A state human services agency governs 1,700+ non-human identities and reclaims 313 Salesforce licenses
313 paid Salesforce licenses were assigned to people who had already left. Oleria gave the agency one view of access across Entra ID, SharePoint, and Salesforce, brought 1,773 non-human identities and 23 AI agents under governance, and removed 1,600+ empty directory groups.

Watch video

1,773
Non-human identities and 23 AI agents
Inventoried, assigned owners, and governed continuously
313
Salesforce licenses
Reclaimed from accounts belonging to former employees
1,633
Empty groups
Identified and removed automatically
Industry
Government and public sector
Use Cases
NHI security
AI agent governance
Adaptive identity governance
Size
~1,000 core staff
~1,500 Entra ID users
~7,900 Salesforce users including external educators and providers
About the organization
The agency serves families, educators, and care providers statewide. Its programs depend on thousands of external users working alongside its own staff. Its services run on Microsoft Entra ID, SharePoint Online, and Salesforce, with lifecycle requests handled through a managed service provider.
The challenge
As services moved to the cloud, permissions spread across three platforms with no shared view, and joiner, mover, and leaver changes ran through manual service provider tickets. The team needed one place to see access, act on it, and prove it to auditors.
- No cross-platform view. The team could not trace inherited permissions from Active Directory and Entra ID into Salesforce objects and SharePoint resources.
- Dormant and leaver access. 506 accounts had been inactive for more than 89 days, including 7 with administrative privileges. 1,539 disabled former employees still held Entra ID and SharePoint group memberships.
- External sharing and ownership gaps. 24,148 assets were shared externally, 318 of them labeled confidential or restricted. More than 11,000 SharePoint resources had no assigned internal owner.
- License spend and ticket delays. 313 Salesforce licenses remained assigned to disabled accounts, and some exit requests waited weeks in the ServiceNow queue.
"Oleria gave us clear visibility across our entire identity landscape within minutes, surfacing dormant accounts, unowned data, and residual access our existing tools missed. Our team now centralizes governance and automates routine lifecycle cleanup without adding operational overhead."
Director of Information Security and Enterprise Architecture, state human services agency
“People are really, really good at sharing things — but not so good at revoking those privileges once they’re no longer needed.”

The solution
The agency deployed Oleria across Entra ID, SharePoint Online, and Salesforce. Oleria ingests permissions, activity, and identity attributes into one Access Knowledge Graph and pairs continuous visibility with automated remediation.
- Unified access graph maps nested groups and traces access from each identity to specific documents, Salesforce objects, and permission set groups.
- Non-human identity and AI agent governance inventories 1,773 service principals, integration accounts, and API tokens plus 23 Copilot Studio agents, with owners and activity thresholds for each.
- Sensitivity-label sharing controls use Microsoft labels to surface externally shared assets, with one-click revocation of dormant third-party and anonymous access.
- Automated lifecycle remediation disables dormant accounts, removes residual group memberships for departed staff, and deletes empty groups older than 30 days.
- Salesforce access certification reviews profiles, permission sets, and permission set groups against actual use each quarter.
Business outcomes
The agency now runs identity governance from one platform, with spend and risk both moving down.
- License savings. 313 Salesforce licenses were reclaimed from former employees' accounts.
- Smaller attack surface. 506 dormant accounts, including 7 privileged admin accounts, were remediated, and residual group access was removed from 1,539 disabled accounts.
- Cleaner directory. 1,633 empty Entra ID groups were removed, and 11,000+ SharePoint resources were brought under owner tracking.
- Protected records. External sharing was reviewed across 24,148 files, securing 318 confidential and restricted documents.
- Non-human identity oversight. 1,773 non-human identities and 23 AI agents are inventoried and governed continuously.
- Faster lifecycle changes. Policy-driven joiner, mover, and leaver workflows reduce dependence on manual service provider tickets.
Key takeaways
- Non-human identities and AI agents now outnumber many agencies' staff, and they need owners and activity limits.
- Connecting identity status to license assignment turns governance into direct budget savings.
- Automated lifecycle workflows close leaver gaps that ticket queues leave open.
“If you ask any CISO, ‘How many files have you shared outside the company?'. . . most don't have answers — or they don’t have easy ways to answer those questions. In Oleria, I can answer those questions with a click.”
.avif)
Vimeo
“Having visibility and the ability to remove that share or that file access...is a real differentiator.”
.avif)
Vimeo
“Oleria allows our business to focus on driving revenue, and less on checking compliance boxes.”
.avif)
Vimeo