Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
Use Case

Offboarding Residual Access

Detect and remove access that remains after employees, contractors, or vendors leave, across identity, SaaS, cloud, and on-premises systems, with a full evidence trail.

Why it matters

When someone leaves, access revocation is rarely complete the first time.

Identity accounts may be disabled but not deleted. SaaS seats stay assigned. Cloud roles persist under service accounts tied to the departed user. Group memberships survive org restructuring. Licenses remain allocated. Each of these is an open access point with no authorized user behind it, and each one is a potential audit finding or a vector for unauthorized reuse.

  • Disabled accounts are not deleted accounts, and disabled accounts can be re-enabled
  • SaaS platforms are not automatically notified when an employee leaves
  • Cloud service accounts linked to departed users are often forgotten entirely
  • Residual group memberships extend access to shared resources beyond the intended scope
How Nuxari helps

The governed approach

Residual Account Detection

Nuxari cross-references observed identity accounts against HR departure records or manually flagged users to identify accounts that should have been revoked.

SaaS Seat Identification

Connected SaaS connectors identify seats assigned to departed users, where the license is still active but the user is no longer with the organization.

Cloud Role Scanning

Cloud IAM connectors scan for roles, policies, and service accounts tied to departed user identities across AWS, Azure, and GCP.

Group Membership Review

Group memberships that survived departure are surfaced as findings, particularly security groups that extend access to shared resources or privileged systems.

License Reclamation

Licenses assigned to departed users are flagged for reclamation. Removal workflows route through approval to ensure license recovery is documented.

Evidence of Removal

For each revocation or removal action, Nuxari captures a signed, timestamped evidence record confirming what was removed, by whom, with what authorization.

Identity Lifecycle

Access removed. Evidence captured. Every departure leaves a complete record of what was revoked, when, and by whom.

Offboarding Residual Access
IT professional completing a structured offboarding workflow with organized documentation
Workflow

How the lifecycle runs

  1. 01
    Departure event is received or detected
    An offboarding workflow is triggered, either from an HR system event, a manager request, or detection of a disabled account with remaining access.
  2. 02
    Cross-system residual access scan runs
    Nuxari queries all connected systems, identity providers, SaaS platforms, cloud IAM, group directories, to identify all access tied to the departing user.
  3. 03
    Residual access is surfaced as findings
    Each remaining access point becomes a finding: system, access type, severity, and the reason it is flagged as residual.
  4. 04
    Removal workflows are drafted and approved
    Removal actions are grouped into an offboarding workflow and submitted for approval. Each system's removal action requires its own authorization step.
  5. 05
    Removal executes across all systems
    Approved removal actions execute in sequence. Each action is logged with execution status and system confirmation.
  6. 06
    Validation confirms access is removed
    Nuxari re-queries each system after removal to confirm the access no longer appears in observed state.
  7. 07
    Evidence package is assembled
    A complete offboarding evidence bundle is created, finding per system, approval, execution, validation, and control mapping.
Example scenario

Contractor departure with residual access across four systems

A contractor's engagement ended. A routine observation cycle detected that the contractor's access remained active across several systems three weeks after the expected departure date.

Illustrative example. Not real customer data.

Demo · Illustrative only
  1. 01Entra ID: account disabled but not deleted, detected as residual
  2. 02M365: license still assigned, $22/mo idle since departure
  3. 03GitHub: organization member with repository access, detected
  4. 04AWS: service account with EC2 read policy, detected
  5. 05Offboarding workflow drafted covering all four systems
  6. 06IT Manager approves all four removal actions
  7. 07Entra ID account deleted; M365 license reclaimed; GitHub access revoked; AWS policy removed
  8. 08Validation: all four systems re-observed, access confirmed removed
  9. 09Evidence bundle assembled with per-system records
Audit trail

Evidence produced

  • Residual access finding per system with detection timestamp
  • Departure event record and trigger source
  • Offboarding workflow document with scope and approval
  • Per-system approval record with authorizer identity
  • Per-system execution log with confirmation
  • Per-system validation result confirming removal
  • License reclamation record with estimated cost recovery
  • Control-mapped evidence bundle exportable as PDF or JSON
Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.