A ghost license is an active software entitlement assigned to someone who no longer needs it, often because they changed roles or left the organisation. These stale licences waste budget and can also preserve access longer than intended, which creates avoidable exposure in identity and offboarding workflows.
Expanded Definition
A ghost license is not just unused software; it is an entitlement that remains assigned after a role change, transfer, leave event, or separation, so the organisation still pays for it and may still permit access. In NHI and IAM operations, the term is most useful when entitlement review is tied to joiner-mover-leaver controls rather than occasional budget cleanup.
Definitions vary across vendors on whether a ghost license includes only paid seats or also dormant trial, admin, and bundled entitlements, but the operational risk is the same: access persists after business need has ended. This is closely related to offboarding hygiene, license reclamation, and privilege reduction, yet it is narrower than general identity sprawl because it centers on a specific entitlement that should have been removed or reallocated.
For governance, the right question is not only whether the licence is unused, but whether its continued assignment creates a false sense of compliance in systems that assume license state reflects current authorisation. NIST frames identity and access management as a core control family in the NIST Cybersecurity Framework 2.0, which makes stale entitlement removal part of routine access assurance. The most common misapplication is treating ghost licenses as a procurement issue alone, which occurs when finance tracks spend but identity teams do not validate entitlement-to-role alignment.
Examples and Use Cases
Implementing ghost-license cleanup rigorously often introduces coordination overhead, requiring organisations to weigh reclaimed spend against the operational cost of entitlement reconciliation across HR, IAM, and application owners.
- A sales platform seat remains assigned to a former account executive after offboarding, and the user is still listed as an active paid licence holder until the quarterly review.
- A contractor’s design-tool entitlement is left in place after the contract ends, so the organisation pays for a dormant account that still has portal access.
- An engineer moves from production support to architecture, but the old admin licence is not removed, creating a stale access path that no longer matches the role.
- A collaboration suite retains a premium add-on after a team downsizes, and the licence pool is never reclaimed because no deprovisioning event triggers review.
- In a service-account environment, an automation licence is left attached to an identity that no longer runs workloads, which can obscure whether the account should be retired or rotated.
These patterns are visible in NHIMG research on Ultimate Guide to NHIs, which shows that only 20% of organisations have formal processes for offboarding and revoking API keys, a reminder that entitlement cleanup often fails when lifecycle controls are weak. In access management terms, the same discipline is consistent with the intent of the NIST Cybersecurity Framework 2.0: verify that assigned access still matches current need before the licence is treated as valid.
Why It Matters in NHI Security
Ghost licenses matter because stale entitlements are an indicator that the organisation has lost precision in identity governance. In NHI security, that often means service accounts, API-enabled workflows, or human-adjacent access paths remain active longer than intended, which increases the chance that a forgotten entitlement becomes an unexpected control failure. NHIMG research shows that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, and 91.6% of secrets remain valid five days after notification, illustrating how slowly remediation can move when lifecycle ownership is unclear.
The risk is not only financial waste. A ghost license can preserve access to data, collaboration spaces, or administrative consoles after a mover or leaver event, undermining least privilege and delaying detection of authorization drift. The same pattern often appears where offboarding is fragmented, because no team owns the final entitlement check. NHIMG’s Ultimate Guide to NHIs is explicit that formal offboarding and revocation processes remain rare, which is why a ghost licence should be treated as a lifecycle control signal, not a finance-only anomaly.
Organisations typically encounter the security impact only after a role change, departure, or audit uncovers an entitlement that should have been removed, at which point ghost license review becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Ghost licenses reflect stale entitlement lifecycle failures in NHI governance. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access review applies to stale license assignments. |
| NIST SP 800-63 | IAL2 | Identity proofing and lifecycle assurance support valid assignment decisions. |
| NIST Zero Trust (SP 800-207) | PL-10 | Zero trust assumes access is continuously validated, not left hanging. |
| NIST AI RMF | AI systems can inherit stale entitlements through agent and tool access paths. |
Audit AI and agent access for unused entitlements and revoke when no longer needed.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org