Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What breaks when software licences are not tied…
NHI Lifecycle Management

What breaks when software licences are not tied to identity lifecycle processes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: NHI Lifecycle Management

Licences drift from the people actually using them, which creates orphaned entitlements, wasted spend, and offboarding gaps. In SaaS estates, that also makes it harder to prove that access was revoked when a user left or changed roles, so procurement and IAM must share the same record of entitlement state.

How licence state drifts when it is disconnected from joiner-mover-leaver controls

Once software licences are managed as a procurement record instead of an identity record, entitlement state stops tracking actual user state. The result is not just overspend, but a control gap: licences remain assigned after role changes, account closure, or contractor exit, so the estate starts to contain permissions that no longer have a valid owner.

That drift matters because licence assignment is often the visible proof that access was approved, but it is only trustworthy when it follows the same lifecycle as the user or role that justified it. Joiner-Mover-Leaver (JML) Guide and IAM and IGA Basics both reinforce that entitlement state should be created, changed, and removed in step with identity events, not left to separate admin queues.

In SaaS estates, the operational failure usually shows up as orphaned entitlements, stale access, and inconsistent records between HR, procurement, and IAM. A licence can continue to exist even after the user who justified it has left, or a mover event can leave the person with a more expensive or more privileged package than their current job requires.

That same mismatch also weakens auditability. If a team cannot tie licence revocation to a leaver event or role change, it becomes difficult to show that access was actually removed on time, especially when the entitlement is the control point that grants access to the application. The lifecycle view matters as much for ownership as for security evidence, which is why NHI Ownership and Accountability Guide and Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs are useful parallels for understanding why every entitlement needs a named owner and a removal path.

What breaks in procurement, audit, and access revocation

The first break is reconciliation. Procurement may know what was bought, while IAM knows who should still have access, and neither system can be trusted on its own if they are not reconciled against the same source of truth. That is how unused seats persist, freed licences are not reclaimed, and spend leaks across business units without a clear owner.

The second break is revocation. If offboarding only removes directory access but does not also remove the application licence, the entitlement may remain available for reactivation, reassignment, or delayed cleanup. In practice, the difference between “removed” and “still assigned” can be the difference between a clean offboarding trail and a control that only looks complete on paper.

The third break is evidence. The organisation needs to be able to show that a user change triggered both access review and entitlement change, with timestamps that line up. A licence record that is not lifecycle-aware cannot support that evidence chain, even if the application itself eventually blocks login.

Why this turns into security exposure rather than only cost waste

Licence drift is usually introduced as a cost problem, but it becomes a security problem when stale entitlements preserve access after the business believes it has been removed. That can leave ex-employees, contractors, or moved staff with residual application access, and in some environments the licence is itself the control that unlocks sensitive data, admin features, or integration scope.

The security issue is amplified when licences are shared, over-assigned, or tied to accounts that are not routinely reviewed. Ultimate Guide to NHIs, Key Challenges and Risks and Top 10 NHI Issues both show the broader pattern: when ownership, rotation, and offboarding are weak, access persists longer than intended and the organisation loses visibility into who can still act.

For SaaS, the practical threat is that an old licence can become the easiest re-entry path after a move or departure, especially if access is restored faster than records are corrected. That is why licence state should be treated as a live entitlement control, not a billing artefact.

Risk and Threat Considerations

When licence records and identity lifecycle processes diverge, organisations can lose both control and proof. The main risk is residual access: a person who has left, changed roles, or lost sponsorship may still retain an active entitlement long enough to create unnecessary exposure, audit findings, or delayed detection of misuse.

Failure mechanism: The licence remains assigned because the revocation workflow is split across procurement, IAM, and the application owner, so the offboarding or mover event removes one record but not the entitlement state that actually governs access.

Impact: Orphaned entitlements, wasted spend, and weak evidence of timely revocation follow, and in the worst case the stale licence preserves a usable access path after the organisation believes access has been removed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementLicence drift often leaves stale access material and weak revocation tracking.
AC-2 — Account ManagementUser moves and departures should drive entitlement changes and account cleanup.
AU-6 — Audit Record Review, Analysis, and ReportingYou need evidence that licence revocation happened when the user changed or left.
Recommendation — Tie entitlement removal to credential and authenticator lifecycle events. Synchronise licence assignment and removal with account lifecycle changes. Correlate identity changes with entitlement updates in audit review.
ISO/IEC 27001:2022A.5.16 — Identity managementLicence state must follow identity lifecycle and ownership changes.
A.5.18 — Access rightsSoftware licences function as access-enabling entitlements that require review and removal.
Recommendation — Maintain identity-linked ownership and lifecycle records for software entitlements. Review and revoke application entitlements when access is no longer justified.

Practitioner Guidance

What to prioritise: Put licence state into the same lifecycle control as joiner, mover, and leaver processing. If procurement cannot show the current owner, last change date, and revocation path for each entitlement, treat the record as operationally incomplete.

What to verify: Check that every licence can be traced to a current identity, role, or approved exception, and that offboarding produces both access removal and entitlement removal. The key test is whether you can prove, for a departed user, when the licence was removed and who approved it.

Practitioner takeaway: The control objective is not simply to reclaim unused licences, it is to ensure that every paid entitlement has a live identity justification and a reliable revocation trail.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org