Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What breaks when SaaS licenses are not revoked…
NHI Lifecycle Management

What breaks when SaaS licenses are not revoked after employees leave?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: NHI Lifecycle Management

Unrevoked licenses keep billing active and preserve access longer than business need requires. The failure is lifecycle control, because the organisation continues paying for subscriptions that no longer map to a current user or a current purpose. That is why offboarding and SaaS entitlement review need to be linked.

Why unreclaimed SaaS licenses keep costing and exposing the business

When a departing employee’s subscription is not revoked, the first break is lifecycle control: the licence remains tied to a person who no longer needs it, so spend keeps running and access can outlive business need. That creates avoidable waste, but it also leaves a valid entitlement sitting on an account that is no longer under normal supervision.

In practice, the problem is not limited to the seat itself. Many SaaS products bundle data access, sharing, integrations, and delegated permissions into the same account. If offboarding only removes the person from HR records, the organisation may still have an active subscription, active sessions, connected apps, or stored tokens that continue to work until someone explicitly closes the loop.

For that reason, license revocation should be treated as part of entitlement removal, not as a separate finance task. The business outcome to check is whether the account, licence, and any linked access paths are actually severed together, because each leftover component can preserve some level of reach into the service.

Where offboarding breaks down in SaaS

The common failure is a split between people workflow and application workflow. HR may signal that employment ended, IT may disable a directory account, and procurement may keep renewing the subscription, yet no single owner confirms that the SaaS entitlement was reclaimed and reassigned. That gap is what turns a routine departure into an orphaned subscription and an unnecessary access path.

One useful way to think about it is that SaaS offboarding has three independent checks: remove the user’s ability to sign in, remove the paid entitlement, and review what the account touched before departure. If any of those checks is missing, the control is incomplete. A licence that is merely inactive from the user’s perspective can still represent spend; a licence that is still active can still represent exposure.

This is why licence cleanup is usually strongest when it is tied to joiner-mover-leaver process design and routine entitlement review. NHI lifecycle management and lifecycle processes for managing identities both illustrate the same operational pattern: lifecycle controls only work when provisioning, review, and offboarding are treated as one connected process.

What teams should verify before calling offboarding complete

Practitioners should verify that licence removal is happening at the system of record, not just in a spreadsheet or ticket. The person should be removed from the SaaS tenant or deprovisioned through the identity flow, any delegated roles should be checked, and the subscription record should reflect that the seat is free for reassignment or cancellation. If the organisation cannot prove those steps, it does not really know whether the licence is gone.

It also helps to verify what the account was used for before it was closed. A departing employee may have been the only owner of a workspace, integration, or shared content library, so reclaiming the licence without reviewing ownership can create a different problem: lost administrative continuity. Good offboarding therefore checks both access removal and asset handover.

For readers who manage many subscriptions, the useful signal is stale entitlement age. If a licence remains assigned long after departure, or if the account is still able to authenticate after the offboarding date, the process has failed. Top 10 NHI Issues and the guide to the secret sprawl challenge both reinforce the broader control lesson that stale access and stale secrets are usually lifecycle problems before they become incident problems.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementUnrevoked SaaS licences are an account lifecycle failure that CIS account management addresses.
Recommendation — Revoke and reassign stale SaaS accounts and licences during offboarding.
NIST CSF 2.0ID.AM-01 — Physical devices and systems within the organization are inventoriedSaaS licences need accurate asset and entitlement inventory to prevent orphaned subscriptions.
Recommendation — Maintain an accurate inventory of SaaS entitlements and owners.
NIST SP 800-53 Rev 5AC-2 — Account ManagementOffboarding must disable and remove accounts and associated access promptly after departure.
Recommendation — Automate account disablement and entitlement revocation at separation.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess rights must be removed when personnel leave or no longer need access.
Recommendation — Remove SaaS access rights and review lingering subscriptions at offboarding.
SOC 2 (AICPA)CC6.2 — Logical and Physical Access ControlsSOC 2 access controls require timely removal of access for departed users.
Recommendation — Evidence timely removal of SaaS access and licence ownership at offboarding.

Practitioner Guidance

What to prioritise: Reclaim the licence at the same time you revoke sign-in access, because billing drift and access drift often happen together. If the offboarding workflow only closes one of those paths, the control is incomplete.

What to verify: Confirm that the SaaS account, paid seat, delegated roles, and any connected integrations are all cleared or reassigned. The best evidence is an auditable record that shows the entitlement was removed and the asset owner was updated.

Common mistake: Treating licence removal as procurement cleanup after the employee is gone. In reality, delayed removal leaves both unnecessary spend and a wider window for residual access to persist unnoticed.

Practitioner takeaway: A safe SaaS offboarding process does not just disable users, it closes the entitlement lifecycle end to end, so the business stops paying for access that no longer has a legitimate owner.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org