By NHI Mgmt Group Editorial TeamBased on Josys: “End-to-End Access Management Using Josys Workflows” (February 11, 2026)

TL;DR: A trigger-condition-action workflow model for onboarding, offboarding, access reviews, and license management across SaaS apps is described by Josys, and a study found that 89% of former employees still retained access to at least one application from a previous employer. The governance gap is not the lack of automation, but the lack of reliable lifecycle closure across dozens of disconnected systems.


At a glance

What this is: This is a SaaS access management workflow article that argues repeatable trigger, condition, and action automation helps close joiner, mover, and leaver gaps across disconnected apps.

Why it matters: It matters because IAM and IGA teams still lose control at lifecycle boundaries, where access, licensing, and offboarding decisions must stay consistent across many SaaS systems.

By the numbers:

  • 89% of former employees still retain access to at least one application from a previous employer.

Context

SaaS lifecycle management breaks down when joiner, mover, and leaver events have to be repeated manually across disconnected applications. The issue is not simply speed. It is whether identity governance can reliably close access, license, and review actions across the stack when the source of truth and the target apps do not move in lockstep.

Josys frames the problem as a workflow design issue: trigger, app, condition, action. That matters for IAM because lifecycle controls are only as strong as the weakest downstream system, and a successful offboarding or access review has to leave no residual access behind.


Key questions

Q: What breaks when employee offboarding depends on disconnected SaaS apps?

A: The first failure is that deprovisioning stops being automatic. If an app cannot accept identity or entitlement changes through a reliable control path, access removal falls back to manual work, which increases the chance of missed accounts, lingering admin rights, and audit findings after the employee leaves.

Q: Why does incomplete SaaS lifecycle closure increase identity risk?

A: Incomplete closure increases risk because access state becomes inconsistent across apps, licenses, and review records. That inconsistency lets stale entitlements survive, undermines accountability, and makes it harder to prove that joiner, mover, and leaver decisions were actually enforced everywhere they should have been.

Q: What are the signs that SaaS access review processes are not working?

A: A weak process usually shows up as poor visibility into which SaaS apps are used, unclear ownership for accounts, duplicated app functions, and inconsistent evidence for auditors. If teams cannot cross reference applications, users, authentication methods, and missing controls, the review process is not giving reliable governance signals. That usually means the estate is still fragmented and identity sprawl remains unchecked.

Q: How should IAM teams combine access reviews with license reclamation?

A: They should treat them as one closure process. If a reviewer says access is no longer needed, the workflow should revoke the entitlement, recover the seat, and record the result in a way that can be audited later. Otherwise governance stays descriptive instead of operational.


Technical breakdown

Why trigger-condition-action workflows matter for SaaS lifecycle control

A trigger-condition-action model turns lifecycle events into repeatable access decisions. The trigger starts the workflow, the condition limits who it applies to, and the action performs the access change, such as granting, revoking, notifying, or creating a ticket. In governance terms, this is an orchestration layer across SaaS applications, HR data, and identity systems. The technical value is not the workflow itself, but the way it reduces manual dependency between systems that do not natively share lifecycle state. Practical implication: treat workflow logic as part of the access control plane, not as a convenience layer.

Practical implication: govern workflow logic as part of the access control plane, not as a convenience layer.

How SaaS integrations affect onboarding and offboarding accuracy

The article highlights native integrations, webhook triggers, and HTTP requests as the mechanisms that connect lifecycle events to downstream SaaS changes. That means the real control surface is not just account provisioning, but integration coverage, event reliability, and whether every app that matters can be reached consistently. If a workflow cannot invoke the right app at the right moment, the lifecycle process leaves orphaned accounts or delayed entitlements behind. Practical implication: inventory which SaaS apps are reachable by automated lifecycle flows and which still require manual closure.

Practical implication: inventory which SaaS apps are reachable by automated lifecycle flows and which still require manual closure.

Where access reviews and license management converge

Access reviews and license optimization are often treated as separate operations, but in SaaS environments they are tightly linked. A review that confirms an entitlement should be removed is only useful if the action is executed immediately and verified afterward. Similarly, license reclamation without access validation can save money while leaving hidden permission paths intact. The article’s workflow model makes that linkage explicit by letting review responses trigger action. Practical implication: tie certification outcomes to revocation and seat recovery so governance closes the loop.

Practical implication: tie certification outcomes to revocation and seat recovery so governance closes the loop.


Threat narrative

Attacker objective: The objective is to preserve access after an employment or role change so accounts remain available for misuse, oversight, or lateral abuse inside SaaS data paths.

  1. Entry occurs through ordinary joiner, mover, or leaver events that are processed inconsistently across SaaS applications.
  2. Standing access persists because offboarding, review, or license changes do not reach every connected system at the same time.
  3. Impact appears when former users or stale accounts retain access to at least one application and keep a usable foothold in the environment.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Lifecycle closure is the real control boundary in SaaS identity governance. The article shows that automation only helps when every downstream app receives the same joiner, mover, or leaver decision. In practice, the governance problem is not triggering an action, but proving that the action reached every system that still matters. Practitioners should treat incomplete closure as a control failure, not an administrative inconvenience.

Disconnected SaaS stacks create access residue, not just operational friction. When onboarding, offboarding, review, and licensing are spread across separate tools, each handoff becomes a point where entitlement state can diverge. That divergence is exactly how stale access survives. The implication for identity programmes is that lifecycle assurance has to be measured by closure quality across the stack, not by the number of workflows deployed.

Workflow orchestration should be governed like identity policy, because it is identity policy. The trigger, condition, and action pattern is not merely process automation. It defines who gets access, when access ends, and which exceptions are tolerated. Once organisations understand that, the control conversation shifts from efficiency to accountability. Practitioners need deterministic lifecycle rules, not loosely coupled task automation.

Access reviews and offboarding are the same governance loop when SaaS is the target. A review that does not lead to enforced revocation leaves the programme with paper assurance and live exposure. Likewise, offboarding that does not feed license and entitlement cleanup keeps costs and risk aligned in the wrong direction. IAM teams should collapse these workflows into one closure model rather than managing them as separate disciplines.

Third-party exposure is the hidden multiplier in SaaS lifecycle failures. The article’s scenario is not limited to one app or one workforce segment; it reflects how permissions can persist wherever integrations, exceptions, and app-specific workflows exist. The named concept here is lifecycle closure gap: the distance between a governance decision and its confirmed removal everywhere it was applied. Practitioners should make that gap visible.

From our research library:

What this signals

Lifecycle closure gap: SaaS governance will increasingly be judged by whether offboarding and access review decisions actually propagate into every connected application. Teams that cannot prove end-to-end closure will keep carrying stale access, orphaned accounts, and audit uncertainty even when their workflows look mature on paper.

The practical shift is from managing individual SaaS admins to managing the reliability of the entire lifecycle path. That means measuring whether workflow triggers, integration coverage, and post-action verification produce a closed state, not just a completed task.


For practitioners

  • Map lifecycle closure across every SaaS app Identify where onboarding, offboarding, review, and license changes are executed manually, and mark every app that can still retain access after the source record changes.
  • Link offboarding to verified revocation Require each leaver workflow to confirm that access was removed in every connected system, not just that a ticket was opened or a request was issued.
  • Connect access review outcomes to execution Route reviewer decisions into automated revocation and license recovery actions so certification ends with a state change, not a report entry.
  • Surface shadow users and orphaned apps Use workflow coverage to expose accounts and applications that sit outside IT control, then reconcile them into the governed lifecycle path.

Key takeaways

  • The core issue is not whether SaaS access can be automated, but whether lifecycle decisions are fully enforced across every app that matters.
  • Josys cites a study showing that 89% of former employees still retain access to at least one application from a previous employer, which underscores how common lifecycle leakage remains.
  • The control that matters most is confirmed closure across onboarding, offboarding, reviews, and license recovery, because incomplete execution leaves live access behind.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centres on access that persists after joiner or leaver events.
NHI-05 — Overprivileged NHIStale SaaS access becomes overprivileged when role changes are not enforced everywhere.
NHI-09 — NHI ReuseReusing old app access across lifecycle changes creates hidden entitlement carryover.
Recommendation — Automate offboarding closures so every SaaS entitlement is revoked when the lifecycle event occurs. Review SaaS entitlements after role changes and remove privileges no longer needed for the job. Eliminate entitlement reuse by assigning lifecycle-specific access and revoking prior permissions at each change.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsSaaS lifecycle workflows are fundamentally about governing permissions and entitlements.
Recommendation — Apply PR.AA-05 to ensure entitlement changes are enforced consistently across SaaS applications.
CIS Controls v8CIS-5 — Account ManagementThe article is about keeping account state accurate across onboarding and offboarding.
Recommendation — Use account management controls to keep SaaS accounts aligned with current employment and role state.

Key terms

  • Lifecycle Closure: Lifecycle closure is the discipline of making sure access does not only get granted and adjusted, but also removed when the business need ends. In identity governance, it means provisioning, change, review, and revocation are treated as one control loop rather than separate tasks.
  • Trigger-Condition-Action Workflow: A trigger-condition-action workflow is an orchestration pattern that starts from an event, filters it through rules, and then performs a defined task. For identity governance, it is useful only when the final action changes real access state across connected applications.
  • Access residue: Access residue is the leftover access that remains after a user or account has changed status, moved roles, or left the organisation. It often appears in downstream applications, shared workspaces, and integrations, and it is one of the clearest signs that lifecycle governance is incomplete.
  • Shadow User: A shadow user is an account that exists outside the organisation's normal IT or IAM control plane. These accounts often surface after mergers, app sprawl, manual provisioning, or delegated admin use, and they matter because they can bypass standard lifecycle review and revocation processes.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org