Residual Access Sweep
Scan all connected systems for access belonging to offboarded users, generate findings for residual access, and create remediation tasks for each system with remaining access.
Requires a Nuxari account. Installs as Draft — no changes until you enable it.
Back to templatesWhat this template does
This automation job reads the list of users marked as offboarded in the identity system and scans every connected system for access those users still hold. Any residual access — group memberships, licenses, SaaS roles, cloud permissions — surfaces as a finding, and a remediation task is created for each system where access remains. This verifies that offboarding actually removed access everywhere.
When to use it
Use this template as a completeness check after offboarding to catch residual access that offboarding workflows may have missed. It is especially valuable in environments with many systems where a single offboarding run can leave behind access in less-integrated platforms.
How it works
Offboarded user collection
Nuxari reads the list of users marked as offboarded in the connected identity system.
Cross-system access scan
Each connected system is scanned for access still held by any offboarded user.
Residual finding generation
Residual access surfaces as findings, grouped by user and system, describing exactly what access remains.
Remediation task creation
A remediation task is created for each system with remaining access, ready to route into an approval-gated removal workflow.
What gets created in your tenant
Residual Access Scanner
A job that scans connected systems for access belonging to offboarded users.
Residual Access Findings
A findings queue populated by access still held by offboarded users.
Offboarding Completeness Evidence
Structured evidence records confirming offboarding completeness across systems.
What evidence it produces
- Offboarded user list from identity source
- Residual access findings per system
- Remediation tasks for each system with remaining access
- Offboarding completeness summary
Safety and approval model
Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.
This template installs in Draft state and is read-only — it detects residual access and creates tasks but never removes any access. No scans run until you connect the required connectors and explicitly enable the job. Removal of residual access is handled through separate approval-gated remediation workflows.
Customization options
- Offboarded user source (identity status, group, or marker)
- Connector scope (which systems are swept)
- Lookback window after offboarding date
- Severity thresholds for residual access types
- Scan frequency (daily, weekly)
- Notification routing for residual findings
Related templates
Scheduled Employee Offboarding
Plan, approve, and execute complete employee offboarding in advance. Revokes access across identity, SaaS, and cloud at the scheduled time and generates a full evidence package.
View templateDormant Account Review
Identify accounts with no sign-in or activity in a configurable window, generate a dormancy report, and route owner review tasks — without modifying any accounts automatically.
View templateDisable Inactive User
Route discovered inactive user accounts through an approval gate and disable them across connected identity systems, capturing full evidence for each account.
View templateUse this template
Install in your Nuxari tenant and run the full approval and evidence workflow from day one.
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.