For generating an accurate and informative report,
you need to tag the sanctioned applications consistently across
firewalls with multiple virtual systems, and across firewalls that
belong to a device group on Panorama. If the same application is
tagged as sanctioned in one virtual system and is not sanctioned
in another or, on Panorama, if an application is unsanctioned in
a parent device group but is tagged as sanctioned in a child device
group (or vice versa), the SaaS Application Usage report will report
the application as partially sanctioned and will have overlapping
results.