Practitioner's guide to the future of identity — new maturity model
Access the guide

A state human services agency governs 1,700+ non-human identities and reclaims 313 Salesforce licenses

313 paid Salesforce licenses were assigned to people who had already left. Oleria gave the agency one view of access across Entra ID, SharePoint, and Salesforce, brought 1,773 non-human identities and 23 AI agents under governance, and removed 1,600+ empty directory groups.

Watch video

1,773

Non-human identities and 23 AI agents

Inventoried, assigned owners, and governed continuously

313

Salesforce licenses

Reclaimed from accounts belonging to former employees

1,633

Empty groups

Identified and removed automatically

Industry

Government and public sector

Use Cases

NHI security

AI agent governance

Adaptive identity governance

Size

~1,000 core staff

~1,500 Entra ID users

~7,900 Salesforce users including external educators and providers

About the organization

The agency serves families, educators, and care providers statewide. Its programs depend on thousands of external users working alongside its own staff. Its services run on Microsoft Entra ID, SharePoint Online, and Salesforce, with lifecycle requests handled through a managed service provider.

The challenge

As services moved to the cloud, permissions spread across three platforms with no shared view, and joiner, mover, and leaver changes ran through manual service provider tickets. The team needed one place to see access, act on it, and prove it to auditors.

  • No cross-platform view. The team could not trace inherited permissions from Active Directory and Entra ID into Salesforce objects and SharePoint resources.
  • Dormant and leaver access. 506 accounts had been inactive for more than 89 days, including 7 with administrative privileges. 1,539 disabled former employees still held Entra ID and SharePoint group memberships.
  • External sharing and ownership gaps. 24,148 assets were shared externally, 318 of them labeled confidential or restricted. More than 11,000 SharePoint resources had no assigned internal owner.
  • License spend and ticket delays. 313 Salesforce licenses remained assigned to disabled accounts, and some exit requests waited weeks in the ServiceNow queue.

"Oleria gave us clear visibility across our entire identity landscape within minutes, surfacing dormant accounts, unowned data, and residual access our existing tools missed. Our team now centralizes governance and automates routine lifecycle cleanup without adding operational overhead."

Director of Information Security and Enterprise Architecture, state human services agency

“People are really, really good at sharing things — but not so good at revoking those privileges once they’re no longer needed.”

Peter Clay
CISO, Aireon

The solution

The agency deployed Oleria across Entra ID, SharePoint Online, and Salesforce. Oleria ingests permissions, activity, and identity attributes into one Access Knowledge Graph and pairs continuous visibility with automated remediation.

  • Unified access graph maps nested groups and traces access from each identity to specific documents, Salesforce objects, and permission set groups.
  • Non-human identity and AI agent governance inventories 1,773 service principals, integration accounts, and API tokens plus 23 Copilot Studio agents, with owners and activity thresholds for each.
  • Sensitivity-label sharing controls use Microsoft labels to surface externally shared assets, with one-click revocation of dormant third-party and anonymous access.
  • Automated lifecycle remediation disables dormant accounts, removes residual group memberships for departed staff, and deletes empty groups older than 30 days.
  • Salesforce access certification reviews profiles, permission sets, and permission set groups against actual use each quarter.

Business outcomes

The agency now runs identity governance from one platform, with spend and risk both moving down.

  • License savings. 313 Salesforce licenses were reclaimed from former employees' accounts.
  • Smaller attack surface. 506 dormant accounts, including 7 privileged admin accounts, were remediated, and residual group access was removed from 1,539 disabled accounts.
  • Cleaner directory. 1,633 empty Entra ID groups were removed, and 11,000+ SharePoint resources were brought under owner tracking.
  • Protected records. External sharing was reviewed across 24,148 files, securing 318 confidential and restricted documents.
  • Non-human identity oversight. 1,773 non-human identities and 23 AI agents are inventoried and governed continuously.
  • Faster lifecycle changes. Policy-driven joiner, mover, and leaver workflows reduce dependence on manual service provider tickets.

Key takeaways

  • Non-human identities and AI agents now outnumber many agencies' staff, and they need owners and activity limits.
  • Connecting identity status to license assignment turns governance into direct budget savings.
  • Automated lifecycle workflows close leaver gaps that ticket queues leave open.

“If you ask any CISO, ‘How many files have you shared outside the company?'. . . most don't have answers — or they don’t have easy ways to answer those questions. In Oleria, I can answer those questions with a click.”

Mark Carter
CIO and CISO
Vimeo

“Having visibility and the ability to remove that share or that file access...is a real differentiator.”

Kevin Towey
Director, Security GRCP
Vimeo

“Oleria allows our business to focus on driving revenue, and less on checking compliance boxes.”

Kevin Towey
Director, Security GRCP
Vimeo