Skip to content
Article

What Is SaaS? Examples, Benefits and SaaS Integration

SaaS means using software over the internet by subscription, with nothing to install. Examples, shared responsibility and SaaS integration explained.

Oğuzhan Gerçek··7 min read
What Is SaaS? Examples, Benefits and SaaS Integration

Short answer: SaaS (Software as a Service) means using an application over the internet by subscription, with nothing to install. The provider runs the servers, the operating system, the application itself and its updates; all that is left to you is using it from a browser or a client app. Email, office suites and CRM are the best-known examples. But some responsibilities never pass to the provider in any model: data, user accounts and access permissions stay with you.

What is SaaS?

Under the definition in SP 800-145 from the US National Institute of Standards and Technology (NIST), with SaaS the consumer uses the provider's applications running on a cloud infrastructure. The consumer does not manage the network, servers, operating systems, storage or even individual application capabilities; its control is limited to user-specific application settings.

In practice this means acquiring the right to use software by subscription instead of buying it and installing it on your own servers. Payment is usually per user, monthly or yearly; the application runs in the provider's data center and can be reached from anywhere with an internet connection.

The best-known examples fall into these groups:

  • Email and office apps: Microsoft 365, Google Workspace
  • Customer relationship management (CRM): Salesforce
  • Communication and meetings: Zoom, Slack
  • IT service management: ServiceNow

How does SaaS work?

NIST's cloud definition includes pooling resources in a multi-tenant model: the same application and infrastructure serve many customers together, each customer's data is kept logically separate, and resources are assigned dynamically among customers according to demand.

For the user, this architecture has three consequences:

  • The provider does the updates: New versions reach everyone; there is no upgrade project for you to run. In exchange, you cannot choose when a change arrives.
  • Scaling is easy: Adding users means adding subscriptions; growing the infrastructure is the provider's job.
  • Customization is limited: You can configure the application only as far as the provider allows; you have no access to the source code or the infrastructure.

SaaS vs IaaS vs PaaS

The three models differ in where responsibility changes hands. With IaaS the provider runs the infrastructure; the operating system and everything above it is yours. With PaaS the operating system and the platform the application runs on also pass to the provider; you bring your application. With SaaS the application itself belongs to the provider too. We compare the three side by side in our IaaS, PaaS and SaaS article.

Who is responsible for what in SaaS?

The provider running the application does not mean everything is the provider's. According to Microsoft's shared responsibility table, four responsibilities always stay with the customer, whatever the deployment model: data, endpoints, user accounts and access management. In SaaS, that means:

  • Data: Classifying and protecting data, and making sure it can be recovered after accidental deletion or ransomware, is your responsibility. You need to know which scenarios the provider's recycle bin and retention periods cover, and plan a separate backup for the ones they don't.
  • Accounts and access: Creating accounts when people join, closing them when they leave, multi-factor authentication and regular permission reviews. The open account of a departed employee is a gap in your layer, however secure the provider is.
  • Endpoints: The security of the laptops and phones that connect to SaaS.
  • Configuration: Sharing settings, external user access and third-party app permissions.

Then there are the provider's own outages: planning how work continues when the application is down is also yours. We cover that preparation in our SaaS outages article.

What is SaaS integration?

Once an organization uses many SaaS applications, the real work is connecting them to each other and to its own systems. SaaS integration is built in three layers:

  • Identity (SSO): Users sign in to every application with one session through the organization's identity system, not with a separate password for each. The connection uses the SAML 2.0 or OpenID Connect standard. When an employee leaves, disabling the account in the identity system blocks new sign-ins to every application connected through SSO.
  • User provisioning (SCIM): Accounts are created and removed in SaaS applications automatically. The standard for this is the SCIM protocol (RFC 7644), published by the IETF in 2015.
  • Data (API): Data flows between applications through the providers' APIs and event notifications (webhooks). A customer record moving from the CRM to the ERP, or a form turning into a support ticket, is this layer's job.

The part most often skipped when designing an integration is failure: hitting an API's rate limit, a provider outage, or a transfer that stops halfway. An integration without retries and monitoring quietly produces incomplete data. We handle the identity side in our identity management service and the data side in system integration.

Using SaaS in Türkiye: KVKK and data residency

A significant share of SaaS tools run in data centers abroad. If an application that processes personal data is hosted outside Türkiye, using it counts as a cross-border data transfer under the KVKK (Türkiye's personal data protection law), and the conditions in Article 9, amended as of June 1, 2024, apply. We cover the details in our article on KVKK and cross-border transfers. Rules are stricter for banks; we look at them in our BDDK article.

How big is the SaaS market?

According to IDC's forecast of March 4, 2026, worldwide public cloud spending will grow more than 21% year over year in 2026 and pass $1 trillion. More than half of that spending goes to SaaS; the fastest-growing category is PaaS, up more than 37% year over year.

When is SaaS the right choice?

For processes that work much the same in every organization, such as email, office apps, HR or accounting, SaaS is often the right choice: running that software on your own servers means dedicating a team to work that does not set you apart. It needs more careful thought when:

  • The application has to be customized deeply to the organization's processes
  • Sector regulation requires data to stay in the country (as in banking) and the provider has no region in Türkiye
  • The business stops when the application stops, and the provider's service level commitment (SLA) does not cover that risk
  • It is unclear in what format, and how quickly, your data will be returned when the contract ends

Frequently asked questions

What does SaaS mean? Software as a Service: using an application over the internet by subscription, without installing it.

What are examples of SaaS? Email and office suites such as Microsoft 365 and Google Workspace, CRMs such as Salesforce, and communication tools such as Zoom and Slack are the best-known examples.

What is the difference between SaaS and installed software? With installed (on-premises) software you buy the license, install it on your own servers, and handle updates and operation yourself. With SaaS you get the right to use it by subscription; installation, updates and infrastructure are the provider's.

Is SaaS secure? The security of the infrastructure and the application is the provider's; the security of accounts, access permissions, configuration and data is yours. So how secure a SaaS application is depends as much on how your layer is managed as on the provider.

Should SaaS data be backed up? Data stays the customer's responsibility in every model. Check which scenarios the provider's recycle bin and retention periods cover, and plan a separate backup for the ones they don't.

What is SaaS integration? Connecting SaaS applications to the organization's identity system (SSO), user provisioning (SCIM) and other applications (API). The goal is that users work with single sign-on, accounts are managed automatically, and data does not have to be moved between applications by hand.

Sources