Offboarding Residual Access
Detect and remove access that remains after employees, contractors, or vendors leave, across identity, SaaS, cloud, and on-premises systems, with a full evidence trail.
When someone leaves, access revocation is rarely complete the first time.
Identity accounts may be disabled but not deleted. SaaS seats stay assigned. Cloud roles persist under service accounts tied to the departed user. Group memberships survive org restructuring. Licenses remain allocated. Each of these is an open access point with no authorized user behind it, and each one is a potential audit finding or a vector for unauthorized reuse.
- ✓Disabled accounts are not deleted accounts, and disabled accounts can be re-enabled
- ✓SaaS platforms are not automatically notified when an employee leaves
- ✓Cloud service accounts linked to departed users are often forgotten entirely
- ✓Residual group memberships extend access to shared resources beyond the intended scope
The governed approach
Residual Account Detection
Nuxari cross-references observed identity accounts against HR departure records or manually flagged users to identify accounts that should have been revoked.
SaaS Seat Identification
Connected SaaS connectors identify seats assigned to departed users, where the license is still active but the user is no longer with the organization.
Cloud Role Scanning
Cloud IAM connectors scan for roles, policies, and service accounts tied to departed user identities across AWS, Azure, and GCP.
Group Membership Review
Group memberships that survived departure are surfaced as findings, particularly security groups that extend access to shared resources or privileged systems.
License Reclamation
Licenses assigned to departed users are flagged for reclamation. Removal workflows route through approval to ensure license recovery is documented.
Evidence of Removal
For each revocation or removal action, Nuxari captures a signed, timestamped evidence record confirming what was removed, by whom, with what authorization.
Access removed. Evidence captured. Every departure leaves a complete record of what was revoked, when, and by whom.

How the lifecycle runs
- 01Departure event is received or detectedAn offboarding workflow is triggered, either from an HR system event, a manager request, or detection of a disabled account with remaining access.
- 02Cross-system residual access scan runsNuxari queries all connected systems, identity providers, SaaS platforms, cloud IAM, group directories, to identify all access tied to the departing user.
- 03Residual access is surfaced as findingsEach remaining access point becomes a finding: system, access type, severity, and the reason it is flagged as residual.
- 04Removal workflows are drafted and approvedRemoval actions are grouped into an offboarding workflow and submitted for approval. Each system's removal action requires its own authorization step.
- 05Removal executes across all systemsApproved removal actions execute in sequence. Each action is logged with execution status and system confirmation.
- 06Validation confirms access is removedNuxari re-queries each system after removal to confirm the access no longer appears in observed state.
- 07Evidence package is assembledA complete offboarding evidence bundle is created, finding per system, approval, execution, validation, and control mapping.
Contractor departure with residual access across four systems
A contractor's engagement ended. A routine observation cycle detected that the contractor's access remained active across several systems three weeks after the expected departure date.
Illustrative example. Not real customer data.
- 01Entra ID: account disabled but not deleted, detected as residual
- 02M365: license still assigned, $22/mo idle since departure
- 03GitHub: organization member with repository access, detected
- 04AWS: service account with EC2 read policy, detected
- 05Offboarding workflow drafted covering all four systems
- 06IT Manager approves all four removal actions
- 07Entra ID account deleted; M365 license reclaimed; GitHub access revoked; AWS policy removed
- 08Validation: all four systems re-observed, access confirmed removed
- 09Evidence bundle assembled with per-system records
Evidence produced
- Residual access finding per system with detection timestamp
- Departure event record and trigger source
- Offboarding workflow document with scope and approval
- Per-system approval record with authorizer identity
- Per-system execution log with confirmation
- Per-system validation result confirming removal
- License reclamation record with estimated cost recovery
- Control-mapped evidence bundle exportable as PDF or JSON
What powers this use case
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.