IT and security teams walk into budget conversations with soft savings: time saved, risk avoided. Finance funds hard savings: costs that visibly went down. Here's the difference and how to close it.
Every identity governance program produces genuine value. Faster provisioning, fewer manual tickets, smaller breach exposure, cleaner audits. And every year, programs producing that value walk into renewal conversations and struggle to defend their line item, while projects with weaker fundamentals sail through.
The difference usually isn't the value. It's the category of savings the case was built on, and IT and security teams that learn the category distinction stop losing winnable budget conversations.
What Soft Savings Are
Soft savings are value that's real but doesn't appear as a reduced cost in the accounts. In an identity program, they're most of what the program naturally produces:
- Time saved by automating provisioning and deprovisioning: hours the IT team gets back every week
- Risk avoided: the breach that didn't happen, the fine that wasn't paid, the audit finding that never materialized
- Productivity gained: employees getting access in minutes instead of days
- Process quality: fewer errors in exactly the records auditors examine
None of this is fake. Automating user provisioning genuinely frees up an IT team; avoided incidents genuinely protect the business. But notice what all four have in common: no ledger line gets smaller. The IT team's salaries are unchanged, the software bill is unchanged, the insurance premium is unchanged. The value is real and invisible to accounting at the same time.
Soft savings are values you have to describe. Hard savings are value finance can check.
What Hard Savings Are
Hard savings are cost reductions that show up in the accounts: a number that was one figure last quarter and is a smaller figure this quarter, traceable to a specific action. In an identity platform, they come from the SaaS management side:
- Reclaimed licenses from offboarded users and unused seats
- Tier downgrades for users on premium plans with standard-tier usage
- Cancelled redundant subscriptions: three tools doing one job, consolidated to one
- Better renewal pricing from consolidating fragmented contracts into one negotiation
Each of these reduces an actual invoice. When finance audits the claim, there's a before-number, an after-number, and the action connecting them.
Why Finance Weighs Them Differently
This isn't finance being difficult. It's how financial planning works, and IT and security leaders who understand it stop taking it personally:
- Hard savings are verifiable. A claim about reclaimed licenses can be checked against the vendor invoice. A claim about avoided breach cost can only be modeled, and every vendor's model says their product saves millions.
- Hard savings are bookable. Finance can put a reduced software line into next year's budget. It can't book "the team has more time" anywhere.
- Soft savings have been oversold to them for decades. Every tool pitch ever made included time-savings math (minutes per task × tasks per year × loaded hourly cost). Finance has learned to discount that arithmetic on sight, not because it's always wrong, but because it's unfalsifiable.
A budget case built purely on soft savings asks finance to fund a description. A case with hard savings in it gives finance something they can defend to their own stakeholders, which is the part IT and security teams tend to underestimate: finance has an audience too.
Finance isn't rejecting your value. It's rejecting claims it can't verify, because it has to defend your line item to someone else.
The Identity Program's Problem: It Naturally Produces the Wrong Kind
Here's why this distinction matters specifically for IT and security teams running identity programs. Governance work is soft-savings-heavy by nature: its best outcomes are avoided events and saved time, exactly the categories finance discounts.
An IGA-only platform makes this worse in a way most teams don't notice until renewal time. Every IGA frees licenses when it revokes access at offboarding, real hard savings, created automatically. But without license cost and contract data in the same platform, those savings can't be attributed: no number ties the revocation to a dollar figure, so the hard savings the program genuinely created stay invisible, and the case reverts to soft-savings arithmetic.
That's the quantified gap: per Zluri's ROI research, 43% of the total savings the platform produces are hard savings, and that's precisely the share an IGA-only setup can't prove. Without it, the business case is reduced to asserting that removing unused licenses obviously saves something, an argument finance has heard from every vendor, backed by no number they can check.
The fix is architectural, not rhetorical: SaaS management alongside the IGA on one platform is what turns created-but-invisible savings into attributed ones, and what makes the downgrade and consolidation categories possible at all.
What This Does to the Finance Relationship
The soft/hard distinction changes more than the pitch deck. It changes what kind of relationship IT and security have with finance:
The prose version of the contrast: with a soft-savings-only case, every budget cycle is a re-justification, IT describes value, finance discounts it, and the program survives on goodwill. With hard savings attributed on the same platform, finance gets numbers it was already looking for (spend visibility, renewal data, per-app cost), which gives it a working stake in the program rather than a gatekeeping role. And when the figures come from one platform, there's nothing to reconcile: both teams argue from the same numbers instead of about them.

One warning from the other direction: running SaaS management as a separate platform next to the IGA recreates the problem in a new form. Two platforms counting apps, licenses, and spend independently will not agree, and every budget conversation starts with reconciling whose numbers are right. Conflicting figures put finance and IT on opposite sides of the table; what that full setup costs is its own analysis in the real TCO of running the two separately.
How to Build the Case With Both
Neither category alone makes the full argument. The working structure:
- Lead with hard savings, because they establish credibility: reclaimed licenses, downgrades, and consolidations with before/after numbers. This is the part of the case finance verifies, and verification of one claim buys trust for the rest.
- Let hard savings carry the cost argument: documented software savings offsetting a meaningful share of the platform cost turns "fund our program" into "the savings cover the platform, and the governance comes with it."
- Present soft savings as capacity and risk posture, not dollars. Hours returned to the team and exposure windows shortened are strong claims when they're not dressed up as ledger arithmetic. State them in their own units: days-to-provision, Mean Time to Revoke, tickets eliminated.
- Report on a cadence, not at renewal. Savings surfaced quarterly through governance dashboards mean the renewal conversation opens with a track record instead of a pitch, which is how the program's measurable value compounds politically.
Frequently Asked Questions
Are soft savings not worth mentioning to finance at all?
They're worth mentioning in the right units. Time saved and risk reduced are legitimate outcomes finance understands; what triggers the discount reflex is converting them into dollar figures via loaded-hourly-cost arithmetic. State soft savings as operational metrics (cycle times, ticket volumes, exposure windows) and let hard savings do the dollar talking.
Our IGA vendor gave us an ROI model with large soft-savings numbers. Should we use it?
Use it internally to understand the value drivers, but be careful presenting it as the core of a budget case. Finance teams see vendor ROI models constantly and know they're built to justify the purchase. A smaller number finance can verify beats a larger one it can't.
We already run a separate SaaS management tool. Doesn't that give us the hard savings evidence?
It gives finance a version of it, on a platform whose figures won't match the IGA's. The savings attribution problem isn't just having spend data somewhere; it's having the governance action and the cost data in one system, so a revocation carries its own dollar figure. Two platforms produce two counts and a standing reconciliation argument.
Is the 43% hard-savings figure universal?
It's the share found in Zluri's ROI research across its customer base; individual environments vary with license sprawl, headcount growth, and how much redundancy has accumulated. The direction holds regardless: a large minority of total platform value is hard savings, and none of that share is provable without SaaS management data in the platform.
Does leading with license savings undersell the security value of the program?
It funds the security value. The governance program's most important outcomes stay soft (risk posture, audit readiness, least privilege), and they're exactly the outcomes that need stable, defended funding. Hard savings are what make that funding easy to defend. Leading with them isn't reframing security as procurement; it's buying the program the budget stability its security outcomes need.
















