# Permanent Guest Provisioning

*/Problems/Permanent_Guest_Provisioning*

## Problem Overview

IT and security teams provision guest accounts for contractors, vendors, and external agencies to collaborate on internal SaaS platforms and code repositories. When these short-term engagements end, project managers fail to notify IT, leaving third-party access active indefinitely. This creates hidden attack vectors and consumes expensive per-seat software licenses.

Unlike full-time employees governed by automated HR systems, guest workers lack centralized lifecycle triggers. Identity providers process the initial access request but have no visibility into contract expiration dates or project milestones. Consequently, de-provisioning relies entirely on manual audits or proactive alerts from business units, which rarely happen in practice.

Security administrators attempt to manage this by conducting periodic access reviews, exporting user lists into spreadsheets and chasing department heads for verification. This manual reconciliation scales poorly across dozens of disparate applications. The result is a growing backlog of unmonitored external accounts connected to sensitive corporate data long after the vendor relationship terminates.

## Problem Severity Frequency

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Severity**: 3
**Frequency**: quarterly
**Budget Reality**:
- **Price Ceiling**: ~$10k-25k/yr - caps near the value of recovered software licenses and offset audit labor
- **Who Controls Spend**: CISO or VP IT signs, Identity Access Management lead recommends
- **Existing Budget Line**: true
- **Switching Cost From Status Quo**: moderate: requires integration with existing Identity Providers and granular API connections to dozens of downstream SaaS applications
**Regulatory Risk**: high
**Time Cost Per Event**: ~3-5 days of security admin and department head labor per quarterly review
**Money Cost Per Event**: ~$1k-3k in labor per review cycle, plus ongoing wasted per-seat license fees
**Annual Cost Per Affected Entity**: ~$30k-80k all-in for wasted licenses and manual reconciliation labor

## Problem Why Now

The transition away from zero-interest-rate policies in 2023 forced finance teams to scrutinize per-seat SaaS expenditures, exposing massive waste tied to dormant contractor licenses. Concurrently, attackers shifted tactics to exploit these forgotten supply-chain access points, leveraging compromised third-party credentials to bypass primary defenses. Previously, companies absorbed the software costs and accepted the security risk, but new regulatory mandates regarding incident disclosure demand tighter control over non-employee identities.

Legacy Identity and Access Management systems fail to address this because they rely entirely on deterministic lifecycle triggers from human resources platforms. External vendors, agencies, and short-term contractors never enter these centralized HR databases, leaving IT without a reliable system of record for project expiration dates. Security administrators attempt to compensate using manual quarterly access reviews, but reconciling thousands of guest identities across disjointed platforms via spreadsheets collapses under modern third-party collaboration volumes.

The recent maturation of large language models, specifically their ability to reliably parse long-context legal and financial documents as of early 2024, creates a new technical mechanism to solve this. Systems can now ingest unstructured Statements of Work or vendor agreements directly from procurement tools to extract precise engagement timelines and scope. This allows IT teams to bind identity provisioning to contractual reality, replacing reliance on human memory with automated, intent-based access revocation.

## Problem Current Solutions

**Status Quo**: Security administrators export user directories from identity providers into spreadsheets and manually message department heads to verify if external contractors still require access.
**Workarounds**:
- exporting CSV user directories
- chasing sponsors via Slack
- setting manual calendar reminders for contract ends
- scripting 90-day inactivity suspensions
**Named Tools In Use**:
- [Okta](/Products/Okta)
- [Microsoft Entra ID](/Products/Microsoft_Entra_ID)
- [Microsoft Excel](/Products/Microsoft_Excel)
- [Slack](/Products/Slack)
- [GitHub Enterprise](/Products/GitHub_Enterprise)
**Why Insufficient**: Identity providers are designed to sync with automated HR systems for employee lifecycles but possess no native awareness of external project milestones or vendor contract end dates. They cannot dynamically trigger offboarding based on engagement status, reducing guest de-provisioning to a retroactive, human-dependent auditing exercise.

## Problem Market Profile

**Incumbents**:
- [Okta](/Problems/Permanent_Guest_Provisioning/Competitors/Okta)
- [Microsoft Entra ID](/Problems/Permanent_Guest_Provisioning/Competitors/Microsoft_Entra_ID)
- [SailPoint](/Problems/Permanent_Guest_Provisioning/Competitors/SailPoint)
- [Lumos](/Problems/Permanent_Guest_Provisioning/Competitors/Lumos)
- [Opal Security](/Problems/Permanent_Guest_Provisioning/Competitors/Opal_Security)
**Substitutes**:
- exporting CSV user directories
- chasing sponsors via Slack
- setting manual calendar reminders for contract ends
- scripting 90-day inactivity suspensions
**Position Axes**:
- Context Source (Directory/HR-driven vs. Project/Contract-driven)
- Enforcement Method (Periodic Audit vs. Continuous Auto-revocation)
**Market Dynamics**: The market is shifting from static, scheduled access reviews toward continuous identity security, with modern access management tools attempting to consolidate internal employee and external guest lifecycles into a single automated control plane.
**Competition Concentration**: Incumbents and legacy identity platforms cluster heavily in the directory-driven, periodic audit quadrant, relying entirely on structured HR systems to feed status changes. Substitutes like CSV exports and Slack messages dominate the directory-driven, manual enforcement space. The project-driven, continuous auto-revocation quadrant remains comparatively unoccupied, lacking solutions that natively link infrastructure access to dynamic vendor contract dates and project milestones.

## Mint Vocabulary Bag

**Action Verbs**:
- provision
- whitelist
- revoke
- expire
- validate
- authorize
**Gerund Stems**:
- provision
- whitelist
- onboard
- expire
- revoke
- validate
**Abstract Nouns**:
- scope
- tenure
- egress
- ingress
- clearance
- lifecycle
**Concrete Nouns**:
- badge
- token
- proxy
- cred
- key
- account
**Metaphor Nouns**:
- envoy
- sentinel
- beacon
- herald
- threshold
**Structure Nouns**:
- directory
- ledger
- vault
- portal
- terminal
- plane

## Problem Candidate Solutions

- [Ledgontract](/Problems/Permanent_Guest_Provisioning/Startups/Ledgontract) — Agent
- [Intractablelamp](/Problems/Permanent_Guest_Provisioning/Startups/Intractablelamp) — Service-as-Software
- [Chronic](/Problems/Permanent_Guest_Provisioning/Startups/Chronic) — Software
- [Planebase](/Problems/Permanent_Guest_Provisioning/Startups/Planebase) — Agent
- [Scopeforge](/Problems/Permanent_Guest_Provisioning/Startups/Scopeforge) — Software

## Problem Solution Space2x2

```mermaid
quadrantChart
    x-axis Manual Access Reviews --> Continuous Verification
    y-axis Coarse Role Mapping --> Granular Resource Scoping
    quadrant-1 Dynamic Precise Access
    quadrant-2 Static Precise Access
    quadrant-3 Static Broad Access
    quadrant-4 Dynamic Broad Access
    Ledgontract: [0.80, 0.70]
    Intractablelamp: [0.20, 0.30]
    Chronic: [0.60, 0.20]
    Planebase: [0.30, 0.80]
    Scopeforge: [0.90, 0.90]
```

## Problem Affected Roles

- IT Operations Manager — Guest Provisioning
- Security Administrator — Access Reviews
- Project Manager — Contractor Lifecycle
- Vendor Risk Manager — Third-Party Access
- Software Asset Manager — License Costs
- IT Compliance Auditor — Access Audits
- Engineering Manager — Repository Access
- Identity Access Administrator — IAM Operations

## Problem Affected Companies

- Enterprise Software Publishers — High Code Access
- Global Marketing Agencies — Freelance Heavy
- Financial Services Firms — Strict Compliance
- Media Production Studios — Project-Based Crews
- Healthcare Networks — B2B Vendor Heavy
- E-Commerce Retailers — External Logistics
- Managed IT Providers — Decentralized Access
- Management Consulting Firms — Subcontractor Ecosystems

## Problem Affected Processes

- Vendor Lifecycle Management — Procurement
- Access Entitlement Review — Security Operations
- Software License Management — IT Operations
- Project Offboarding Workflow — Project Management
- Contractor Identity Provisioning — Identity Management
- Compliance Audit Reporting — Governance
- Third-Party Access Governance — Access Control

## Problem Matching Opportunities

- Autonomous Vendor Access Deprovisioning — Identity Security
- Dormant Guest Identity Remediation — IAM Operations
- Predictive Contractor License Recovery — SaaS Management
- Just-In-Time Partner Access Control — Zero Trust
- Continuous External User Auditing — Compliance

## Problem Token Hero

**Genre**: problem-hero
**Rendered**: IT and security teams provision guest accounts for contractors, vendors, and external agencies to collaborate on internal SaaS platforms and code repositories.
**Mechanism**: overview-derived-v1
**Template Id**: problem-overview-derived
**Vocab Fingerprint**: 73baae5d609e7627

## Neighborhood

### Related (entails child problem)

- [Lapsed Vendor Credential Exposure](/Problems/Lapsed_Vendor_Credential_Exposure) — entails child problem · Problems

### Competitors

- [Lumos](/Competitors/Lumos) — competes with · Competitors
- [Microsoft Entra ID](/Competitors/Microsoft_Entra_ID) — competes with · Competitors
- [Okta](/Competitors/Okta) — competes with · Competitors
- [Opal Security](/Competitors/Opal_Security) — competes with · Competitors
- [SailPoint](/Competitors/SailPoint) — competes with · Competitors

### What it's used for

- [GitHub Enterprise](/Products/GitHub_Enterprise) — used for · Products
- [Microsoft Entra ID](/Software/Microsoft_Entra_ID) — used for · Software
- [Microsoft Excel](/Software/Microsoft_Excel) — used for · Software
- [Okta](/Software/Okta) — used for · Software
- [Slack](/Software/Slack) — used for · Software

### Entails child problem

- [Contract Date Extraction](/Problems/Contract_Date_Extraction) — entails child problem · Problems
- [Guest Inactivity Detection](/Problems/Guest_Inactivity_Detection) — entails child problem · Problems
- [Orphaned License Harvesting](/Problems/Orphaned_License_Harvesting) — entails child problem · Problems
- [Sponsor Access Verification](/Problems/Sponsor_Access_Verification) — entails child problem · Problems
- [Ticket Based Access](/Problems/Ticket_Based_Access) — entails child problem · Problems

### Solves problem

- [Intractablelamp](/Startups/Intractablelamp) — candidate solution for · Startups
- [Ledgontract](/Startups/Ledgontract) — candidate solution for · Startups
- [Planebase](/Startups/Planebase) — candidate solution for · Startups
- [Scopeforge](/Startups/Scopeforge) — candidate solution for · Startups
- [Chronic](/Startups/Chronic) — candidate solution for · Startups

### Similar Problems

- [Orphaned Account Cleanup](/Problems/Orphaned_Account_Cleanup) — similar · Problems
- [Revoke Unmanaged Application Access](/Problems/Revoke_Unmanaged_Application_Access) — similar · Problems
- [Software Seat License Sprawl](/Startups/Rivocess/Problems/Software_Seat_License_Sprawl) — similar · Problems
- [SaaS License Overprovisioning](/Departments/Example_One/Problems/SaaS_License_Overprovisioning) — similar · Problems
- [Shadow Provisioning Discovery](/Problems/Shadow_Provisioning_Discovery) — similar · Problems
- [Audit Contractor Management](/Problems/Audit_Contractor_Management) — similar · Problems
- [Software Provisioning Request](/Problems/Software_Provisioning_Request) — similar · Problems
- [Security Contract Renewals](/Problems/Security_Contract_Renewals) — similar · Problems
- [Cross-Border Data Security](/CompanyTypes/Offshore_Accounting_BPO/JobTypes/Outsourced_%2F_CAS_Firm_Bookkeeper/Problems/Cross-Border_Data_Security) — similar · Problems
- [Prevent Auto-Renewal Creep](/Problems/Prevent_Auto-Renewal_Creep) — similar · Problems
- [Access Provisioning](/Problems/Access_Provisioning) — similar · Problems
- [Contractor Procurement Standardization](/Problems/Contractor_Procurement_Standardization) — similar · Problems
- [Third-Party Vendor Vulnerability](/Problems/Third-Party_Vendor_Vulnerability) — similar · Problems
- [Vendor Entitlement Mapping](/Problems/Vendor_Entitlement_Mapping) — similar · Problems
- [Privilege Drift Eradication](/Problems/Privilege_Drift_Eradication) — similar · Problems
- [Software Seat License Sprawl](/CompanyTypes/Offshore_Accounting_BPO/JobTypes/Outsourced_%2F_CAS_Firm_Bookkeeper/Problems/Software_Seat_License_Sprawl) — similar · Problems
- [Reconcile Software Spend](/Problems/Reconcile_Software_Spend) — similar · Problems

### Similar Startups

- [Cutlock](/Startups/Cutlock) — similar · Startups

### Similar Metrics

- [Orphaned Account Rate](/Metrics/Orphaned_Account_Rate) — similar · Metrics
