By NHI Mgmt Group Editorial TeamBased on Zluri: “How to Get More Out of Harvest Via Zluri’s Integration?” (June 26, 2025)

TL;DR: Automated user discovery, license management, provisioning, deprovisioning, and access reviews in Harvest show how SaaS administration and user lifecycle controls converge when teams need tighter governance over who can use time-tracking and invoicing functions, according to Zluri. The deeper issue is that manual access handling still creates avoidable privilege and offboarding gaps across identity programmes.


At a glance

What this is: This is Zluri’s discussion of how Harvest integration surfaces gaps in user lifecycle handling, licence management, and access reviews across SaaS administration.

Why it matters: It matters because IAM teams managing human access and SaaS governance still need reliable joiner-mover-leaver controls, not just convenient app administration.


Context

Harvest is a time-tracking and invoicing application, but the governance issue emerges when access to its billing and project functions is still managed manually. In identity terms, the problem is not feature use, it is whether provisioning, deprovisioning, and review steps follow a consistent lifecycle.

Zluri frames the integration as a way to automate user discovery, licence allocation, and offboarding in Harvest while preserving control over who can see billable rates or create invoices. That makes the article relevant to human IAM and SaaS access governance, where role drift and delayed offboarding often create avoidable risk.


Key questions

Q: What breaks when Harvest access is managed manually instead of through lifecycle controls?

A: Manual handling usually breaks at the handoff between onboarding, role change, and offboarding. Users can keep licences or permissions after they no longer need them, which creates stale access and weakens auditability. The real failure is not just inefficiency. It is the inability to prove that every Harvest entitlement still matches an active business need.

Q: Why do unused SaaS accounts create security risk?

A: Unused SaaS accounts are risky because they often remain tied to valid entitlements even after the business has stopped using them. If offboarding, role change, and access review processes are weak, those accounts can persist as dormant access paths that are still reachable if credentials or session tokens are abused.

Q: What should IAM teams do when employees leave a SaaS-supported role?

A: They should revoke the application account, remove any role-based privileges, and verify that connected functions such as billing access are also withdrawn. Offboarding is only complete when the identity no longer has a path into the application or its sensitive actions. Partial removal still leaves the governance gap open.

Q: How should organisations decide who can see billing and invoice functions in Harvest?

A: Grant those permissions only to roles that genuinely need them, then review them separately from ordinary app access. Billing visibility and invoice creation are governed entitlements because they touch financial information and customer-facing actions. Treat them as sensitive access, not convenience settings, and revoke them when the role no longer requires them.


Technical breakdown

Why manual Harvest administration creates lifecycle drift

Manual administration creates drift because access changes happen in pieces rather than as a governed lifecycle. A user may be added, assigned a licence, and later removed from one function but not another, especially when different teams handle onboarding, billing access, and offboarding separately. In IAM terms, that leaves gaps between entitlement assignment and entitlement revocation. The article’s core point is that governance fails when lifecycle actions are treated as one-off tasks instead of a controlled process tied to role changes and departure events.

Practical implication: map Harvest access changes to a single joiner-mover-leaver process with clear ownership for each entitlement state.

How licence allocation and access reviews intersect in SaaS governance

Licence management and access reviews are closely linked because unused access often persists long after it stops being operationally needed. If licences are not periodically reclaimed and reviewed, organisations pay for inactive accounts and retain unnecessary authorisation paths. In SaaS environments, that matters as much for cost control as for security control. Review processes need to confirm not only who is active, but whether the assigned role still matches current job function and whether privileged features such as invoice creation remain justified.

Practical implication: combine licence recertification with periodic entitlement review so access is removed when business use no longer supports it.

Why billable-rate access is a governance boundary, not just a convenience setting

Access to billable rates and invoice creation is a governance boundary because it exposes financial data and customer-facing actions, not merely interface preferences. The article shows that project managers may need this access, but that the permission should be tightly tied to role and revoked when the role ends. This is a standard identity control problem: privilege should reflect current responsibility, and sensitive business functions should not remain open after job change or departure. The underlying issue is entitlement precision, not software usability.

Practical implication: treat billing visibility and invoice rights as sensitive entitlements and place them under explicit role-based approval and revocation rules.


NHI Mgmt Group analysis

Harvest-style SaaS workflows expose an identity lifecycle gap, not a point product problem. The article is really about what happens when app administration, licensing, and offboarding are handled as disconnected tasks. That pattern leaves access lingering after it is no longer needed, which is exactly where SaaS governance fails in practice. The practitioner conclusion is that lifecycle control has to sit above the application layer, not inside individual tool workflows.

Unused licences and inactive accounts are the same governance signal viewed from two angles. One is cost leakage, the other is access persistence. Organisations often treat those as separate operational issues, but they usually point to the same weakness: entitlement reviews are not being used to drive revocation. The implication is that access reviews without licence reclamation miss the control objective.

Billable-rate visibility is a sensitive entitlement, not an ordinary UI permission. Once an account can see pricing or create invoices, the access path carries commercial and fraud exposure as well as standard insider-risk concerns. That means role mapping must be tighter than broad job titles, and offboarding must revoke business-function permissions with the same discipline used for core application access. Practitioners should classify these rights as governed entitlements, not convenience settings.

Human IAM and SaaS governance meet in the same failure mode: delayed revocation. The article illustrates a familiar pattern where joiner-mover-leaver processes are technically present but operationally weak. The identity programme may know who should have access, yet still fail to remove access quickly or completely when roles change. The result is not just excess privilege, but a governance model that cannot prove entitlement currency.

Access review is the named concept that best captures this article’s value. Discovery, licensing, provisioning, and deprovisioning only become meaningful when they feed a reviewable governance record. Without that record, organisations can automate account handling but still not answer the most important question: whether each Harvest entitlement remains justified. The practitioner takeaway is to treat lifecycle evidence as the real control surface.

What this signals

Lifecycle governance is the real control surface in SaaS administration. Harvest-style integrations can automate tasks, but they do not remove the need to decide who should have access, for how long, and under what role condition. Organisations that rely on ticket-based administration without lifecycle evidence will continue to accumulate access drift.

Access reviews only matter when they lead to removal or reclamation. A review that confirms access but does not reclaim licences or revoke stale entitlements leaves the underlying problem unchanged. For IAM teams, the operational question is whether review results flow into deprovisioning and entitlement cleanup.

Billing-related permissions should be treated as governed business functions. Once users can see rates or create invoices, the access boundary crosses from simple app use into financial control. That makes role precision and timely offboarding more important than broad application availability.


For practitioners

  • Tighten Harvest joiner-mover-leaver workflows Tie account creation, role changes, and deprovisioning to one lifecycle process so access is not managed as separate admin tasks.
  • Reclaim inactive Harvest licences regularly Use discovery and usage review to identify unused licences and return them before renewal or role reassignment.
  • Review billing and invoice permissions as sensitive entitlements Limit billable-rate visibility and invoice creation to the smallest role set that genuinely needs those functions.
  • Remove access immediately when employment or role changes Make offboarding trigger revocation of Harvest access and any connected permissions, including project manager functions.
  • Include SaaS access in periodic recertification Confirm that Harvest users, licences, and privileged functions still match current business need during access reviews.

Key takeaways

  • Harvest administration becomes an identity governance issue when provisioning and deprovisioning are still handled manually.
  • Inactive licences and stale accounts point to the same weakness, which is a lifecycle process that is not closing access cleanly.
  • Billing visibility and invoice creation should be treated as sensitive entitlements and revoked with role change or offboarding.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63C — FederationThe article centers on SaaS access governance and lifecycle handling for application access.
Recommendation — Apply federation governance to ensure app access changes are reflected consistently across connected SaaS systems.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsHarvest access, billing rights, and licence assignment are entitlement-control problems.
Recommendation — Use PR.AA-05 to review and revoke Harvest entitlements when role need changes.
CIS Controls v8CIS-5 — Account ManagementThe article focuses on adding, removing, and reviewing user access across SaaS apps.
Recommendation — Apply CIS-5 to manage Harvest accounts through a defined joiner-mover-leaver process.
ISO/IEC 27001:2022A.5.15 — Access ControlThe post highlights how access should be limited and withdrawn as roles change.
Recommendation — Enforce A.5.15 so Harvest access follows role need and is removed when no longer justified.

Key terms

  • Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
  • Deprovisioning: Deprovisioning is the removal of access when a user changes roles or leaves an organisation. For security teams, it is the point where stale accounts, tokens, and permissions should disappear. Weak deprovisioning leaves residual access that can outlive the business need that created it.
  • Licence Reclamation: Licence reclamation is the removal or downgrade of software entitlements that are no longer justified by usage. In identity governance terms, it is a lifecycle action based on observed need, and it becomes more effective when usage telemetry is reliable enough to trigger automated review or deprovisioning.
  • Sensitive Entitlement: A sensitive entitlement is any access right that exposes financial, administrative, or operational actions rather than simple application viewing. In this article’s context, billable-rate visibility and invoice creation are sensitive because they influence customer-facing and financial workflows.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org