By NHI Mgmt Group Editorial TeamBased on 1Password: “Streamlining SaaS onboarding and offboarding” (February 10, 2026)

TL;DR: Modern SaaS environments fragment onboarding and offboarding across managed apps, unmanaged apps, licenses, and manual handoffs, so access clean-up often fails even when SSO is in place, according to 1Password. The practical issue is lifecycle control, not workflow speed, because incomplete deprovisioning leaves orphaned access, wasted spend, and audit gaps.


At a glance

What this is: This is an analysis of why SaaS onboarding and offboarding still fail when access is fragmented across managed and unmanaged applications.

Why it matters: It matters because IAM and IGA teams cannot reliably provision or revoke access, reclaim licenses, or produce clean audit evidence if they cannot see the full SaaS estate.


Context

SaaS onboarding and offboarding are lifecycle controls, not just IT chores. In modern environments, the access problem is not only whether SSO exists, but whether every application, license, and manual handoff is visible enough to govern end to end.

When teams cannot see unmanaged apps or shadow IT, deprovisioning becomes partial by default. That leaves orphaned accounts, unreclaimed licenses, and incomplete audit trails, which turns offboarding into a governance gap rather than a workflow problem.

For IAM and IGA programmes, this is a familiar failure mode: lifecycle intent is clear, but the control boundary is too narrow. The article’s starting point is typical of SaaS-heavy organisations that rely on SSO as a proxy for full access governance.


Key questions

Q: What breaks when SaaS offboarding only removes SSO access?

A: Partial offboarding leaves residual risk because application-level permissions, active sessions, and data custody may still persist. A user can appear removed from the identity provider while remaining reachable in the application or through transferred data paths. Effective offboarding must verify that access is removed everywhere it exists.

Q: Why do unmanaged SaaS apps create access risk even when SSO is in place?

A: Because SSO only governs the apps it covers. Employees can still use browser tools, local accounts, and OAuth-linked services outside federation, which leaves access invisible to standard identity reporting. The risk is not the absence of authentication, but the absence of complete lifecycle control over what users can actually reach.

Q: How do organisations know if SaaS lifecycle automation is actually working?

A: Look for evidence that provisioning, approval, and revocation happen in the same workflow and that stale licenses disappear after role changes or departures. If users keep access after they no longer need it, automation is only partially implemented. Effective lifecycle automation shows up as faster offboarding, fewer abandoned licenses, and cleaner audit trails.

Q: What is the difference between provisioning access and governing the SaaS lifecycle?

A: Provisioning grants access at the start of employment or engagement. Lifecycle governance also covers revocation, ownership transfer, entitlement recovery, and evidence capture when that access ends or changes, across both managed and unmanaged apps.


Technical breakdown

Why SSO does not complete SaaS offboarding

Single sign-on centralises authentication, but it does not automatically discover or disable every SaaS account that exists outside the SSO boundary. Many applications are adopted directly by teams, provisioned through local admin consoles, or connected through informal workflows. That means the identity plane and the application plane diverge. If the offboarding process only touches the federated path, access can survive in standalone app accounts, local licenses, shared workspaces, and delegated admin roles. The technical failure is not authentication itself, but incomplete lifecycle coverage across the full application estate.

Practical implication: model offboarding around app inventory and account discovery, not just federation coverage.

How orphaned access and wasted licenses persist

Offboarding needs to revoke access, transfer ownership, and reclaim entitlements in the same lifecycle sequence. When those steps are split across tickets and spreadsheets, each manual handoff becomes a failure point. An orphaned account is an identity that still authenticates or retains data access after its owner departs, while an unreclaimed license keeps consuming budget even when the user is gone. The technical issue is lifecycle fragmentation: permissions, data ownership, and commercial entitlements are managed in separate systems with no single enforcement path.

Practical implication: tie deprovisioning, license recovery, and ownership transfer to one governed workflow.

Why audit evidence depends on continuous visibility

Auditability in SaaS lifecycle management depends on being able to show what was discovered, what was changed, and when it happened. If unmanaged apps are invisible, the audit trail becomes incomplete even when the ticket was closed. This is especially important when contractors, temporary workers, and shadow IT tools are involved, because their access patterns change faster than periodic reviews can catch. The control problem is not absence of intent, but absence of verified completeness. Without that verification, you cannot prove that onboarding and offboarding reached the full SaaS estate.

Practical implication: require discovery logs and action trails as evidence of complete lifecycle execution.


  • Ledger Connect Kit npm compromise 2023: Attackers phished a former Ledger employee with unrevoked npm access and published a wallet-draining Connect Kit, stealing about $600k on 14 Dec 2023.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Full SaaS visibility is the control boundary that onboarding and offboarding actually need: lifecycle governance fails when teams can only manage the apps behind SSO. SaaS adoption now happens across managed, unmanaged, and shadow tools, so the identity programme must start from discovery rather than federation alone. The practitioner conclusion is simple: if an app is not visible, it is not governable.

Offboarding is not complete until entitlements, accounts, and ownership have all been handled: removing sign-in access is only one step in a broader lifecycle chain. Licenses, files, folders, and delegated admin rights can outlive the employee unless the workflow closes every path at once. The implication for IAM and IGA teams is that deprovisioning should be treated as a multi-object control, not a single account event.

Managed SaaS and unmanaged SaaS now require the same lifecycle discipline: the distinction between official and unofficial tools no longer changes the governance expectation. If contractors and employees can create productive work outside central control, lifecycle processes must be designed for the full application estate. Practitioners should evaluate whether their programme governs where work happens, not just where IT prefers it to happen.

Visibility debt is the right name for this control gap: teams accumulate governance risk whenever they cannot reliably enumerate the applications, licenses, and access paths they are expected to revoke. That debt shows up later as orphaned accounts, wasted spend, and weak audit evidence. The practitioner takeaway is to treat discovery coverage as a lifecycle prerequisite, not a reporting feature.

Lifecycle automation is now an IAM and IGA design requirement, not an efficiency tweak: the article shows that manual cleanup cannot scale with modern SaaS sprawl. The operational conclusion is that provisioning and deprovisioning need to be consistent across managed and unmanaged apps, or the programme will continue to rely on exception handling as a business process.

From our research library:

What this signals

Visibility debt: when unmanaged apps sit outside the identity programme, offboarding stops being a single control and becomes a scavenger hunt across tickets, admin consoles, and forgotten licenses. The programme signal to watch is whether discovery now covers the full SaaS estate, not just the apps behind federation.

Lifecycle controls should be evaluated on completeness, not speed alone. If accounts are removed but files, folders, licenses, or delegated ownership remain, the organisation has only reduced one part of the risk while leaving the rest to manual cleanup.

Full SaaS discovery is increasingly a prerequisite for audit-ready lifecycle governance. Without it, teams cannot prove that joiner and leaver actions reached the real application landscape rather than the subset already managed by IT.


For practitioners

  • Build a complete SaaS app inventory Continuously discover managed apps, unmanaged apps, and shadow IT so onboarding and offboarding workflows are based on the full estate, not only SSO-connected services.
  • Automate deprovisioning across every app path Remove access, reclaim licenses, and transfer files or folders in one governed workflow so manual checklists do not leave orphaned access behind.
  • Require an audit trail for lifecycle actions Record what was discovered, what was changed, and who approved it so offboarding can be proven after the fact.
  • Map contractor and shadow IT offboarding separately Treat short-term workers and unsanctioned tools as higher-risk lifecycle cases because they are more likely to bypass standard provisioning and revocation paths.

Key takeaways

  • SaaS onboarding and offboarding fail most often at the boundaries that SSO does not cover, not at the point where identity is first created.
  • Incomplete discovery produces orphaned access, unreclaimed licenses, and weak audit evidence because the workflow never reaches every app and entitlement.
  • The control answer is end-to-end lifecycle governance across discovery, deprovisioning, entitlement recovery, and evidence capture.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article centers on incomplete SaaS offboarding and lingering access after departure.
NHI-05 — Overprivileged NHIPartial revocation leaves residual access and licenses beyond the minimum needed.
NHI-10 — Human Use of NHIHuman onboarding and offboarding still depend on non-human app accounts, licenses, and delegated access.
Recommendation — Map every leaver workflow to NHI-01 and verify revocation across managed and unmanaged apps. Review residual SaaS entitlements against NHI-05 and remove unused access paths during offboarding. Govern human-driven SaaS access changes as NHI lifecycle events when apps fall outside SSO.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe issue is incomplete authorization management across the SaaS estate.
Recommendation — Apply PR.AA-05 to ensure access changes are complete across all SaaS entitlements.
CIS Controls v8CIS-5 — Account ManagementThe article is about provisioning and revocation discipline for user and app accounts.
Recommendation — Use CIS-5 to govern account lifecycle actions and eliminate orphaned access.

Key terms

  • SaaS Lifecycle Governance: SaaS lifecycle governance is the set of controls that manage applications from onboarding through access assignment, renewal, and decommissioning. It matters because the security value of SaaS management depends on whether the organisation can prove ownership, revoke access, and retire unused tools on demand.
  • Orphaned Account: An orphaned account is an identity that remains active without a clear owner or business purpose. These accounts are dangerous because they often escape review, retain unnecessary access, and provide attackers with low-friction entry points into otherwise governed environments.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.
  • Entitlement Reclamation: Entitlement reclamation is the process of taking back access that is no longer needed. It usually follows usage review, role change, or offboarding, and it is one of the clearest ways to reduce excess access in SaaS environments without harming productivity.

Deepen your knowledge

NHI governance, identity lifecycle management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org