Nobody sets out to pay for four tools that write text. It happens one reasonable decision at a time: a general assistant, then a writing tool because it had a better editor, then a meeting notetaker, then whatever came bundled with a suite you already pay for. Each addition made sense. The aggregate does not.
The same accumulation happens with data access, and that is the part worth auditing more carefully than the invoices.
What changed in 2026
- Bundling absorbed standalone features. Capabilities that justified separate subscriptions — transcription, summarization, image generation — arrived inside suites people already pay for, making many standalone tools redundant.
- Shadow adoption grew in organizations. Individually expensed tools spread faster than procurement could track, which turned tool sprawl into a security question rather than a budget one.
- Data handling terms diverged sharply. The gap between vendors that train on your inputs and vendors that contractually do not became a meaningful basis for choosing between otherwise similar tools.
- OAuth grant accumulation got attention. People discovered dozens of live authorizations to services they had stopped using, with access still active.
The audit, by job rather than by tool
| Job to be done |
Ask |
| Drafting and editing text |
How many tools do this? Which one do you open by reflex? |
| Meeting capture and notes |
Is one recording every call while another sits unused? |
| Code assistance |
Editor plugin, standalone agent, and a suite feature? |
| Image or design generation |
How often, actually, in the last three months? |
| Search and research |
Does a general assistant already cover this? |
| Transcription |
Is it bundled somewhere you already pay? |
Listing by job rather than by subscription is what makes the duplication visible. A list of subscriptions looks like a set of distinct products. A list of jobs shows four products competing for one task, three of which you have not opened in weeks.
Then check usage honestly. Most tools show a last-used date or activity history. The subscription you are certain you use is frequently one you used enthusiastically for two weeks in spring.
The part that matters more than money
For each tool, find what it can reach. Connected email, calendar, cloud storage, code repositories, chat workspaces. Then check whether that access is still live — because cancelling a subscription does not automatically revoke an OAuth grant, and a dormant authorization to your entire email history is a real exposure regardless of whether you are still paying.
Go through the third-party app permissions in each major account you hold and revoke anything you do not recognize or no longer use. This is a fifteen-minute task most people have never done, and it typically turns up more than expected.
Also check the data terms for the tools you keep. Whether inputs are used for training, how long data is retained, and where it is processed vary substantially between vendors, and for anything touching client or employee data those differences matter more than feature comparisons. The same reasoning applies to connected agent tooling, where MCP security risks covers a related and growing surface.
Common mistakes
- Auditing the invoice only. Free tools with broad account access are frequently the larger risk.
- Keeping a tool because it was expensive. Sunk cost. The question is whether you use it now.
- Cancelling without revoking access. The grant survives the subscription.
- Ignoring bundled capability. You may already be paying for the feature you bought separately.
- Doing this once. Sprawl regrows. A quarterly pass takes twenty minutes and holds the line.
FAQ
How often should I do this?
Quarterly is enough for an individual. Organizations with expense-driven adoption benefit from a more frequent inventory.
What if a team depends on a tool I want to cut?
Consolidation needs a migration plan, not just a cancellation. Identify the replacement, verify it does the job, then move.
Is a single vendor for everything better?
Simpler for access management and often cheaper, at the cost of flexibility and vendor concentration. Reasonable people choose either way.
How do I find OAuth grants I have forgotten?
Check the security or connected-apps section of each major account — email, cloud storage, code hosting, chat. There is no single central list.
Where to go next
For the general version of this exercise, read how to do a subscription audit. For the data side, personal AI privacy checklist, and for connected tool risk, MCP security risks.