Join our Newsletter — 33% off our NHI Course

Why do ghost licenses and delayed offboarding create security risk in SaaS environments?

Ghost licenses often indicate that access persists after employees move roles or leave, which weakens identity control and increases the chance of misuse. When offboarding is slow or incomplete, teams lose track of who can still reach business systems. That creates unnecessary exposure, especially in large SaaS estates where ownership and license usage change frequently.

Why This Matters for Security Teams

Ghost licenses are not just a procurement cleanup issue. In SaaS estates, a license often carries access, group membership, API scopes, delegated admin rights, and downstream app trust. When offboarding is delayed, those entitlements can remain active long after a role change or departure, weakening identity control and creating a ready path for misuse. Guidance from the NIST Cybersecurity Framework 2.0 still applies here: access must be governed as a lifecycle, not a one-time event.

NHI Management Group’s NHI Lifecycle Management Guide and Top 10 NHI Issues both stress that standing access, stale ownership, and poor deprovisioning are recurring control failures. The risk is amplified in SaaS because entitlements are often distributed across HR, IT, app owners, and procurement, so no single team sees the full picture. In practice, many security teams encounter unauthorized persistence only after a former employee account has already been used, rather than through intentional offboarding verification.

How It Works in Practice

Delayed offboarding creates risk because SaaS access rarely ends in one place. A user may lose the primary login, but still retain a license, an OAuth grant, a shared mailbox, an admin role, or an integration token attached to the same account. If a license remains assigned, that account may still be billable and, more importantly, still be functional. The State of Non-Human Identity Security reports that 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, which is a useful proxy for how easily delegated SaaS access can disappear from view.

Operationally, teams should treat SaaS entitlement removal as a chained workflow, not a single checkbox:

  • disable the primary identity in the directory or IdP;
  • revoke sessions, tokens, and OAuth grants;
  • remove group-based and direct app assignments;
  • transfer ownership of records, files, automations, and shared assets;
  • verify that admin, billing, and support roles are removed;
  • confirm the license is returned to the pool only after access is fully cut off.

This is where the Ultimate Guide to NHIs becomes relevant even for human accounts: lifecycle discipline matters whether the identity is human or non-human, because the control failure is the same, which is stale privilege. SaaS environments also benefit from periodic entitlement reconciliation against HR events, so role changes trigger review before access drift becomes permanent. These controls tend to break down when app ownership is decentralised and provisioning is manual, because no one team can reliably revoke every downstream entitlement.

Common Variations and Edge Cases

Tighter offboarding often increases operational overhead, requiring organisations to balance fast access removal against business continuity for shared accounts, long-lived workflows, and regulated record retention. Some SaaS tools do not support clean revocation of nested permissions, so best practice is evolving toward compensating controls rather than assuming complete automation.

Shared service accounts, contractor access, and acquired-company tenants are common edge cases. A user may be gone, but the license may be tied to a service workflow, a finance approval chain, or an integration that would break if removed too early. In those cases, current guidance suggests separating human access from functional automation, documenting the owner of each entitlement, and using short review windows instead of open-ended exceptions. The Salesloft OAuth token breach is a reminder that SaaS trust chains can be abused quickly once a token or delegated grant survives past its intended use. Former employee tokens remaining active is a recurring lifecycle failure, not an edge case, and the 2025 State of NHIs and Secrets in Cybersecurity underscores how persistent those exposures can be.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 Ghost licenses often reflect stale NHI lifecycle ownership.
NIST CSF 2.0 PR.AC-4 Offboarding is an identity access control and review problem.
NIST SP 800-63 Lifecycle assurance depends on timely deactivation of digital identities.
NIST AI RMF AI RMF governance maps to ownership and accountability for access decisions.
NIST Zero Trust (SP 800-207) Zero Trust requires continuous verification, not lingering trust after departure.

Inventory SaaS identities, then remove unused entitlements and revoke stale access on every offboarding event.