A brief history of SaaSOps (and why it matters)

0


Ask most people outside of IT what SaaSOps means, and you’ll get a blank stare. Even inside IT, the answer usually comes out a little fuzzy at first: “It’s the same idea as DevOps, but for IT pros.” That’s directionally right, but it undersells what’s actually going on.

Dig into the history of SaaSOps, though, and two things become clear. First, there’s a really obvious need for a set of processes and skills to manage a SaaS environment, especially since every organization uses so many of them. Second, it’s genuinely interesting to look back at the series of events that got us to where we are today: A world in which SaaS operations is not just a luxury, but a necessity for any company that uses SaaS.

Let’s take a look at the brief, but insanely interesting history of SaaSOps, including how fast SaaS became a driver of innovation, the external threats against it, and how the benefits of SaaS helped IT discover a need for a more centralized way to manage all of the products its employees use.

What is SaaSOps?

SaaSOps, short for SaaS operations, is the set of processes and skills IT professionals use to manage, secure, and optimize a company’s SaaS environment. 

It’s the same idea as DevOps, but applied to the growing stack of SaaS applications an optimization relies on, everything from onboarding and offboarding users to monitoring unsanctioned apps and closing security gaps between platforms.

Why did SaaS adoption grow so quickly?

It’s hard to imagine now, but things haven’t always been this way.

When I started my career in 2009, most applications I used for work were installed locally on my computer (If you’re curious, I’m pretty sure that machine was a Dell Optiplex 780, which felt luxurious at the time).

The only real SaaS product we used was Salesforce. Most people at that company hadn’t even imagined the concept of things like email or Microsoft Word living exclusively in the cloud—especially on the enterprise level.

In fact, there were a lot of people who thought it was a really bad idea. Richard Stallman, founder of the Free Software Foundation and creator of the computer operating system GNU, told the world in 2008 that using web-based apps like Gmail was, “worse than stupidity… if you use a proprietary program or somebody else’s web server, you’re defenseless. You’re putty in the hands of whoever developed that software.”

Things have changed dramatically since then. We surveyed over 525 IT professionals as part of our 2026 State of SaaSO report and found that the average company uses 118 SaaS applications. 

IT teams adopted SaaS in large part because it freed them from supporting on-prem hardware and software, especially as they continue to be asked to do more with less. And end-users tend to agree that SaaS applications are just better than their on-prem counterparts. But as enterprises and startups move to the cloud en masse, new threats enter the picture on a daily basis.

What security risks came with the rise of SaaS?

As SaaS adoption spread, so did the threats against organizations using it.

Notably in 2015, an IT admin at a midsize company you probably haven’t heard of enabled an option in Slack that allowed users to generate document previews when employees shared Google Drive items with each other. Not a big deal, right?

Actually, it’s kind of a huge deal.

Turns out that when you put a sharing link in Slack, those documents were saved in Slack’s databases. And by integrating the two apps with just one click, the admin exposed 100 Drive accounts. Oh, and did we mention that this midsize organization is part of the General Services Administration (GSA)? Or in other words, the federal government?

Again, kind of a huge deal.

The threat has only grown since, and the pace has picked up sharply in the last few years. Where the early risks came from unmanaged SaaS sprawl, today’s biggest exposures increasingly trace back to AI tools adopted faster than IT could govern them. Employees connect AI assistants to company email, documents, and CRM data without a formal review. SaaS vendors ship new AI features, on by default, that quietly expand what an application can see and do. 

Each one of these moves looks small in isolation. Together, they’ve created a new category of risk that didn’t exist a decade ago: sensitive data flowing into AI models with no clear owner, no audit trail, and no governance policy keeping pace.

A New Methodology for Managing and Securing your SaaS Environment

In 2011, Google stopped offering free Google Apps to organizations with more than 10 users. By the end of 2018, Google reported that 5 million customers around the world were paying for Google Workspace (formerly G Suite). SaaS adoption snowballed from there, and not just for Google: companies like Salesforce, Microsoft, and SAP saw their SaaS market share grow more than 73% by 2015.

But as more companies adopted more and more SaaS apps, IT leaders discovered that managing a stack of SaaS apps becomes far more difficult each time you add a new app. Without a centralized platform to secure a SaaS environment, IT teams had no choice but to manage each app from its native console—which, by the way, changes constantly.

In addition to growing external threats against SaaS-based organizations, our CEO David Politis started BetterCloud because everyone in his network agreed that IT needed a better way to manage and secure G Suite.

And while BetterCloud started as a platform designed to secure Google Workspace exclusively, it became abundantly clear that Google Workspace wasn’t the only thing keeping IT admins up at night.

For years, Politis used the term SaaSOps to describe the need and methodology for managing and automating IT operations. And based on what he was seeing in the market, Politis took pen to paper and unveiled the first definition of SaaSOps during BetterCloud’s 2019 Altitude event.

After announcing the definition, Politis urged IT professionals to champion SaaSOps and update their job titles to include it. That might have seemed like a big ask to some folks, but SaaSOps has become a full-blown movement since then.

For many people in IT, the growth of using SaaSOps is far from surprising. 76% of respondents see unsanctioned apps as a security risk, but only 49% of IT organizations inspire confidence in their ability to identify and monitor unsanctioned SaaS usage on company networks.

As SaaS applications become more and more ubiquitous over the coming years, it will undoubtedly become a bigger challenge to manage and secure a SaaS environment—and as a result, IT leaders across the country are quickly embracing the history and future of SaaSOps.

How is SaaS management evolving in the age of AI?

SaaSOps hasn’t stood still since 2019. As AI tools get embedded into nearly every SaaS application, and as employees adopt standalone AI apps on their own, SaaS management has evolved into a core pillar of a much bigger discipline: SaaS governance.

The shift matters because AI changes what IT is actually responsible for. It’s no longer enough to know which SaaS apps are in use. IT now needs visibility into:

  • Which apps have AI features turned on, and what data those features can access
  • Which AI tools employees have connected to company data without IT’s knowledge, often called shadow AI
  • How permissions and data flows change when an app adds an AI agent or assistant
  • Whether AI-driven automation inside SaaS tools is compliant with internal policy and external regulation

In other words, the same sprawl problem that created SaaSOps in the first place is repeating itself, just faster and with higher stakes. An unsanctioned SaaS app is a risk. An unsanctioned AI tool with standing access to company data is a bigger one.

That’s why the conversation among IT leaders has broadened from “how do we manage our SaaS stack” to “how do we govern it.” SaaS governance builds on everything SaaSOps established, discovery, security, and lifecycle management, and extends it to cover AI-specific risks: model access, data exposure, agent permissions, and policy enforcement across an environment that now includes both SaaS apps and the AI layered on top of them.

This isn’t just a theoretical shift, it’s already reshaping the market. In March 2026, CoreStack acquired BetterCloud specifically to build what the combined company calls an Agentic Governance OS, a platform designed to govern cloud, SaaS, and AI systems together instead of as separate problems handled by separate tools. That kind of move is a strong signal of where the industry believes SaaS management is headed: toward unified governance of every system, human-driven or AI-driven, that touches company data.

FAQ: SaaSOps quick answers

What does SaaSOps stand for? 

SaaSOps stands for SaaS operations, the practice of managing, securing, and optimizing an organization’s SaaS applications.

Is SaaSOps the same as DevOps? 

Not exactly, but the concepts are related. DevOps focuses on the software development and deployment lifecycle, while SaaSOps focuses on managing the SaaS applications an organization already uses, including access, security, and app sprawl.

Who started the SaaSOps movement? 

David Politis, founder and CEO of BetterCloud, coined and formalized the term SaaSOps, introducing the first official definition at BetterCloud’s 2019 Altitude event.

Why do companies need SaaSOps? 

Companies use dozens of SaaS applications on average, and each one adds complexity and security risk. SaaSOps gives IT teams a centralized methodology for managing that sprawl instead of handling every app through its own separate console.

How many SaaS apps does the average company use? 

According to BetterCloud’s 20265 State of SaaSOps report, the average company used 118 SaaS applications.

How does SaaS governance relate to SaaSOps? 

SaaS governance is the natural evolution of SaaSOps in the age of AI. It builds on the same foundation, discovery, security, and lifecycle management, but extends it to cover AI-specific risks like shadow AI, model access to company data, and agent permissions.



Source link

You might also like