Join our Newsletter — 33% off our NHI Course

SaaS onboarding and offboarding: where access handoffs still break

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Modern SaaS environments fragment onboarding and offboarding across managed apps, unmanaged apps, licenses, and manual handoffs, so access clean-up often fails even when SSO is in place, according to 1Password. The practical issue is lifecycle control, not workflow speed, because incomplete deprovisioning leaves orphaned access, wasted spend, and audit gaps.

Editorial analysis by NHI Mgmt Group, based on content published by 1Password: “Streamlining SaaS onboarding and offboarding”.

Key questions

Q: What breaks when SaaS offboarding only removes SSO access?

A: Partial offboarding leaves residual risk because application-level permissions, active sessions, and data custody may still persist.

Q: Why do unmanaged SaaS apps create access risk even when SSO is in place?

A: Because SSO only governs the apps it covers.

Q: How do organisations know if SaaS lifecycle automation is actually working?

A: Look for evidence that provisioning, approval, and revocation happen in the same workflow and that stale licenses disappear after role changes or departures.

Practitioner guidance

  • Build a complete SaaS app inventory Continuously discover managed apps, unmanaged apps, and shadow IT so onboarding and offboarding workflows are based on the full estate, not only SSO-connected services.
  • Automate deprovisioning across every app path Remove access, reclaim licenses, and transfer files or folders in one governed workflow so manual checklists do not leave orphaned access behind.
  • Require an audit trail for lifecycle actions Record what was discovered, what was changed, and who approved it so offboarding can be proven after the fact.

Bottom line: SaaS onboarding and offboarding fail most often at the boundaries that SSO does not cover, not at the point where identity is first created.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 23 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Full SaaS visibility is the control boundary that onboarding and offboarding actually need: lifecycle governance fails when teams can only manage the apps behind SSO. SaaS adoption now happens across managed, unmanaged, and shadow tools, so the identity programme must start from discovery rather than federation alone. The practitioner conclusion is simple: if an app is not visible, it is not governable.

A few things that frame the scale:

  • Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What is the difference between provisioning access and governing the SaaS lifecycle?

A: Provisioning grants access at the start of employment or engagement. Lifecycle governance also covers revocation, ownership transfer, entitlement recovery, and evidence capture when that access ends or changes, across both managed and unmanaged apps.

👉 Read our full editorial: SaaS onboarding and offboarding still fail without full visibility


This post was modified 23 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.