Stale SaaS Account Review
Detect user accounts in connected SaaS applications that have had no activity above a configurable threshold and route deactivation or removal through an approval-gated workflow.
Requires a Nuxari account. Installs as Draft — no changes until you enable it.
Back to templatesWhat this template does
This automation job queries activity data from connected SaaS applications and identifies user accounts that have not had any qualifying activity — sign-in, file access, API call — within a configurable inactivity window. Identified accounts are grouped by application and presented to the configured reviewer. The reviewer can approve deactivation, exclude an account, or request a user attestation before deciding. All deactivations are approval-gated and logged with evidence.
When to use it
Use this template when you want to systematically reduce the attack surface from accounts that are no longer actively used, without relying on manual tracking. It is especially useful after organizational changes, project completions, or when you lack a formal offboarding process that consistently removes SaaS access.
How it works
Activity collection
Nuxari collects sign-in and usage activity data from connected SaaS applications for the configured review period.
Inactivity identification
Accounts with no activity in the configured window are identified and grouped by application.
Review routing
The stale account list is presented to the configured reviewer with last activity timestamps, account owner details, and recommended actions.
Decision collection
The reviewer approves deactivation, excludes the account from the current review, or requests a user attestation. Each decision is logged.
Deactivation and evidence
Approved deactivations are executed in the target application. A closing evidence record is generated for each deactivated account.
What gets created in your tenant
SaaS Activity Scanner
A recurring job that queries activity data from connected SaaS applications and identifies stale accounts.
Stale Account Deactivation Approval
A review and approval workflow for each batch of identified stale accounts.
Stale Account Review Evidence
Structured evidence records for each activity scan, account identification, review decision, and deactivation action.
What evidence it produces
- Stale account inventory per application
- Last activity timestamp per account
- Review decision log with approver identity
- Deactivation confirmation per account
- Post-review access state snapshot
Safety and approval model
Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.
This template requires an approval decision before enabling. No execution occurs without a recorded approver sign-off.
This template installs in Draft state. No activity scans run and no accounts are reviewed until you configure the connector scope and explicitly enable the job. Deactivation requires approval and cannot be executed automatically. The job collects activity metadata only — it does not read account content, emails, or documents. All review decisions and deactivation actions are logged with full audit records.
Customization options
- Inactivity threshold (14, 30, 60, or 90 days)
- Application scope (select which connected SaaS apps are included)
- Account types to include (regular users, service accounts, shared accounts)
- Review routing and approval chain
- Attestation option (prompt user before deactivating)
- Review frequency (monthly, quarterly, or on-demand)
Related templates
M365 License Reclaim Campaign
Identify Microsoft 365 licenses with no recent sign-in or activity, send user attestation requests, and route confirmed reclamations through approval before removing assignments.
View templateScheduled Employee Offboarding
Plan, approve, and execute complete employee offboarding in advance. Revokes access across identity, SaaS, and cloud at the scheduled time and generates a full evidence package.
View templateGitHub Access Drift Review
Compare approved GitHub organization membership and repository access against observed state. Surface drift as findings and route removals through approval-gated workflows with evidence.
View templateUse this template
Install in your Nuxari tenant and run the full approval and evidence workflow from day one.
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.