# Orphaned Account Cleanup

*/Problems/Orphaned_Account_Cleanup*

## Problem Overview

Enterprise IT and security teams constantly battle unmanaged access left behind by former employees and contractors. When workers depart, centralized identity providers disable core credentials but routinely fail to catch localized accounts in decentralized SaaS apps or legacy databases. These orphaned accounts remain fully active, consuming expensive software licenses and creating severe backdoor access vulnerabilities.

This gap persists due to a fundamental disconnect between human resources directories and ground-level software purchasing. Department heads frequently buy specialized tools with corporate credit cards outside official procurement channels, bypassing Single Sign-On integration entirely. Even sanctioned applications regularly require manual de-provisioning because automated lifecycle protocols like SCIM are locked behind expensive enterprise vendor pricing tiers.

Traditional identity governance platforms fail to solve this because they rely strictly on structured API integrations. They cannot detect or suspend accounts in unmapped applications lacking native administrative hooks. Security analysts are left cross-referencing HR departure lists with raw network logs and expense reports, manually logging into obscure administrative portals to delete individual profiles.

## Problem Severity Frequency

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Severity**: 4
**Frequency**: event-driven
**Budget Reality**:
- **Price Ceiling**: ~$25k-60k/yr - priced as an IAM bolt-on, capped by the labor savings of 0.5-1 FTE and recovered shadow IT licenses
- **Who Controls Spend**: CISO or VP of IT approves, IT Operations Manager recommends
- **Existing Budget Line**: true
- **Switching Cost From Status Quo**: moderate: buyers will not replace their core IdP, so a new tool must bolt on via read-only integrations with HRIS, network logs, and expense systems
**Regulatory Risk**: high
**Time Cost Per Event**: ~1-3 hours per departing employee
**Money Cost Per Event**: ~$200-800 per departure in wasted SaaS licenses and security analyst labor
**Annual Cost Per Affected Entity**: ~$50k-150k all-in

## Problem Why Now

The explosion of decentralized software purchasing means department heads routinely bypass IT procurement using corporate credit cards. Simultaneously, SaaS vendors lock automated offboarding protocols like SCIM behind prohibitive enterprise pricing tiers, widely known as the SSO Tax. Companies cannot economically integrate their long-tail applications into centralized identity providers, leaving hundreds of localized accounts completely disconnected from human resources departure triggers.

This unmanaged account sprawl now collides directly with aggressive identity-based cyberattacks and stricter reporting mandates, such as the SEC cybersecurity disclosure rules effective late 2023. Threat actors explicitly target dormant accounts as frictionless entry vectors that bypass primary network defenses. Legacy identity governance tools remain blind to this threat because they fundamentally require structured, vendor-supported APIs to detect or suspend users.

The structural barrier to cleaning these orphaned accounts breaks today due to the maturation of vision-capable large language models and autonomous browser agents. Instead of relying on rigid APIs or paying enterprise tier premiums, automated systems now visually parse unstructured expense reports to discover shadow applications. These same browser agents autonomously navigate custom administrative web interfaces to click through and revoke access exactly as a human security analyst does, solving the long-tail offboarding problem at machine scale.

## Problem Current Solutions

**Status Quo**: IT and security analysts manually cross-reference HR termination lists with expense reports and network logs to hunt for unsanctioned SaaS accounts, then log into local administrative portals to delete former employee profiles.
**Workarounds**:
- export HR termination CSV
- audit expense reports for SaaS charges
- grep network logs for departed users
- manual login to localized admin consoles
**Named Tools In Use**:
- [Okta](/Products/Okta)
- [Microsoft Entra ID](/Products/Microsoft_Entra_ID)
- [SailPoint](/Products/SailPoint)
- [Workday](/Products/Workday)
- [Splunk](/Products/Splunk)
- [SAP Concur](/Products/SAP_Concur)
**Why Insufficient**: Traditional identity governance tools rely entirely on structured API integrations and fail completely when applications lack native administrative hooks. They require IT to already know an application exists, leaving decentralized shadow IT unmanaged and vulnerable.

## Problem Market Profile

**Incumbents**:
- [Okta](/Problems/Orphaned_Account_Cleanup/Competitors/Okta)
- [Microsoft Entra ID](/Problems/Orphaned_Account_Cleanup/Competitors/Microsoft_Entra_ID)
- [SailPoint](/Problems/Orphaned_Account_Cleanup/Competitors/SailPoint)
- [Nudge Security](/Problems/Orphaned_Account_Cleanup/Competitors/Nudge_Security)
- [Cerby](/Problems/Orphaned_Account_Cleanup/Competitors/Cerby)
**Substitutes**:
- Exporting HR termination CSVs
- Auditing expense reports for SaaS charges
- Grepping network logs for departed users
- Manually logging into localized admin consoles
**Position Axes**:
- Discovery Scope (Federated/APIs vs. Shadow IT/Heuristics)
- Remediation Execution (Manual/Alert-driven vs. Automated Takedown)
**Market Dynamics**: The market is fragmenting between rigid enterprise identity suites and standalone SaaS posture management tools, though emerging AI-driven web automation is beginning to connect discovery directly to headless remediation.
**Competition Concentration**: Incumbent identity governance platforms cluster heavily in the Federated and Automated Takedown quadrant, relying entirely on structured SCIM or API integrations to disable accounts. Substitutes and manual workarounds occupy the Shadow IT and Manual Execution quadrant, requiring human analysts to parse logs and manually execute takedowns in local portals. The Shadow IT and Automated Takedown quadrant remains sparse, as programmatically tearing down unfederated accounts without official administrative hooks introduces significant technical friction.

## Mint Vocabulary Bag

**Action Verbs**:
- deprovision
- prune
- reconcile
- revoke
- disable
- quarantine
**Gerund Stems**:
- reconcil
- deprovision
- prun
- quarantin
- revok
- audit
**Abstract Nouns**:
- dormancy
- exposure
- drift
- access
- lifecycle
- entropy
**Concrete Nouns**:
- account
- identity
- credential
- privilege
- mailbox
- license
**Metaphor Nouns**:
- sieve
- anchor
- driftwood
- filter
- husk
- cinder
**Structure Nouns**:
- directory
- registry
- tenant
- domain
- cluster
- vault

## Problem Candidate Solutions

- [Guest](/Problems/Orphaned_Account_Cleanup/Startups/Guest) — Agent
- [Millen](/Problems/Orphaned_Account_Cleanup/Startups/Millen) — Service-as-Software
- [Forgotten](/Problems/Orphaned_Account_Cleanup/Startups/Forgotten) — Software
- [Gladering](/Problems/Orphaned_Account_Cleanup/Startups/Gladering) — Software
- [Mailboxdomain](/Problems/Orphaned_Account_Cleanup/Startups/Mailboxdomain) — Service-as-Software

## Problem Solution Space2x2

```mermaid
quadrantChart;x-axis Discovery Focus --> Remediation Focus;y-axis Application Layer --> Identity Provider Layer;Guest: [0.3, 0.8];Millen: [0.7, 0.6];Forgotten: [0.2, 0.2];Gladering: [0.8, 0.3];Mailboxdomain: [0.5, 0.5];
```

## Problem Affected Roles

- IAM Administrator — Identity Governance
- Information Security Analyst — Vulnerability Management
- IT Operations Manager — System Administration
- SaaS Administrator — App Management
- IT Asset Manager — License Optimization
- HR Operations Specialist — Employee Offboarding
- Compliance Auditor — Access Controls

## Problem Affected Companies

- Multinational Enterprises — High SaaS Sprawl
- Technology Startups — Rapid Scaling
- Professional Services Firms — High Contractor Use
- Financial Services Institutions — Strict Compliance
- Healthcare Provider Networks — Decentralized Systems
- Higher Education Institutions — Departmental Autonomy
- Large Retail Chains — High Turnover

## Problem Affected Processes

- Offboarding Access Revocation — IT Operations
- SaaS License Harvesting — Asset Management
- Shadow IT Discovery — Security
- Identity Access Auditing — Governance
- SaaS Expense Reconciliation — Finance
- Access Compliance Auditing — Compliance
- Contractor Lifecycle Management — Vendor Management

## Problem Matching Opportunities

- Autonomous Deprovisioning for Enterprise IT — AI Agent
- Continuous Access Auditing for SecOps — Security Posture
- SaaS License Reclamation for Procurement — Cost Optimization
- Shadow IT Remediation for Cloud Admins — Compliance Tool
- Orphaned Identity Resolution for Infosec — Data Governance

## Problem Token Hero

**Genre**: problem-hero
**Rendered**: Enterprise IT and security teams constantly battle unmanaged access left behind by former employees and contractors.
**Mechanism**: overview-derived-v1
**Template Id**: problem-overview-derived
**Vocab Fingerprint**: 9ba02566dc68fb0f

## Neighborhood

### Related (entails child problem)

- [Lapsed Vendor Credential Exposure](/Problems/Lapsed_Vendor_Credential_Exposure) — entails child problem · Problems

### Competitors

- [Microsoft Entra ID](/Competitors/Microsoft_Entra_ID) — competes with · Competitors
- [Nudge Security](/Competitors/Nudge_Security) — competes with · Competitors
- [Okta](/Competitors/Okta) — competes with · Competitors
- [SailPoint](/Competitors/SailPoint) — competes with · Competitors
- [Cerby](/Competitors/Cerby) — competes with · Competitors

### What it's used for

- [Splunk](/Products/Splunk) — used for · Products
- [Microsoft Entra ID](/Software/Microsoft_Entra_ID) — used for · Software
- [Okta](/Software/Okta) — used for · Software
- [SailPoint](/Software/SailPoint) — used for · Software
- [Workday](/Software/Workday) — used for · Software
- [SAP Concur](/Products/SAP_Concur) — used for · Products

### Entails child problem

- [Departed User Tracking](/Problems/Departed_User_Tracking) — entails child problem · Problems
- [Employee Offboarding Execution](/Problems/Employee_Offboarding_Execution) — entails child problem · Problems
- [Shadow IT Discovery](/Problems/Shadow_IT_Discovery) — entails child problem · Problems
- [Unfederated Account Deletion](/Problems/Unfederated_Account_Deletion) — entails child problem · Problems
- [Unused Seat Reclamation](/Problems/Unused_Seat_Reclamation) — entails child problem · Problems

### Solves problem

- [Gladering](/Startups/Gladering) — candidate solution for · Startups
- [Guest](/Startups/Guest) — candidate solution for · Startups
- [Mailboxdomain](/Startups/Mailboxdomain) — candidate solution for · Startups
- [Millen](/Startups/Millen) — candidate solution for · Startups
- [Forgotten](/Startups/Forgotten) — candidate solution for · Startups

### Similar Problems

- [Permanent Guest Provisioning](/Problems/Permanent_Guest_Provisioning) — similar · Problems
- [Revoke Unmanaged Application Access](/Problems/Revoke_Unmanaged_Application_Access) — similar · Problems
- [Software Seat License Sprawl](/Startups/Rivocess/Problems/Software_Seat_License_Sprawl) — similar · Problems
- [Shadow Provisioning Discovery](/Problems/Shadow_Provisioning_Discovery) — similar · Problems
- [SaaS License Overprovisioning](/Departments/Example_One/Problems/SaaS_License_Overprovisioning) — similar · Problems
- [Privilege Drift Eradication](/Problems/Privilege_Drift_Eradication) — similar · Problems
- [Reconcile Software Spend](/Problems/Reconcile_Software_Spend) — similar · Problems
- [Prevent Auto-Renewal Creep](/Problems/Prevent_Auto-Renewal_Creep) — similar · Problems
- [Software Provisioning Request](/Problems/Software_Provisioning_Request) — similar · Problems
- [Orphaned Resource Termination](/Problems/Orphaned_Resource_Termination) — similar · Problems
- [Security Contract Renewals](/Problems/Security_Contract_Renewals) — similar · Problems
- [Vendor Entitlement Mapping](/Problems/Vendor_Entitlement_Mapping) — similar · Problems

### Similar Metrics

- [Orphaned Account Rate](/Metrics/Orphaned_Account_Rate) — similar · Metrics

### Similar Startups

- [Turnorge](/Startups/Turnorge) — similar · Startups
- [Cessum](/Startups/Cessum) — similar · Startups
- [Departuredepot](/Startups/Departuredepot) — similar · Startups
- [Symon](/Startups/Symon) — similar · Startups
- [Prilum](/Startups/Prilum) — similar · Startups
- [Abdicative](/Startups/Abdicative) — similar · Startups
