Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Automation JobAccess Governancelow riskApproval required

Stale SaaS Account Review

Detect user accounts in connected SaaS applications that have had no activity above a configurable threshold and route deactivation or removal through an approval-gated workflow.

IT teams managing multiple SaaS applicationsSecurity teams reducing the attack surface from inactive accountsOrganizations with frequent employee churn or project-based accessMSPs performing SaaS hygiene for clients
Use template

Requires a Nuxari account. Installs as Draft — no changes until you enable it.

Back to templates
~20 min setup
Required
Entra ID

What this template does

This automation job queries activity data from connected SaaS applications and identifies user accounts that have not had any qualifying activity — sign-in, file access, API call — within a configurable inactivity window. Identified accounts are grouped by application and presented to the configured reviewer. The reviewer can approve deactivation, exclude an account, or request a user attestation before deciding. All deactivations are approval-gated and logged with evidence.

When to use it

Use this template when you want to systematically reduce the attack surface from accounts that are no longer actively used, without relying on manual tracking. It is especially useful after organizational changes, project completions, or when you lack a formal offboarding process that consistently removes SaaS access.

How it works

01

Activity collection

Nuxari collects sign-in and usage activity data from connected SaaS applications for the configured review period.

02

Inactivity identification

Accounts with no activity in the configured window are identified and grouped by application.

03

Review routing

The stale account list is presented to the configured reviewer with last activity timestamps, account owner details, and recommended actions.

04

Decision collection

The reviewer approves deactivation, excludes the account from the current review, or requests a user attestation. Each decision is logged.

05

Deactivation and evidence

Approved deactivations are executed in the target application. A closing evidence record is generated for each deactivated account.

What gets created in your tenant

Automation Job

SaaS Activity Scanner

A recurring job that queries activity data from connected SaaS applications and identifies stale accounts.

Approval Workflow

Stale Account Deactivation Approval

A review and approval workflow for each batch of identified stale accounts.

Evidence Package Template

Stale Account Review Evidence

Structured evidence records for each activity scan, account identification, review decision, and deactivation action.

What evidence it produces

  • Stale account inventory per application
  • Last activity timestamp per account
  • Review decision log with approver identity
  • Deactivation confirmation per account
  • Post-review access state snapshot

Safety and approval model

Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.

This template requires an approval decision before enabling. No execution occurs without a recorded approver sign-off.

This template installs in Draft state. No activity scans run and no accounts are reviewed until you configure the connector scope and explicitly enable the job. Deactivation requires approval and cannot be executed automatically. The job collects activity metadata only — it does not read account content, emails, or documents. All review decisions and deactivation actions are logged with full audit records.

Customization options

  • Inactivity threshold (14, 30, 60, or 90 days)
  • Application scope (select which connected SaaS apps are included)
  • Account types to include (regular users, service accounts, shared accounts)
  • Review routing and approval chain
  • Attestation option (prompt user before deactivating)
  • Review frequency (monthly, quarterly, or on-demand)

Use this template

Install in your Nuxari tenant and run the full approval and evidence workflow from day one.

Use template
Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.