SaaS trial sprawl: the apps you tried once and never closed
Somewhere in your environment there is a tool that someone trialed for two weeks last year. The project it was meant for shipped, or stalled, or moved to a different tool. The trial account is still there. It still holds whatever data was loaded into it during the evaluation. It may still authenticate. And there is a fair chance it converted to a paid plan on a card nobody is watching.
This is trial sprawl. It is the residue of evaluation. Each trial made sense on the day it started, and almost none of them were closed on the day they stopped being needed. It builds up for predictable reasons and carries three distinct costs, and it can be cleared: find the trials in your environment, close each one so it is actually gone, and keep the next ten from accumulating the same way. The signals are in systems you already have: your expense data, your identity provider, your OAuth grant list, and the people who ran the trials.
- A forgotten trial is not a single problem. It carries three distinct costs: the data still loaded into it, the access it keeps live, and the spend if it converted to paid. Each resolves differently.
- Trial sprawl accumulates by default, not by indiscipline: trials are frictionless to start, easy to forget, often started without IT, and closed by nothing in the system.
- No single source surfaces all trials. Pull from four and reconcile: expense and card data, the identity provider and SSO app list, the OAuth grants the trial issued, and a short staff survey for the trials started on personal email.
- Closing a trial properly takes four steps in order: export or delete the data first, revoke any connections it made, deprovision the account, and stop the billing. The order matters because cancellation can restrict access to data you wanted to remove.
- Under GDPR, personal data sitting in a forgotten trial is still personal data you are responsible for, in a processor relationship you may never have papered with an agreement.
- Three lightweight controls stop the next ten: a one-page trial policy, a request-and-review path that records each trial, and a periodic sweep of expense data.
what trial sprawl is
A trial is a short-lived account in a SaaS product, created to evaluate it before buying. Someone needs a tool for a project, signs up, and the account is live in minutes, and they load real data in to make the evaluation meaningful, because a tool you cannot test with your own data tells you very little. Then the project ends, or the tool loses the comparison, or the need simply passes. The account does not end with it. Closing a trial is a deliberate act that someone has to remember to do, and nothing in the default flow does it for them.
So the trial stays. It keeps the data that was loaded during the evaluation. It often keeps a working login. If it connected to your Google Workspace or Microsoft 365 during setup, it keeps that connection. And if a card was entered to extend the evaluation past the free window, it may have quietly become a paid subscription that renews every month without anyone deciding it should. Trial sprawl is the sum of all these forgotten accounts across an organisation. Individually each one looks harmless. Collectively they are a class of access and data exposure that no process owns, because the process that created them, evaluation, is the one process that is not supposed to last.
why it accumulates
Trial sprawl is the predictable result of how trials work, not a failure of discipline. Trials are frictionless to start, because that is the point of them: a vendor wants you in the product as fast as possible, and the same low friction that makes evaluation easy makes the account easy to create without anyone else knowing it exists. They are easy to forget, because a trial is tied to a specific moment of need, and when that need passes attention moves on with no reminder pointing back. They are often started without IT, because a trial feels temporary and low-stakes, so the account exists outside any inventory IT maintains and does not appear in the single sign-on list. And nothing closes them by default: some vendors expire the login after inactivity, many keep the account and data indefinitely, and a converted trial simply continues as a paid account. In no case does anything in the system close the loop on your side. Trials are born easily, forgotten quickly, created quietly, and ended by nobody, so accumulation is the default, not the exception.
the three costs: data
A trial is only a real evaluation if you test it with your own data, so people load real data in. A CRM trial gets a slice of the actual customer list, a document tool gets real contracts, an analytics tool gets a live data export, a support tool gets real tickets with real names and messages in them, and sometimes a trial is handed credentials or an API key so it can pull data on its own. When the evaluation ends, that data does not leave with the decision. It sits in the trial account, in the vendor's environment, under whatever security that vendor happens to maintain. If the account is never closed, the data is never removed. Under GDPR, personal data sitting in a forgotten trial is still personal data you are responsible for, in a processor relationship you may never have papered with an agreement.
the three costs: access
A trial account usually has a working login. The password may be weak, shared, or stored in a browser, because nobody treated a throwaway account as something to protect. If the trial used a personal email rather than a company one, it is invisible to your offboarding process entirely, and it stays valid after the person who created it leaves. The deeper access cost is the connections a trial made during setup: to evaluate a tool properly you often connect it to something, and the trial reads your calendar, mailbox, or files through an OAuth grant, or connects to your CRM through an integration token. Those connections are standing access into live systems, and they do not end when the trial is forgotten. The trial product may be dormant; the grant it holds into your workspace is not.
the three costs: spend
Many trials ask for a card up front and convert automatically when the free window closes. Some convert at the end of the trial whether or not anyone used the product in the meantime. The charge is often small enough that it does not draw attention on a card statement, which is precisely why it persists. A forgotten trial that converted is a paid subscription nobody decided to keep, renewing every month, for a product nobody opens. Across an environment this typically adds up to a meaningful share of SaaS spend, sitting in subscriptions and seats that no longer serve any purpose. The spend cost is the easiest of the three to measure, because it shows up in finance data, and it is often the signal that leads you to the other two.
how to find them
Trials hide in different places depending on how they were started, so no single source surfaces all of them; pull from several and reconcile. Expense and card data is the strongest signal for the trials that converted to paid: ask finance for a report of recurring SaaS charges, including department and individual card statements, and look for small recurring charges, charges to vendors you do not recognise, and charges that do not map to any tool in your known inventory. The identity provider and SSO app list surfaces trials connected during setup, particularly ones that used company single sign-on to make the evaluation smoother; an application in this list that no team claims, or that maps to a project that has long since ended, is a trial candidate. OAuth grants the trial issued live until someone revokes them, so cross-reference the grant list against your known tools; a grant from an application you do not recognise is both a trial finding and an access finding, and the grant matters more than the login because it reaches back into your live data. A short staff survey catches the trials that used a personal email and never touched single sign-on, which appear in none of the system sources; send a short, blameless, specific note to team leads asking which tools they trialed in the past year or two, which they stopped using, and whether any held real company data. Reconcile the four sources into one list, marking each trial by where it surfaced and by what it appears to hold.
how to close one properly
Closing a trial means more than logging out and forgetting it again. A trial carries up to three of the costs above, and each has to be addressed on its own; closing the login is not the same as removing the data, and stopping the billing does neither. A proper close has four steps. Export or delete the data: decide first whether anything needs to be kept, export it before anything else because deletion is usually final, then delete the data inside the account using the vendor's deletion process, since for personal data deletion is the step that ends your GDPR exposure. Revoke any connections it made: if the trial issued an OAuth grant into your workspace, revoke it in the admin console, and if it connected to your CRM or another system through a token, revoke that token in the system it connected to; revoking is a separate action from closing the account and is the one most often skipped. Deprovision the account: close the user account in the trial product, and if it authenticated through your identity provider remove the application connection there as well. Stop the billing: if the trial converted, cancel the subscription with the vendor and confirm the cancellation in writing, then remove or flag the card it was charging. The order matters, because once you cancel the subscription the vendor may restrict access and you can lose the chance to retrieve anything, so export and delete the data first. Record each trial you close and what you did to it, so the same account does not reappear on the next sweep looking like a fresh finding.
how to stop the next ten
Finding and closing the current set is a one-time clean-up. Without something to change the default, the list rebuilds itself, because the conditions that created it are still in place. Three lightweight controls keep the next ten from accumulating, none of which requires stopping people from evaluating tools. A trial policy is a short, plain statement of who can start a trial, what data is allowed into one, and for how long; the data rule is the important one, so a reasonable default is that trials use synthetic or anonymised data unless there is a specific reason not to, with a time box on every trial so each has an expected end date. A request-and-review path pairs the policy with an easy way to register a trial when it starts, not an approval gate that slows people down but a single place where a trial is recorded with its purpose, owner, and expected end date; a control that simply records keeps the trial visible without getting in anyone's way. A periodic sweep of expense data is the backstop for trials that still start outside the process: a quarterly pass catches converted trials while the spend is still small and the data is still findable. Together these turn trials from accounts that appear and vanish into accounts recorded when they start and closed when they end. Fewer evaluations is not the point.
where this sits in the wider picture
Trial sprawl is one face of a larger pattern. Tools enter an environment faster than any process tracks them, and access outlives the reason it was granted. Forgotten trials, unused OAuth grants, applications outside single sign-on, and accounts belonging to people who have left are all versions of the same gap: access created for a reason that no longer holds, and that nothing closed when the reason passed. Third-party involvement appeared in 48% of breaches, up from 30% a year earlier, according to the Verizon Data Breach Investigations Report 2026. A forgotten trial is third-party access in a fairly literal sense: a live account, and sometimes a live connection, held by a vendor you stopped evaluating and stopped watching. Reviewing trials is part of the same work as reviewing the rest of your access surface, and it draws on the same data. The broader sweep is a SaaS audit, which covers the full inventory across all of these categories.
let's start with a conversation
Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.
Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.
We'll take it from there

+48 783 762 997
julian@unshadowit.com

