Written by: Ian Engelbrecht

Picture this.......... It’s 2 PM. You’re trying to finish an important project, but you realize you’ve spent half your workday just clicking.

You switch from your CRM, to a project management app, into a Teams chat and back to an analytics dashboard. You stare at a monitor with 30 open tabs wondering......

Why does my organization need so much software just for me to do my basic job?

This is the modern workday. We’ve engineered an environment where the actual work is completely eclipsed by the navigational overhead. Software was supposed to be a productivity tool, but it's become a labyrinth.

The Financial Cost of "Frankenstacks" The old IT standard was to buy a specialized tool for every specific business problem. Fast forward to today, and this philosophy has created fragile "Frankenstacks" disjointed, siloed architectures that don't share data natively.

CFOs business owners are leading the charge against this tool sprawl. According to the Zylo SaaS Management Index, the average enterprise runs 305 apps even SMBs are juggling 50 to 100+ apps. More concerning is 53% of software licenses go unused in a typical month.

It’s the equivalent of paying for 12 streaming services but only watching Netflix everyday.

The AI Shelfware Problem In the last two years we saw a boom in AI adoption but standalone AI apps saw the lowest utilization (just 38%). Because of human behavior, if a tool isn’t already in our workflow, we ignore it.

So, the market adapted. CRM, Analytics, and Productivity tools started embedding AI as copilots. Summarizing data without leaving your current UI became the path of least resistance.

But this created a new problem. If just 40% of those 305 enterprise vendors embed generative AI, did we just create 120 shadow AI agents?

The Complexity Tax & Human Latency Tool sprawl isn't just a financial drain, it introduces a massive complexity tax. Inside the average SOC, security teams are managing 40-80 different tools & this is just as crippling for a SMB IT team or their MSP trying to secure an environment without dedicated headcount.

Modern breaches move at machine speed, breakout times are down to minutes or seconds. Meanwhile, MTTD and MTTR are delayed as defenders cross-correlate indicators across fragmented tools. Just as we design data centers around network and disk latency, we must now design platforms to overcome cognitive latency. Humans have become the bottleneck.

The NHI Explosion To reduce this cognitive latency, we are turning to unified portals, using APIs and automation to weave these 300+ applications together.

But this introduces the most critical cybersecurity threat of this era: the explosion of Non-Human Identities (NHIs).

We are now looking at a 100:1 ratio of NHIs to human identities.

Humans are easily managed through JML (Joiner, Mover, Leaver) policies. But when a developer creates a temporary API key or service account, it often gets forgotten. We leave behind active identities that are easily exploited, and we refuse to rotate them out of fear of breaking dependency chains.

Agentic AI has poured gasoline on this fire. With the rapid adoption of MCP (Model Context Protocol) allowing AI to interact with external systems, static keys and hardcoded secrets have drastically increased the attack surface. We are finally paying the price for years of overlooking NHI credential hygiene.

So the question I keep coming back to is...

Are we actually solving tool sprawl? Or are we simply moving the complexity from humans to machines?

Related: Your Company Has AI Everywhere. So Why Isn’t It Getting Faster?