# Turnorge

*/Startups/Turnorge*

## Startup Overview

This security engine traces employee OAuth grants to identify and terminate un-federated orphan accounts. Rather than relying on central identity providers to catalog every application in use, the system maps the web of active single-sign-on permissions to locate disconnected software instances. When personnel depart, the engine automatically revokes access to the shadow applications that evade traditional identity management.

IT administrators and security teams face persistent compliance gaps when offboarding users who authorize unsanctioned applications. Standard procedures rely on manual offboarding checklists or rigid corporate directories, leaving unauthorized accounts active long after an employee departs. These lingering access points expose corporate data to external risks while consuming inactive license fees without triggering internal security alerts.

Legacy directory platforms like Okta Lifecycle Management and BetterCloud only govern applications formally bound to the corporate network. This un-federated native solution operates outside that established perimeter, systematically hunting down the rogue accounts created independently by end users. The commercial model aligns entirely with confirmed risk reduction, charging exclusively per successful account revocation rather than demanding blanket per-user subscription fees.

## Startup Founding Hypothesis

**Approach**: that traces OAuth grants to terminate un-federated orphan accounts
**Competitors**:
- [Okta Lifecycle Management](/Competitors/Okta_Lifecycle_Management)
- [BetterCloud](/Competitors/BetterCloud)
- [manual IT offboarding checklists](/Competitors/manual_IT_offboarding_checklists)
**Differentiator2x2**: un-federated app native and priced entirely per successful revocation

## Startup Solution Coordinate

**Solution**: [Orphan Revocation Engine](/Services/Orphan_Revocation_Engine)

## Startup Position2x2

```mermaid
quadrantChart
    x-axis Federated App Focus --> Un-federated App Native
    y-axis Seat or Fixed Subscription --> Priced Per Revocation
    Okta Lifecycle Management: [0.15, 0.20]
    BetterCloud: [0.35, 0.25]
    Manual IT Checklists: [0.70, 0.15]
    Turnorge: [0.85, 0.85]
```

## Startup Offer

**Proof**:
- Targeting 100% elimination of un-federated SaaS sprawl for enterprise IT teams.
- Aiming to save IT operations up to 5 hours per departing employee.
- Intending to recover wasted license spend by catching hidden shadow IT subscriptions.
**Tiers**:
- Name: Standard Revocation · Price: ~$5–$12 per successful revocation · Inclusions: Automated OAuth tracing and termination for standard un-federated web apps, billed only upon verified account closure.
- Name: Volume Commitment · Price: ~$3–$6 per successful revocation · Inclusions: Discounted rate for organizations processing over 500 monthly offboardings, designed to include custom webhook notifications.
**Guarantee**: Turnorge charges strictly for verified, completed account terminations; if an un-federated account requires manual IT intervention to close, that termination attempt is completely free.
**Business Function**: ProvideService
**Objection Handlers**:
- We already use Okta for offboarding. -> Okta only revokes federated SSO apps; Turnorge specifically hunts down un-federated OAuth grants.
- How does it actually delete accounts? -> It is designed to automate app-specific deletion endpoints and standardized privacy requests.
- What if it deletes an active account? -> Revocations are only triggered by verified HRIS departure events with mandatory manager review.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Direct and clinical, communicating with security-first absolute precision.
**Tagline**: Terminate un-federated orphan accounts by tracing hidden OAuth grants.
**Icon Concept**: badge
**Palette Intent**: institutional-cool
**Visual Identity**: A stark palette of steel gray and ice blue pairs with monospaced typography to evoke the precision of access logs and token revocation.
**Archetype Reference**: the-ruler

## Startup Buyer Chain

**Chain**: Turnorge → IAM Administrator → Enterprise Security Team
**Gtm Motion**: Acquires IT teams through a free initial OAuth grant audit that exposes the exact volume of un-federated shadow IT connected to the corporate workspace. Expands revenue seamlessly by charging only per successful revocation, scaling naturally with the customer's ongoing offboarding ticket volume.
**Agent Channel**: Designed to list in automated SecOps and IT helpdesk tool registries (such as LangChain integration libraries or Microsoft Security Copilot plugin directories), enabling autonomous offboarding agents to discover and trigger the Turnorge revocation API when processing departure tickets.
**Primary Channel**: Targeted for listing in the Google Workspace Marketplace and Microsoft Entra ID App Gallery, capturing IT administrators actively searching for shadow IT discovery and automated offboarding add-ons.

## Startup Customer Journey

```mermaid
flowchart LR; A[Workspace Marketplace Listing] --> B[OAuth Grant Audit]; B --> C[Un-federated App Report]; C --> D[HRIS Offboarding Integration]; D --> E[Revocation API]; E --> F[Volume Commitment Contract]; F --> G[SecOps Plugin Registry];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 30-day proof-of-concept with a mid-market engineering team targeting the successful tracing and termination of 100% of un-federated developer tool access for a cohort of 10 offboarded contractors.
- 60-day enterprise pilot running parallel to existing IAM workflows, aiming to identify and automatically close at least 50 orphaned shadow IT accounts missed by standard SSO de-provisioning.
**Target Metrics**:
- Target: 5 hours of manual IT administration time saved per departing employee
- Aim: 100% automated closure rate for un-federated OAuth grants
- Target: 0 orphaned shadow IT accounts remaining active 24 hours post-HRIS departure event
- Aim: 30% reduction in un-allocated monthly SaaS license spend
**Target Case Studies**:
- Mid-market technology company IT Director: Eliminating the 15+ orphaned shadow IT apps per departing engineer to ensure zero un-federated OAuth grants remain active post-departure.
- Enterprise healthcare Security Operations Manager: Achieving 100% automated termination of non-SSO clinical tools, closing the compliance gap between Okta de-provisioning and actual account deletion.
- High-growth marketing agency VP of Operations: Reclaiming wasted monthly SaaS spend by automatically terminating localized design tool subscriptions tied to former contractors.
**Testimonial Targets**:
- Identity & Access Management (IAM) Lead: Relief that the security gap left by non-SSO applications is closed without adding manual tickets to the IT helpdesk.
- Chief Information Security Officer (CISO): Confidence that employee offboarding is completely verified, extending beyond federated SSO to fully terminate shadow IT access.
- IT Procurement Manager: Satisfaction with the pure usage-based pricing, paying only for verified account terminations rather than absorbing another per-seat platform fee.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: SaaS vendors actively block automated account revocation via undocumented APIs to artificially inflate their active user metrics. · Mitigation Status: unmitigated
- Severity: high · Description: Major identity providers like Okta or Microsoft Entra build native OAuth trace-and-revoke capabilities for un-federated apps. · Mitigation Status: unmitigated
- Severity: high · Description: The pay-per-revocation pricing model creates a revenue cliff where earnings plummet to near-zero after the initial historical cleanup. · Mitigation Status: in-progress
- Severity: moderate · Description: Security and IT teams refuse to grant the sweeping read-write permissions Turnorge requires to execute cross-platform account deletions. · Mitigation Status: in-progress

## Startup Competitors

- [Okta Lifecycle Management](/Competitors/Okta_Lifecycle_Management) — IAM Incumbent
- [BetterCloud](/Competitors/BetterCloud) — SaaS Management
- [Manual IT Offboarding Checklists](/Competitors/Manual_IT_Offboarding_Checklists) — Status Quo
- [Torii](/Competitors/Torii) — SMP Alternative
- [Nudge Security](/Competitors/Nudge_Security) — SaaS Security Platform
- [Astrix Security](/Competitors/Astrix_Security) — App-to-App Security

## Startup Solution Stack

- [Un-Federated Deprovisioning Service](/Services/Un-Federated_Deprovisioning_Service) — Service-as-Software
- [OAuth Trace Agent](/Agents/OAuth_Trace_Agent) — Agent
- [Account Revocation Worker](/Agents/Account_Revocation_Worker) — Agent
- [Shadow Graph Engine](/Software/Shadow_Graph_Engine) — Software
- [Revocation Verification API](/Software/Revocation_Verification_API) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the guarantor of zero-trust security instead of a checklist chaser
- **Want**: to eliminate every un-federated orphan account after an employee departs
- **Identity**: the IT operations manager at a scaling enterprise
**Plan**:
- Step: Upload departures · Detail: Provide the list of departing IDs from your HRIS or IT service management tool.
- Step: Confirm revocations · Detail: Review the identified un-federated accounts and approve the automated termination requests.
- Step: Verify closure · Detail: Receive a verified audit trail of completed deletions for your security compliance logs.
**Guide**:
- **Empathy**: Compliance audits are won in the details of the final offboarding report — but manual IT checklists inevitably miss hidden OAuth-linked seats.
**Problem**:
- **Villain**: Shadow OAuth sprawl
- **External**: Manual offboarding checklists miss un-federated accounts in apps like Canva or Miro that employees joined via 'Sign in with Google' rather than Okta SSO.
- **Internal**: You feel anxious knowing dormant identities are ticking time bombs for a data breach.
- **Philosophical**: Why should IT teams accept invisible security gaps when every access grant is digitally traceable?
**Success**: Every un-federated account is closed automatically, and you only pay for verified terminations with zero manual IT intervention.
**One Liner**: Every week, IT operations managers miss un-federated orphan accounts that bypass SSO. Turnorge traces and terminates hidden OAuth grants so your organization is truly zero-trust.
**Positioning**:
- **So That**: terminate un-federated accounts that SSO tools cannot see
- **Unlike**: Okta Lifecycle Management
- **For Whom**: IT operations managers at scaling enterprises
- **Category**: SaaS Identity Revocation
**Call To Action**:
- **Direct**: Submit offboarding list
- **Transitional**: Review OAuth risk report
**Failure Stakes**:
- Compromised orphan accounts
- Failed SOC2 compliance audits
- Wasted monthly license spend
**Transformation**:
- **To**: enforcing absolute identity hygiene instead of managing partial offboarding
- **From**: an IT lead chasing checklists in BetterCloud
**Controlling Idea**: Offboarding must include un-federated apps to ensure total enterprise security.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Every week, IT operations managers miss un-federated orphan accounts that bypass SSO. Turnorge traces and terminates hidden OAuth grants so your organization is truly zero-trust.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: fc058f096e25841a

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: SaaS Identity Revocation for IT operations managers at scaling enterprises. Unlike Okta Lifecycle Management — terminate un-federated accounts that SSO tools cannot see.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: 1db768da63a69af2

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Manual offboarding checklists miss un-federated accounts in apps like Canva or Miro that employees joined via 'Sign in with Google' rather than Okta SSO.
Solution: Every week, IT operations managers miss un-federated orphan accounts that bypass SSO. Turnorge traces and terminates hidden OAuth grants so your organization is truly zero-trust.
Customer: IT operations managers at scaling enterprises
Unlike: Okta Lifecycle Management
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 8f24fe40b234923d

## Startup Token M E D D P I C C

**Pain**: Manual offboarding checklists miss un-federated accounts in apps like Canva or Miro that employees joined via 'Sign in with Google' rather than Okta SSO.
**Metrics**: Target: Every un-federated account is closed automatically, and you only pay for verified terminations with zero manual IT intervention.
**Rendered**: Pain: Manual offboarding checklists miss un-federated accounts in apps like Canva or Miro that employees joined via 'Sign in with Google' rather than Okta SSO.
Economic buyer: IAM Administrator
Metrics: Target: Every un-federated account is closed automatically, and you only pay for verified terminations with zero manual IT intervention.
Competition: Okta Lifecycle Management
**Mechanism**: spine-derived-v1
**Competition**: Okta Lifecycle Management
**Economic Buyer**: IAM Administrator
**Vocab Fingerprint**: e509b96113617676

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: SaaS Identity Revocation for IT operations managers at scaling enterprises

IT operations managers at scaling enterprises — Manual offboarding checklists miss un-federated accounts in apps like Canva or Miro that employees joined via 'Sign in with Google' rather than Okta SSO. Every week, IT operations managers miss un-federated orphan accounts that bypass SSO. Turnorge traces and terminates hidden OAuth grants so your organization is truly zero-trust.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 09552366774d4093

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: SaaS Identity Revocation. Every week, IT operations managers miss un-federated orphan accounts that bypass SSO. Turnorge traces and terminates hidden OAuth grants so your organization is truly zero-trust. Serves IT operations managers at scaling enterprises.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: fae4c9761e2d670f

## Neighborhood

### Candidate solutions

- [Defect Reporting Latency](/Problems/Defect_Reporting_Latency) — candidate solution for · Problems

### What it offers

- [Calead Scan Sentinel](/Services/Calead_Scan_Sentinel) — offers · Services
- [Orphan Revocation Engine](/Services/Orphan_Revocation_Engine) — offers · Services

### Composed of

- [Anomaly Assessment Agent](/Agents/Anomaly_Assessment_Agent) — composes · Agents
- [Volumetric Analysis Service](/Services/Volumetric_Analysis_Service) — composes · Services
- [OEM Format Ingestion API](/Software/OEM_Format_Ingestion_API) — composes · Software
- [Volumetric Parsing Engine](/Software/Volumetric_Parsing_Engine) — composes · Software
- [Code Compliance Worker](/Agents/Code_Compliance_Worker) — composes · Agents
- [Defect Characterization Agent](/Agents/Defect_Characterization_Agent) — composes · Agents
- [Volumetric Validation Service](/Services/Volumetric_Validation_Service) — composes · Services
- [Volumetric Sync API](/Software/Volumetric_Sync_API) — composes · Software
- [Automated Defect Recognition Engine](/Software/Automated_Defect_Recognition_Engine) — composes · Software
- [Code Cross-Reference Worker](/Agents/Code_Cross-Reference_Worker) — composes · Agents
- [Shadow Graph Engine](/Software/Shadow_Graph_Engine) — composes · Software
- [Revocation Verification API](/Software/Revocation_Verification_API) — composes · Software
- [OAuth Trace Agent](/Agents/OAuth_Trace_Agent) — composes · Agents
- [Account Revocation Worker](/Agents/Account_Revocation_Worker) — composes · Agents
- [Un-Federated Deprovisioning Service](/Services/Un-Federated_Deprovisioning_Service) — composes · Services

### Competitors

- [manual USB transport](/Competitors/manual_USB_transport) — competes with · Competitors
- [Zetec TomoView](/Competitors/Zetec_TomoView) — competes with · Competitors
- [Evident OmniPC](/Competitors/Evident_OmniPC) — competes with · Competitors
- [Physical USB Drives](/Competitors/Physical_USB_Drives) — competes with · Competitors
- [Physical USB Transport](/Competitors/Physical_USB_Transport) — competes with · Competitors
- [Manual USB Transfer](/Competitors/Manual_USB_Transfer) — competes with · Competitors
- [Physical USB Transfer](/Competitors/Physical_USB_Transfer) — competes with · Competitors
- [manual USB data transport](/Competitors/manual_USB_data_transport) — competes with · Competitors
- [Evident OmniPC Software](/Competitors/Evident_OmniPC_Software) — competes with · Competitors
- [Zetec TomoView Analysis](/Competitors/Zetec_TomoView_Analysis) — competes with · Competitors
- [MISTRAS PCMS Platform](/Competitors/MISTRAS_PCMS_Platform) — competes with · Competitors
- [Physical USB Transfers](/Competitors/Physical_USB_Transfers) — competes with · Competitors
- [Manual USB Extraction](/Competitors/Manual_USB_Extraction) — competes with · Competitors
- [Manual Visual Scrubbing](/Competitors/Manual_Visual_Scrubbing) — competes with · Competitors
- [Manual USB Transfers](/Competitors/Manual_USB_Transfers) — competes with · Competitors
- [USB Drive Transport](/Competitors/USB_Drive_Transport) — competes with · Competitors
- [Manual USB Drive Transport](/Competitors/Manual_USB_Drive_Transport) — competes with · Competitors
- [Physical USB drive transport](/Competitors/Physical_USB_drive_transport) — competes with · Competitors
- [manual USB data extraction](/Competitors/manual_USB_data_extraction) — competes with · Competitors
- [Okta Lifecycle Management](/Competitors/Okta_Lifecycle_Management) — competes with · Competitors
- [Nudge Security](/Competitors/Nudge_Security) — competes with · Competitors
- [Astrix Security](/Competitors/Astrix_Security) — competes with · Competitors
- [Torii](/Competitors/Torii) — competes with · Competitors
- [Manual IT Offboarding Checklists](/Competitors/Manual_IT_Offboarding_Checklists) — competes with · Competitors
- [BetterCloud](/Competitors/BetterCloud) — competes with · Competitors

### Who it serves

- [Non-Destructive Testing (NDT) Contractor](/CompanyTypes/Non-Destructive_Testing_(NDT)_Contractor) — serves · CompanyTypes

### Embodies

- [Service-as-Software](/Theses/Service-as-Software) — embodies · Theses

### Similar Startups

- [Turnift](/Startups/Turnift) — similar · Startups
- [Symon](/Startups/Symon) — similar · Startups
- [Departuredepot](/Startups/Departuredepot) — similar · Startups
- [Cessum](/Startups/Cessum) — similar · Startups
- [Abdicative](/Startups/Abdicative) — similar · Startups
- [Prilum](/Startups/Prilum) — similar · Startups
- [Hororus](/Startups/Hororus) — similar · Startups
- [Turnoversocket](/Startups/Turnoversocket) — similar · Startups
- [Acaspoint](/Startups/Acaspoint) — similar · Startups
- [Acceam](/Startups/Acceam) — similar · Startups
- [Octity](/Startups/Octity) — similar · Startups
- [Silocrest](/Startups/Silocrest) — similar · Startups
- [Accocess](/Startups/Accocess) — similar · Startups
- [Direridian](/Startups/Direridian) — similar · Startups
- [Accaze](/Startups/Accaze) — similar · Startups
- [Anthembasis](/Startups/Anthembasis) — similar · Startups
- [Corelamp](/Startups/Corelamp) — similar · Startups
- [Cornerstonedawn](/Startups/Cornerstonedawn) — similar · Startups
- [Venturenexus](/Startups/Venturenexus) — similar · Startups
- [Hegen](/Startups/Hegen) — similar · Startups
