By NHI Mgmt Group Editorial TeamBased on Zluri: “Why Automating User Lifecycle Management is Crucial” (September 12, 2025)

TL;DR: Manual onboarding, role changes, and offboarding leave SaaS access spread across ticket queues and spreadsheets, which slows productivity and increases the chance that stale privileges survive after employees leave, according to Zluri. Automating user lifecycle management shifts access governance from ad hoc handling to repeatable provisioning and deprovisioning discipline.


At a glance

What this is: This article argues that automating user lifecycle management reduces manual access handling across onboarding, role change, and offboarding by making provisioning and deprovisioning repeatable.

Why it matters: It matters because identity teams cannot reliably govern SaaS access when employee changes depend on tickets and spreadsheets instead of controlled lifecycle workflows.


Context

User lifecycle management is the governance process that creates, updates, and removes access as employees join, move, or leave. The article’s core point is that manual handling of those changes leaves gaps in SaaS access control, slows provisioning, and makes revocation easy to miss.

In IAM and IGA programmes, lifecycle discipline is what prevents access from drifting away from job role and employment status. For security and operations teams, the practical question is not whether onboarding or offboarding happens, but whether those events are executed consistently enough to keep access current.


Key questions

Q: What breaks when lifecycle management is still manual?

A: Manual lifecycle management creates delays between a business event and the identity update that should follow it. New hires wait for access, movers accumulate old permissions, and leavers keep credentials longer than they should. The result is predictable drift, avoidable audit issues, and higher security exposure.

Q: Why do delayed offboarding processes create security risk?

A: Delayed offboarding creates security risk because access can remain active after the business relationship ends. Former users may still reach email, files, CRM, or admin tools, which expands the window for data theft or disruption. The issue is not the departure itself, but the period during which stale access still works.

Q: How do organisations know if SaaS lifecycle automation is actually working?

A: Look for evidence that provisioning, approval, and revocation happen in the same workflow and that stale licenses disappear after role changes or departures. If users keep access after they no longer need it, automation is only partially implemented. Effective lifecycle automation shows up as faster offboarding, fewer abandoned licenses, and cleaner audit trails.

Q: What should organisations check before automating onboarding and offboarding?

A: They should verify that account creation, access removal, notification steps, and audit logging all complete in the right order across every connected system. Offboarding is especially sensitive because delayed revocation leaves lingering access after employment ends. If any system can lag behind the workflow, the process is not yet safe to automate end to end.


Technical breakdown

Why manual lifecycle handling breaks access governance

Manual lifecycle handling splits one identity journey across ticket queues, spreadsheets, and disconnected app consoles. That fragmentation makes it hard to see who has access, why they have it, and whether that access still matches the employee’s role. In practice, the failure is not only speed. It is that the governance state becomes distributed across people and tools, so entitlement changes lag behind real employment changes. When that happens, access review and deprovisioning both lose reliability because the system of record is no longer authoritative.

Practical implication: centralise lifecycle events so access state changes from one governed workflow rather than from scattered manual steps.

How automated provisioning changes day-one access

Automated provisioning shifts onboarding from reactive approval handling to predefined access assignment based on role or department. The article describes workflows that can assign SaaS apps and business resources in one run, which reduces waiting time and removes repetitive manual work. Technically, the key shift is that entitlement assignment becomes policy-driven and repeatable, not dependent on a person remembering to request or approve each app. That matters because day-one access is where productivity and control often collide: if access is too slow, users bypass process; if it is too loose, privilege sprawl starts immediately.

Practical implication: define role-based onboarding workflows so new hires receive only the access that matches their approved access profile.

Why offboarding is the highest-risk lifecycle control point

Offboarding is where lifecycle failure becomes a direct security issue. If access is not revoked promptly, former employees can still reach SaaS applications and sensitive data, creating a standing exposure window after separation. The article’s point is that manual offboarding is error-prone because admins must search for every app and remove access one by one. Automated deprovisioning closes that gap by revoking access and deactivating accounts from a single workflow. In governance terms, the control objective is complete removal, not just a best-effort cleanup.

Practical implication: make deprovisioning complete, auditable, and workflow-driven so no departed user retains unrevoked access.


Threat narrative

Attacker objective: The objective is to keep access alive after the employment relationship has changed, so credentials or entitlements can still be used against business systems.

  1. Entry occurs through an employee lifecycle event, such as joining, changing role, or leaving, when access must be created, updated, or removed.
  2. Escalation appears when those changes are handled manually across multiple apps, because stale entitlements and missed revocations persist beyond the intended access window.
  3. Impact follows when ex-employees retain access to SaaS applications and sensitive data, increasing the chance of misuse, data exposure, and downstream breach risk.
  • Internet Archive breach 2024: An exposed GitLab token opened Internet Archive code and 31 million user records; unrotated Zendesk tokens let the attacker back in weeks later.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Lifecycle governance fails when identity changes are treated as tickets instead of state changes. The article describes onboarding, role movement, and offboarding as separate manual tasks, but the real governance problem is that access is no longer updated as a single lifecycle state. When access control depends on human follow-through across tools, the identity record drifts from the employee record. That is not just inefficient. It is a governance failure that weakens both access assurance and auditability.

Automated provisioning is less about speed than about keeping entitlement assignment aligned with role truth. The article’s value proposition is often framed as productivity, but the deeper issue is consistency. If role-based access is not assigned in a repeatable way, the organisation cannot reliably prove that users received the right access at the right time. That matters across IAM and IGA because entitlement drift starts at onboarding, not at the first access review. Practitioners should treat provisioning workflow design as control design.

Offboarding is the clearest test of whether lifecycle governance actually works. The article rightly emphasises that delayed revocation creates security risk, and that risk is not abstract. Departed-user access is one of the simplest ways for stale privilege to outlive the employment relationship. The named concept here is revocation lag: the time between separation and complete access removal. When that lag is tolerated, governance is already failing, and practitioners should measure whether removal is complete, not merely initiated.

One identity, one governed lifecycle is the right model for SaaS-era access control. The article’s “one user, one identity” framing is directionally correct because it pushes organisations away from fragmented access handling. The practical implication is that lifecycle governance must be treated as a cross-app control plane, not a collection of app-by-app exceptions. For identity programmes, that means the real measure of maturity is whether joiner, mover, and leaver events are executed coherently across the estate.

What this signals

Revocation lag: the time between employee separation and full access removal is the lifecycle metric most likely to expose governance weakness. When that gap is measured and reduced, offboarding becomes a control instead of an afterthought.

Lifecycle automation is not only an efficiency project. It is how identity teams keep entitlement state aligned with employment state across SaaS applications, especially where manual cleanup has historically been the source of errors and stale access.


For practitioners

  • Map all joiner, mover, and leaver events to a single lifecycle workflow Replace ticket-driven onboarding and offboarding with one governed process that updates accounts, app entitlements, and deactivation status together.
  • Define role-based onboarding profiles Pre-approve the SaaS apps, business resources, and channel memberships that should be assigned when a user enters a specific role or department.
  • Audit revocation completeness at offboarding Check that every application, account, and access path is removed when employment ends, not just the main user account.
  • Track revocation lag as a control metric Measure the time between separation and full access removal so you can spot where manual cleanup still leaves a stale-access window.
  • Use automated status checks after workflow runs Review completed, failed, and pending lifecycle runs to verify that provisioning and deprovisioning actions actually executed as intended.

Key takeaways

  • Manual lifecycle handling creates governance drift because access updates depend on human follow-through across multiple systems.
  • The security risk is concentrated at offboarding, where incomplete revocation leaves former employees with access that should already be gone.
  • Automated lifecycle workflows improve control when they make assignment, change, and removal consistent, visible, and auditable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centres on revoking access when employees leave, which is the core offboarding control gap.
NHI-05 — Overprivileged NHIManual role changes and stale access create excess entitlement beyond the user’s current job needs.
Recommendation — Automate offboarding so all NHI access is revoked from every application when employment ends. Review lifecycle workflows for excess entitlement and trim access to the minimum role-appropriate set.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccount creation, modification, and disablement are the control actions discussed throughout the article.
Recommendation — Apply account management controls to make provisioning, modification, and disabling consistent and auditable.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about governing who keeps access as employees join, move, or leave.
Recommendation — Align entitlement workflows so access permissions are updated promptly when user status changes.
CIS Controls v8CIS-5 — Account ManagementThe article focuses on managing accounts across onboarding, role change, and offboarding.
Recommendation — Standardise account lifecycle handling so access removal is verified and not left to manual follow-up.

Key terms

  • User Life Cycle Management: User life cycle management is the end-to-end process of creating, updating, reviewing, and removing user identities and access across enterprise systems. It links identity governance to employee onboarding, role changes, and offboarding so access stays aligned with job responsibilities and business need.
  • Provisioning Workflow: A provisioning workflow is a structured process that turns an access request into an approved entitlement across one or more systems. It reduces manual handling by applying rules, approvals, and execution steps consistently so access is granted in a predictable, auditable way.
  • Deprovisioning: Deprovisioning is the removal of access when a user changes roles or leaves an organisation. For security teams, it is the point where stale accounts, tokens, and permissions should disappear. Weak deprovisioning leaves residual access that can outlive the business need that created it.
  • Identity Governance and Administration (IGA): A framework of policies, processes, and technology to manage and govern digital identities and their access rights. Increasingly extended to cover non-human identities alongside human users.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org