Raeburn Research · Framework 2026

SaaS Duplication Risk Framework

A structured way to distinguish genuine technology waste from overlap that has a legitimate operational purpose. This is a methodology publication, not a claim about market-wide average waste.

Functional overlap

How many tools serve materially similar jobs, and whether the overlap is intentional resilience or accidental duplication.

Licence utilisation

Whether paid seats/features are actively used and whether entitlement exceeds operational need.

Integration duplication

Whether multiple tools create redundant connectors, sync jobs, middleware or manual reconciliation.

Data fragmentation

Whether customer, employee, operational or reporting data is split across competing sources of truth.

Administration burden

Time spent provisioning, supporting, renewing, reconciling and governing multiple tools.

Security surface

Additional identities, OAuth grants, vendors, data copies and privileged integrations introduced by the duplicated estate.

Exit friction

Contract, export, workflow, data-model and customisation barriers that make consolidation harder later.

Business criticality

Whether apparent duplication actually supports resilience, regulation, customer segregation or another justified requirement.

Suggested scoring

Score each dimension 0–5, where 0 means no material concern and 5 means severe evidenced risk. Do not simply add scores and call the result a saving. High scores identify where usage telemetry, contracts, interviews, architecture and security evidence should be investigated.

Evidence hierarchy

Prefer billing and entitlement exports, platform usage telemetry, integration inventories, source-of-truth mapping, administrator interviews and contract terms. Estimates should be labelled and separated from observed evidence.

Limitations

The framework does not establish causation, guaranteed savings or a universal benchmark. Consolidation can increase concentration risk, migration risk or loss of specialist capability. Decisions should include security, resilience, legal, operational and exit considerations.