TL;DR: A trigger-condition-action workflow model for onboarding, offboarding, access reviews, and license management across SaaS apps is described by Josys, and a study found that 89% of former employees still retained access to at least one application from a previous employer. The governance gap is not the lack of automation, but the lack of reliable lifecycle closure across dozens of disconnected systems.
Editorial analysis by NHI Mgmt Group, based on content published by Josys: “End-to-End Access Management Using Josys Workflows”.
By the numbers:
- 89% of former employees still retain access to at least one application from a previous employer.
Key questions
Q: What breaks when employee offboarding depends on disconnected SaaS apps?
A: The first failure is that deprovisioning stops being automatic.
Q: Why does incomplete SaaS lifecycle closure increase identity risk?
A: Incomplete closure increases risk because access state becomes inconsistent across apps, licenses, and review records.
Q: What are the signs that SaaS access review processes are not working?
A: A weak process usually shows up as poor visibility into which SaaS apps are used, unclear ownership for accounts, duplicated app functions, and inconsistent evidence for auditors.
Practitioner guidance
- Map lifecycle closure across every SaaS app Identify where onboarding, offboarding, review, and license changes are executed manually, and mark every app that can still retain access after the source record changes.
- Link offboarding to verified revocation Require each leaver workflow to confirm that access was removed in every connected system, not just that a ticket was opened or a request was issued.
- Connect access review outcomes to execution Route reviewer decisions into automated revocation and license recovery actions so certification ends with a state change, not a report entry.
Bottom line: The core issue is not whether SaaS access can be automated, but whether lifecycle decisions are fully enforced across every app that matters.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Lifecycle closure is the real control boundary in SaaS identity governance. The article shows that automation only helps when every downstream app receives the same joiner, mover, or leaver decision. In practice, the governance problem is not triggering an action, but proving that the action reached every system that still matters. Practitioners should treat incomplete closure as a control failure, not an administrative inconvenience.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should IAM teams combine access reviews with license reclamation?
A: They should treat them as one closure process. If a reviewer says access is no longer needed, the workflow should revoke the entitlement, recover the seat, and record the result in a way that can be audited later. Otherwise governance stays descriptive instead of operational.
👉 Read our full editorial: End-to-end access management workflows expose SaaS lifecycle gaps