card charges, not the IT asset list. Then your identity provider’s app list. | Finds everything bought outside IT, which in the mid-market is most of it. |
| Real usage | Last-login data from the SSO logs, or the vendor’s own admin console. Never a survey. | Separates the apps people need from the apps people remember agreeing to. |
| One named owner | A human being, in writing. Not a department. Not “IT and Finance.” | An app with two owners has none, and you will discover this during an outage. |
| The date | The order form, including the auto-renew clause and the notice window. Not the invoice. | Turns an opinion about consolidation into a deadline somebody has to meet. |
Four columns. Three of them are clerical. The fourth one is work.
Usage Is the Column Everybody Fakes
Ask a department head whether they use a tool and the answer is yes. Always yes. The tool was their idea, or their predecessor’s idea they inherited and defended, and in either case “we don’t really use it” is a sentence that costs something to say out loud in a room with the CFO in it.
So do not ask. Pull last-login dates out of your identity provider and sort ascending.
What comes back is usually three piles. There is a small pile of apps with daily logins across a real population, and those are not the conversation. There is a large middle pile where 90 seats are licensed and 30 people have logged in this quarter, and that pile is money rather than a decision, because you fix it at renewal by buying fewer seats. Then there is the pile that nobody has opened since a date you can read out loud in a meeting, and that pile is the actual rationalization work, and it is always smaller than people hope and more annoying to unwind than they expect.
Flexera’s 2026 State of ITAM report, which surveyed more than 500 IT asset management professionals, found that only 36% of organizations report complete visibility into their IT estate, and 43% said wasted SaaS spend went up rather than down last year. Those are organizations with ITAM professionals on staff. You probably do not have one of those. Worth sitting with.
I want to be fair about why this happens. Nobody at that manufacturer woke up and decided to overspend by $460K. Somebody needed a tool in a hurry during a quarter when IT was busy, the card worked, the tool was good, and then the need ended and the card kept working. It is not negligence. It is just that no process ever existed to notice.

An App With No Owner Is Already Retired. It Just Still Bills You.
This is the column people skip because it feels like org-chart busywork, and it is the one that predicts whether any of this sticks. Of the 61 vendors on that controller’s list, 19 had no owner anybody could name.
The test is a phone call. Pick an app. Who do you call when it breaks at 4 p.m. on a Thursday, and who signs the renewal, and are those the same person, or at least two people who have met? If you cannot answer in one breath, write “none” in the owner column instead of writing a department name. “None” is honest and it is actionable. “Operations” is neither.
A few patterns I see constantly, and none of them look the same when you find them:
- The app whose owner left in March. Still billing, $890 a month. Nobody renegotiated at renewal because the notice email went to a mailbox that forwards nowhere.
- Two owners, which is the expensive one. Both assume the other is watching the contract, both are slightly annoyed to be asked, and the auto-renew lands anyway. That one cost a client a $64,000 annual commitment on a product they had already decided to drop.
- IT owns the login, finance owns the invoice, and a department owns the actual business process inside it. Three parties, zero accountability, and a tax table that drifted in 2022 and nobody noticed because the reports still print.
- $0 cost, real risk. The free tier somebody connected to your ERP with an API token in 2023. Costs nothing. Has write access. Good luck finding it in the card export, which is why you also pull the identity provider list.
That one scares me. It is also the reason I never run this exercise from accounting data alone.
Then Put the Dates Beside It
Sequencing is the whole game, and the sequence is not yours to pick. Renewal dates, notice windows, end-of-support announcements, and whatever go-live you already promised a board set the order for you. If you have not done this part yet, it is the same exercise as building an IT roadmap backward from dates you don’t control, applied to a narrower list.
There is a second reason to care about the contracts, and it is not savings.
Audit exposure lives in the gap between what you licensed and what you deployed, and that gap is created by exactly the drift this exercise finds. The same Flexera survey found that 48% of organizations were audited in the past year, and 44% had spent more than $1 million on audits across three years, with Microsoft audits reported by 64% of the audited group. An unowned app with unknown deployment is not just waste. It is an unpriced liability sitting in a contract you have not read.
Sorry. That got dry. The point is that the renewal calendar pays for itself twice and most people only count once.
Four Dispositions, and the One Everybody Skips
Every row ends in one of four decisions. Keep, consolidate, retire, re-platform.
Keep is the default, and it should be. Most of your stack is fine. Leave it alone. Resist the urge to touch a working application because the exercise made you feel productive, and right-size the seat count at renewal instead.
Consolidate means two or three tools collapse into one you already own, which is where the money usually is. The three project trackers become one, which at that manufacturer handed back $38,000 a year and one weekly status meeting. The second analytics tool dies because NetSuite already reported the same numbers through a saved search nobody had built. Before you assume a gap needs new software, check whether the platform you are paying for covers it, because the build versus buy question is usually a configure-what-you-own question wearing a disguise.
Re-platform is the expensive one and the honest one. The app is load-bearing. It is also eighteen years old, the vendor stopped shipping updates, and no amount of rationalizing changes that you have a modernization project rather than a cleanup. Put it on the page anyway. It is coming regardless. Knowing it arrives in Q3 of next year is worth more than pretending it isn’t coming.
Retire is the one that gets skipped, and it gets skipped for a specific reason that nobody says in the kickoff meeting. Turning an app off is easy. Keeping its data is not. Somebody has to decide what has to survive, where it lands, how long you are required to hold it, and who signs off that the extract matched the source. That is a real data migration, scoped small, and it is why “retire” rows sit on rationalization lists for three years with nobody touching them while the invoice renews annually out of pure institutional habit.
Count Your Integrations, Not Just Your Apps
Here is the part most rationalization write-ups miss entirely, and it is the part that decides whether your consolidation plan is arithmetic or wishful.
Applications do not sit there. They talk to each other. Every tool you keep is also some number of connections to NetSuite or whatever ERP you run, to your WMS, to Salesforce, to Shopify, and those connections have metered budgets that nobody checks until something stops syncing in December.
Real numbers from a recent integration design of ours. A unit-level design that pushed every individual record would have consumed roughly 1,350,000 API calls a year against a licensed allowance of 130,000. Over by a factor of ten. Batching at the transaction level instead, about 141 documents a month at four to six calls each, used under a quarter of the allowance. Same business outcome. The design decision was arithmetic, not judgment, and it took an afternoon of counting to find.
Apply that to your app list. Eleven tools talking to your ERP is not eleven licenses. It is eleven integrations to maintain, eleven authentication schemes that expire, and eleven sets of error logs somebody is supposed to read. Here is a detail nobody tells you until it costs you a sprint: a NetSuite RESTlet will not accept a plain API key, so any vendor whose integration only offers API-key auth needs an authenticated relay built in front of it. One line in a vendor datasheet, two weeks of work.
Consolidation savings are real, but they show up in the integration count more reliably than in the license count. That is the argument I would make to a CFO, and it is also why the people who do this work well are integration architects rather than procurement analysts.

What This Actually Costs to Do Properly
Two days and a spreadsheet gets you the inventory. I am not going to pretend otherwise, because I just told you to start with a card export. But the inventory is the cheap part, and the gap between “we have a list” and “we turned four things off and the month-end close still worked” is where the budget goes.
For scale, our blended delivery rate runs $215 an hour across roles. A properly scoped discovery and assessment phase on a regulated integration project ran 182 hours at a fixed $44,110, and that bought a written risk assessment and a plan, not a single line of working code. Your rationalization discovery is smaller than that. It is not free. Nothing good is.
Where the real money goes:
- Nothing, for about a third of the rows. Right-size seats at renewal, write the owner’s name down, move on.
- Configuration work inside the platform you already own, to absorb what the retired tool was doing. Weeks, not quarters.
- Data extraction and migration for every “retire” row that holds records somebody will need in an audit.
- Integration rework, which is the line that gets underestimated every single time, because the apps you are cutting are load-bearing in ways that only surface when you unplug them.
One client of ours went from $150M in sales on a pile of disconnected systems to north of $250M on a consolidated stack with actual visibility across ecommerce and wholesale. The consolidation was not the headline achievement anybody put in a press release. It was the thing that made the growth survivable.
Where These Projects Die
Four ways, and I have watched all four.
The savings number gets announced before the work is scoped, so the project spends the rest of its life defending a number somebody made up in a steering meeting. Then there is no owner for the exercise itself, which means it becomes everyone’s side project and dies the week quarter-close lands. Another is a retire decision with no data plan, which is the one that sits on the list for three years. The last one is treating this as an annual event instead of a quarterly fifteen minutes, which guarantees you run the whole archaeology dig again from scratch in eighteen months. All four are avoidable.
None of those are technology problems. The tech is not the hard part. It never is.
What the CFO Asks Me About Nine Minutes In
How much are we actually going to save?
Pick a number after the usage pull, never before. In a 40 to 80 application portfolio I generally expect 8% to 15% of annual software spend to be genuinely recoverable, mostly from seat counts rather than from killing products.
The reason I will not give you a bigger number up front is that the big savings numbers in vendor case studies come from enterprises with 300 apps and real duplication. Your duplication is narrower. The upside in the mid-market is less about waste and more about not needing the next three hires to hold the stack together.
Our IT list and our AP list disagree. Which one is wrong?
Both, usually. The AP export finds what you pay for and misses free tiers with live API access. The identity provider list finds those and misses anything bought on a card without SSO. Run both and union them.
Can we just make a rule that all software purchases go through IT?
You can write it. It will not hold unless IT can answer a request in under a week, because the rule is not the control. The response time is.
I have watched that policy get written four or five times. It works exactly as long as the alternative is slower than the process, and the day somebody needs a tool before Friday it stops working and nobody tells you. Make the front door fast and you will not need the rule.
Who owns this exercise if nobody here owns IT?
Finance owns the inventory and the dates, which is most of the work. What finance cannot do alone is judge whether two applications genuinely overlap, and that question is three or four hours of technical opinion, not a hire.
This is the whole argument for renting technical leadership in slices instead of hiring it, and elsewhere I have written up what a fractional CIO actually does. It is also the cheapest part of the project, which people find suspicious.
Do we need a SaaS management platform to do this?
Not at 40 to 80 applications. A spreadsheet and your SSO logs cover it, and buying a tool to count your tools is a joke that writes itself.
Above roughly 150 applications with a continuous intake of new purchases, yes, the tooling starts to pay. Below that, the tool becomes app number 61 and the thing it was supposed to fix is that you have 61 apps.
Once we decide, how fast can we get the people to execute it?
Faster than the decision took, which is the uncomfortable part. KORE1 fills an IT role in 17 days on average, and staffing is almost never what holds one of these projects up.
What holds it up is a req nobody scoped. “Integration developer” gets you a stack of resumes. “Own the four integrations we are collapsing, through parallel close, then hand the runbook to the internal team” gets you somebody who finishes and leaves on purpose, which is what a consolidation project actually wants. The market for those people is not loose either. The BLS puts the median wage for computer systems analysts at $105,850 as of May 2025, with employment projected to grow 8% through 2035, and software developers higher still at $135,980 with roughly 106,100 openings a year.
Go Pull the Card Export
Not the strategy session. Twelve months of card charges and vendor payments, filtered to software, unioned with your identity provider’s app list. Then four columns.
You will find something you had no idea you were paying for. I have never once run this and not found at least one, and the record in my experience is a $27,000-a-year contract for a product whose entire user base was three people, two of whom no longer worked there.
Then decide what each row forces and staff it accordingly. The judgment calls go to somebody who has made them before. The execution goes to project-based staff you can scale down when it ships, which for consolidation work usually means integration developers and data migration people, and KORE1 keeps 92% of its placements in the seat at twelve months, so you are not re-hiring halfway through. If you want a second opinion on your sequencing before you commit a budget, hit me up through KORE1’s staffing team and we will go through your list.
Four columns. One afternoon. Go look.

