A platform that can't see an app can't manage it. Discovery isn't a feature sitting alongside the rest of the platform, it's the foundation everything else, optimization, security, compliance, gets built on.
As SaaS and AI adoption keeps growing inside most organizations, comprehensive visibility stops being optional, and visibility here means more than a list of application names.
It means knowing who and what actually has access: employees, external users like contractors and freelancers, and non-human identities like service accounts, AI agents, and APIs, all with their own access levels across every app in the stack.
The first real step toward monitoring, controlling, and securing that stack is a discovery process robust enough to surface all of it, not just the applications IT already knows about.
What Is Zluri
Zluri is an identity security platform built to discover, govern, and secure every identity, human and non-human, across an organization. That work spans four products: Identity Visibility and Intelligence (IVIP), Identity Governance and Administration (IGA), Identity Security Posture Management (ISPM), and SaaS Management (SMP).
The discovery engine covered in this article sits inside IVIP specifically, and it's what every other product runs on top of, not a feature specific to any one of them. IGA can't govern access it never found. ISPM can't assess the security posture of an app it doesn't know exists. SMP can't optimize spend on a subscription nobody discovered. Whichever product you're actually using, the identity and application data underneath it all comes from the same discovery layer.
How the Discovery Engine Works
The discovery engine surfaces three layers of visibility: every application in the stack, every identity that touches it, and exactly what access each identity holds inside it. That third layer covers more ground than most discovery approaches account for.
Human identities include not just employees but external users, contractors, freelancers, and vendor accounts, who often sit outside HR systems entirely.
Non-human identities include service accounts, AI agents, and APIs, which routinely hold access to sensitive applications with no individual person directly accountable for them. For every one of these identities, the engine also captures the access level itself, not just that a connection exists, but what that identity can actually see or do within the app.
Zluri runs on a SaaS app library of 240,000+ applications, combined with eight discovery methods working in parallel: IDPs & SSO, Finance & Expense Systems, Direct Integrations, Browser Extensions, CASBs, MDMs, HRMS, and Directories. That combination is what gives IT admins a genuinely complete view, active and idle apps, human and non-human identities, and the specific permission level each one holds, rather than a partial list assembled from whatever a single source happens to catch.

Once an application and the identities attached to it are identified, that same data set is what lets Zluri find and eliminate redundant, unused, underutilized, and risky apps, flag orphaned non-human identities nobody's accountable for, and optimize spend and access across everything that's left.
1: SSO and ID Providers
Zluri's integration with Single Sign-On (SSO) and Identity Provider (IDP) systems is a crucial discovery method that helps organizations gather and manage essential data about their SaaS applications and user activities. By connecting with widely used systems such as Okta and Google Workspace, Zluri is able to pull comprehensive information to enhance visibility and control over application usage within an organization.
Zluri integrates seamlessly with SSO and IDP systems to collect directory information, which includes details about users, their roles, and departments.

This data is vital for understanding who has access to which applications and managing permissions effectively.

Through SSO and IDP systems, Zluri collects data on authorized apps and login events. This includes information about:
- Sign-in Attempts: Tracks the number of times users attempt to log in to applications.
- Access Frequency: Records how often users access specific apps.
- Login Success/Failure: Details whether login attempts were successful or failed.

Further, Zluri also captures data shared with third-party applications, such as names, email addresses, and other relevant user details. This helps in understanding the flow of information and ensuring that data shared with external services is monitored and managed.
2: Finance & Expense Systems
Zluri’s integration with expense and finance management systems is a crucial discovery method that enables organizations to capture and manage data related to their SaaS applications that may not be visible through traditional SSO or identity provider systems. By connecting with financial tools like Netsuite and QuickBooks, Zluri ensures comprehensive visibility into all expenditures related to SaaS applications, including those purchased by employees.

This integration allows Zluri to collect detailed transaction data related to SaaS applications. These systems provide insights into apps that might not be tracked by SSO systems, especially those purchased directly by employees.


Employees often buy software using corporate or personal cards and seek reimbursement. Zluri captures these transactions, ensuring that apps purchased outside of the central procurement process are still identified and managed. This includes applications bought with personal funds and reimbursed later, which might otherwise be missed.
Through finance systems, Zluri gathers crucial transaction details such as:
- Amount Spent: Records the monetary value spent on each app.
- Date of Expense: Captures when the transaction occurred. Zluri maps these transactions to the specific apps purchased, providing a comprehensive view of SaaS expenditures.


For organizations that prefer not to connect directly with their financial systems, Zluri offers the option to manually upload transaction data. Users can upload CSV files containing expense data, which Zluri then processes to match with SaaS applications.

3: Direct (Out-of-Box) Integration
Zluri’s direct integration method is a powerful approach to discovering and managing SaaS applications. By connecting directly with over 300 of the most commonly used SaaS apps across various categories, Zluri ensures comprehensive and granular visibility into your organization's SaaS landscape. This list of supported apps continues to grow, ensuring ongoing relevance and coverage.

Through direct integration, Zluri gathers detailed information about which users have access to each SaaS app and their level of permission (e.g., user or admin). This helps in understanding and managing user roles and access levels across the organization.
Zluri tracks license details for each user, including the specific plan, pricing, and features available in their subscription tier. This information helps in managing licenses more effectively, ensuring that the organization is using the most cost-effective options and that licenses are not being wasted.
The integration also includes access to and analysis of audit logs, which provide a record of what changes have been made within the SaaS applications. This feature is essential for understanding app usage, monitoring security, and maintaining compliance.

This method, combined with the flexibility of custom integrations, makes Zluri a comprehensive solution for SaaS management.
4: Browser Extensions
Zluri uses browser extensions to collect data on websites visited by users, providing an additional layer of visibility into SaaS application usage. This discovery method is available for Chrome, Firefox, and Microsoft Edge, making it accessible for a wide range of users.

The browser extensions capture data about websites visited, including the URL, title, and timestamp of opening or closing the tab. This information helps identify SaaS applications being accessed via web browsers.
The browser extensions are optional and designed to respect user privacy. Zluri does not read cookies, browser history, or any content from the websites visited, focusing only on SaaS-related activities.
Each visit to a website whose domain is in Zluri's master list is identified as a SaaS application. The browser extension logs the visit timestamp and duration, counting each visit as an activity.

Zluri aggregates the activity data at least daily, calculating how frequently users are accessing subscribed SaaS applications. This data is used to generate a percentile score for each user, reflecting their usage of specific applications within the company.
Prompting Installation
- Administrators can prompt users to install the browser extension directly from Zluri.
- Navigate to Sources > Agents > Users, and filter users based on criteria such as no agent installed, no browser agent installed, or any other relevant filter.
- Administrators can send prompts to selected users or all users at once.

Monitoring Installation
- Zluri allows administrators to check how many users have installed the browser extension, ensuring compliance and comprehensive data collection.

Further, you can also check how many users have installed it.


By collecting and analyzing web activity data, it provides valuable insights that support effective SaaS management and optimization.
5: MDMs (Mobile Device Management Platforms)
Mobile Device Management (MDM) discovery method employed by Zluri helps you manage and monitor employees' devices and the applications installed on them. MDM solutions provide comprehensive data about devices, including detailed application information, making it a vital component for organizations aiming to control their SaaS landscape effectively.
MDMs store extensive employee data, encompassing device details and the applications installed on each device. This data includes the list of applications, associated users, and device-specific information. Zluri leverages this inventory to maintain an up-to-date record of all software within the organization.
MDM provides insights into user activities, helping administrators monitor application usage and compliance. In some cases, MDMs can track specific activities performed on devices, offering granular visibility into software interactions.
MDM works in conjunction with other discovery methods used by Zluri, such as desktop agents and browser extensions. The combined data from these methods offers a holistic view of the organization's SaaS ecosystem, aiding in comprehensive management and optimization.
6: Cloud Access Security Brokers (CASBs)
Cloud Access Security Brokers (CASB) are security tools that act as intermediaries between an organization's devices and the internet. They play a crucial role in monitoring and controlling cloud service usage, providing valuable insights into application activity and user behavior.
By observing network traffic, CASBs can identify and list the cloud applications being used within an organization. This method is particularly useful for uncovering applications that may not be explicitly listed or managed through other discovery methods.
Zluri integrates with CASBs to gain an exhaustive list of cloud applications utilized across the organization. It provides granular details on user interactions with cloud applications. Further, Zluri collects and analyzes information on URL access patterns, including timestamps of when URLs were opened and closed.
By leveraging CASB data, Zluri offers enhanced visibility into cloud application usage and user behavior. This information supports better management and optimization of cloud resources, as well as improved security monitoring.
7: Human Resource Management Systems (HRMS)
Human Resource Management Systems (HRMS) are essential tools for managing employee information, including personal details, department affiliations, and job roles. While HRMS primarily focuses on employee data rather than directly monitoring application usage, it provides valuable insights that can aid in discovering and managing SaaS applications.

Zluri integrates with HRMS to import and utilize employee data, such as department, user roles, and job titles. This integration helps in mapping employee information to application usage, though it does not directly track application usage itself.
By aligning employee data from HRMS with SaaS application management, Zluri can better understand which employees are using which applications and ensure appropriate access levels.
Zluri can use departmental data from HRMS to analyze application usage patterns within different teams or departments. Further, this insight helps in optimizing application deployments and managing licenses more effectively based on departmental needs.
8: Directories
Directories, such as Google Directory and Azure Active Directory (AD), are central repositories for managing user identities, roles, and access permissions within an organization. These directory services are critical for handling authentication and authorization across various applications and services. Zluri leverages data from these directories to enhance its discovery and management of SaaS applications.
By analyzing directory data, Zluri can map user access to different SaaS applications based on group memberships and role assignments. This helps in identifying which users have access to which applications and ensures that access rights are appropriately aligned with their roles.
Further, directories provide insights into user authentication events, such as logins and access attempts. Zluri uses this data to monitor application usage patterns, helping to identify frequently used apps and detect any unusual or unauthorized access attempts.
Now, let’s understand the benefits that you can avail from Zluri’s discovery engine.
Advantages of Zluri's Discovery Engine

Eliminates shadow IT. Surfacing unauthorized applications is what lets IT actually act on them, bringing unapproved tools under policy instead of leaving them invisible indefinitely.
Surfaces identities other approaches miss. External users and non-human identities, service accounts, AI agents, APIs, routinely carry standing access with no clear owner. Discovery that stops at "which employees use which apps" misses exactly the identities most likely to go unreviewed for years.
Real-time app and access insight. Knowing who (or what) has access to an app, at what level, and how often it's actually used turns software and access decisions into something grounded in current data instead of institutional memory.
Better SaaS spend visibility. Identifying idle and barely-used applications is the direct path to cutting spend, redirecting budget toward the tools that are actually earning their cost.
Stronger security and compliance. Comprehensive visibility into every identity and access level is what keeps every application aligned with industry standards, avoiding both the security exposure and the regulatory penalty that come from a gap nobody caught.
What Happens After Discovery: Turning Visibility Into Intelligence
Finding every identity and application is the necessary first step, but raw discovery data on its own doesn't tell you what to actually do. That's the job of IRIS, Zluri's Identity Risk Intelligence System, the layer that takes everything the discovery engine surfaces and turns it into context someone can act on.
IRIS runs that transformation through four stages.
- Aggregation and staging ingests the identity signals coming in from all eight discovery methods while preserving where each piece of data originally came from.
- Normalization and canonicalization standardizes those formats and merges duplicate identities into single, canonical records, so the same person or service account showing up under three different sources doesn't get treated as three different entities.
- A relationship graph then connects identities to their access, mapping effective permissions and revealing access paths that a flat permissions list would never show, how access was actually granted, and where it quietly spreads from there.
- Finally, intelligence and decisioning detects risks and anomalies in that graph, prioritizes them by actual exposure, and recommends what to do about each one.
In practice, that's what separates "we found the app" from something genuinely useful: contextual spend insight that flags which discovered subscriptions are worth optimizing and which aren't, risk and compliance signals that surface orphaned accounts, dormant access, and toxic permission combinations before they're exploited, and direct recommendations for correcting access issues rather than just a report noting that they exist.
Discovery answers what's out there. IRIS answers what matters about it, and what to do next.
Book a demo to see your actual apps and identities, discovered from eight sources at once.
Frequently Asked Questions
Why does Zluri use eight discovery methods instead of one comprehensive source?
Because every method has a specific blind spot. SSO only sees applications integrated with it, finance records show spend but not usage, browser extensions can't see activity outside the browser. Combining sources is what gets discovery close to complete rather than trading one gap for another.
Does Zluri's discovery engine work without direct integrations for every application?
Yes. Applications without a direct integration still get surfaced through the other seven methods, SSO logins, finance records, browser activity, and more, which is specifically what catches shadow IT and employee-purchased tools that were never part of a formal integration list.
How current is the data Zluri's discovery engine surfaces?
It depends on the source. SSO and directory data reflect real-time login and access events. Browser extension data aggregates at least daily. Finance data updates as transactions sync from connected systems or get uploaded manually. The combination is what keeps the overall picture current even where any single source lags.
Is browser extension-based discovery a privacy risk for employees?
Zluri's browser extension is scoped deliberately: it doesn't read cookies, browsing history, or page content, only activity against domains on its own SaaS application list. It's also optional, and admins can see and manage installation status directly rather than it running invisibly in the background.
Does the discovery engine find non-human identities like service accounts and API tokens, not just employee accounts?
Yes, and this is often the bigger blind spot. Service accounts, AI agents, and API tokens frequently hold standing access to sensitive applications with no individual person accountable for reviewing them. Several of the eight discovery methods, SSO and identity providers, directories, and direct integrations in particular, surface these identities alongside human ones, since they typically live in the same underlying systems.
How does discovery handle external users like contractors and freelancers?
External users usually sit outside HRMS entirely, since they're not employees, which is exactly why relying on HR data alone would miss them. SSO logs, direct app integrations, and directory data all pick up external accounts as long as they're provisioned through a connected system, closing the gap that HRMS-only visibility would leave open.
















