TL;DR: Manual provisioning, deprovisioning, license cleanup, and scope selection become error-prone as app usage grows, creating avoidable access and compliance risk for IT teams, according to Zluri. The core issue is not automation itself but the governance assumption that human-paced user lifecycle management can still keep up with modern application sprawl.
At a glance
What this is: This is a Zluri analysis of Insightly lifecycle automation, showing that manual access control becomes unreliable as user counts, role changes, and app usage grow.
Why it matters: It matters because IAM teams cannot treat provisioning and deprovisioning as low-risk clerical work once app access, licence usage, and compliance obligations move faster than human review cycles.
Context
Manual user lifecycle management is the point of failure here, not the presence of automation. The article shows how provisioning, deprovisioning, role assignment, and licence cleanup become increasingly brittle when handled through repeated human steps inside Insightly.
For IAM and IGA teams, the governance issue is whether access administration still depends on human-paced coordination after the application footprint expands. That is a lifecycle control problem across NHI-adjacent tooling and human account management, because permissions, licences, and offboarding all need the same accountable process.
Key questions
Q: What breaks when user lifecycle management is still handled manually in SaaS environments?
A: Manual lifecycle management breaks at the handoff points. Joiners can wait for access, movers can keep the wrong permissions, and leavers can retain active access longer than intended. That creates operational drag for IT and IAM teams and increases the chance that sensitive code, reports, or governance data remain exposed after a user should have been removed.
Q: When does manual user provisioning become a compliance risk?
A: Manual provisioning becomes a risk when role changes, offboarding, or access exceptions happen often enough that humans cannot keep up. At that point, stale accounts and delayed removals become predictable failure modes. Automated lifecycle control is the point where identity governance starts matching the speed of the business.
Q: How can IAM teams tell whether access and licence governance are drifting?
A: Look for inactive users who still hold licences, users whose permissions no longer match their role, and licences that remain assigned after app usage drops. Those signals show that entitlement state is no longer aligned with operational need. When those mismatches appear together, lifecycle governance is already slipping.
Q: How should teams automate account changes without creating bad access policy?
A: They should define role mappings, approval conditions, and revocation rules before automating anything. Automation should execute a clear governance model, not replace one. If the underlying permissions are wrong, the workflow will simply apply the wrong access more consistently.
Technical breakdown
Why manual provisioning breaks at scale
Manual provisioning is a workflow problem, not just an administrative inconvenience. Each new user requires account creation, permission assignment, and profile updates, and every one of those steps creates a chance for inconsistent access or delayed onboarding. As application usage grows, the chance of oversight rises because the operator must navigate the same interface repeatedly, often across changing roles and entitlements. In governance terms, the control is only as reliable as the person performing it. Once user volume or role churn increases, that assumption stops being dependable.
Practical implication: move recurring onboarding steps into governed workflows with explicit role mapping and approval paths.
Why deprovisioning and licence cleanup are the same control problem
Deprovisioning and licence cleanup are usually treated as separate tasks, but the article shows they are part of one lifecycle control. When users leave, change roles, or stop using an app, stale access and unused licences both signal that entitlement state has drifted from business need. That drift creates security exposure, audit noise, and unnecessary software spend. The real issue is not just access removal, but maintaining authoritative ownership of who should still have access and which licences remain justified. If those two views diverge, governance weakens quickly.
Practical implication: align offboarding, access review, and licence reconciliation so the same source of truth drives all three.
How workflow automation changes the permission model
Workflow automation shifts the control point from manual administration to policy-driven execution. Instead of staff remembering which permissions to assign or revoke, the workflow encodes role, scope, and account actions so access changes happen consistently. In the article’s example, that includes onboarding flows, role selection, and revocation actions triggered from a central system. That matters because it reduces dependency on memory and ad hoc operator judgment. The architecture is still governance-heavy: automation only helps when the underlying scopes, roles, and approval conditions are already designed correctly.
Practical implication: define approval logic and role scope before automating account actions, otherwise the workflow only accelerates bad governance.
NHI Mgmt Group analysis
Manual lifecycle control is a governance debt, not an efficiency gap: The article shows that provisioning, deprovisioning, and licence cleanup all degrade once user volume and role churn rise. Human-paced administration can work at small scale, but it fails as soon as the organisation expects repeatable accuracy across many accounts. The practitioner lesson is that lifecycle governance must be designed as a control system, not handled as an inbox task.
Access and licence drift are the same failure mode in different forms: A user who still has access after changing roles and a user who still holds an unused licence both indicate entitlement state is no longer aligned to business need. That is why IAM and IGA teams should treat licence optimisation as part of access governance, not procurement housekeeping. The control objective is authoritative entitlement state, not just lower software spend.
Workflow automation exposes weak role design: Automation does not fix unclear scopes, bad role definitions, or missing approval logic. It makes those problems more visible because the same mistake is repeated at machine speed instead of human speed. The implication is that teams must tighten role design and lifecycle policy before they automate more deeply.
Lifecycle governance now spans human users and the systems that administer them: The article is about human access administration, but the operational pattern is familiar across all identity programmes. When a workflow becomes the place where access is granted and removed, the governance question becomes whether that workflow is authoritative enough to survive audit, turnover, and growth. Teams should judge automation by control integrity, not convenience.
Insightly lifecycle automation is really a visibility problem in disguise: The article’s repeated emphasis on identifying inactive users, unused licences, and current access scope shows that the core issue is entitlement visibility. Without that visibility, IT teams cannot know whether a licence, permission, or user record still reflects reality. Practitioners should read this as a reminder that lifecycle automation depends on accurate discovery first.
What this signals
Lifecycle automation is now an access-control design question: Teams should stop treating provisioning and deprovisioning as separate admin chores and start treating them as one entitlement lifecycle. Once roles, licences, and offboarding sit in the same operational flow, control quality depends on policy design and authoritative inventory, not manual effort.
The broader pattern is that application growth exposes every weak assumption in joiner-mover-leaver governance. If the organisation cannot keep access state, licence state, and employment state aligned, then the programme is already relying on human memory where machine-enforced workflow should be doing the work.
For practitioners
- Automate onboarding and offboarding workflows Replace manual account setup and removal with governed workflows that assign roles, create accounts, and revoke access from a central process instead of through repeated console work.
- Reconcile active users against licence holdings Review which users still hold Insightly licences, then compare that list to current app usage so unused licences and inactive accounts can be removed together.
- Tie role changes to access updates Make role changes trigger permission review so users who move departments do not keep access that no longer matches their job function.
- Define scope and approval logic before automation Set the scopes, approval conditions, and account actions that the workflow is allowed to execute before connecting the app to automated lifecycle management.
Key takeaways
- Manual user administration becomes unreliable when provisioning, deprovisioning, and licence cleanup all depend on repeated human action.
- Licence sprawl and access drift are connected symptoms of the same entitlement governance problem.
- Automation helps only when role design, approval logic, and lifecycle ownership are defined before the workflow goes live.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article repeatedly focuses on removing access when users leave or change roles. |
| NHI-05 — Overprivileged NHI | Stale or mismatched permissions are the core access risk highlighted by the article. | |
| Recommendation — Automate offboarding so account removal and entitlement revocation happen through a governed workflow. Review role assignments regularly and remove permissions that no longer match business need. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about managing who should retain access and under what conditions. |
| Recommendation — Use entitlement governance to keep access changes aligned with role changes and offboarding. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article centers on account creation, removal, and licence hygiene across the user lifecycle. |
| Recommendation — Centralise account management so provisioning, deprovisioning, and account review follow one process. | ||
Key terms
- User Life Cycle Management: User life cycle management is the end-to-end process of creating, updating, reviewing, and removing user identities and access across enterprise systems. It links identity governance to employee onboarding, role changes, and offboarding so access stays aligned with job responsibilities and business need.
- Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.
- Provisioning Workflow: A provisioning workflow is a structured process that turns an access request into an approved entitlement across one or more systems. It reduces manual handling by applying rules, approvals, and execution steps consistently so access is granted in a predictable, auditable way.
- Deprovisioning: Deprovisioning is the removal of access when a user changes roles or leaves an organisation. For security teams, it is the point where stale accounts, tokens, and permissions should disappear. Weak deprovisioning leaves residual access that can outlive the business need that created it.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org