
Quick summary: Oleria Trustfusion automates the discovery of dormant, inactive user and non-human accounts that quietly drain IT budgets and expand your attack surface. By continuously correlating HR, IDP, and actual application-level activity signals, Oleria helps identity security teams eliminate "zombie accounts" and recover up to 15–30% of SaaS software spend.
Security and IT teams gain continuous, accurate visibility into every licensed account — regardless of source system — and can immediately identify accounts that are inactive but still consuming licenses. The result is a smaller attack surface, reduced SaaS spend, and an auditable record of remediation actions taken.
Business impact: Organizations typically find 15–30% of licensed seats tied to dormant accounts. Revoking them eliminates a high-risk initial-access vector—zombie accounts—that are often missed by traditional deprovisioning, and recovers budget that can be immediately redeployed.
Identifying inactive licensed accounts sounds simple, but in practice it requires reconciling data across HR systems, identity providers, and dozens of SaaS applications — each with its own definition of "active" and its own activity log format. Without a unified platform, teams face:
· Fragmented data sources. HR systems, Okta/Entra ID, Salesforce, GitHub, Snowflake, and others each hold a partial view. No single tool correlates them automatically.
· No standard definition of dormancy. Last-login timestamps alone are unreliable. A user can appear "active" in an IDP but never touch the downstream SaaS application the license is for.
· License data lives in finance, not security. Procurement and IT manage seat counts in spreadsheets or separate ITAM tools that are rarely connected to identity or access data.
· Manual reconciliation is slow and error-prone. Quarterly audits by hand take weeks. By the time the list is clean, new joiners and leavers have already made it stale.
· Non-human identities are invisible. Service accounts, shared accounts, and OAuth-based app integrations hold licenses too — but are rarely included in human-focused access reviews.
· Offboarding gaps persist. Even when HR systems trigger deprovisioning, timing delays and partial automation leave accounts open — and licensed — for days, weeks, or longer.
As a core capability of our AI native Identity Security Platform, Oleria Trustfusion continuously ingests identity, access, and activity signals from across your environment and normalizes them into a composite Access Graph. This graph makes it possible to calculate true dormancy — not just IDP last-login, but actual application-level activity — and to surface every licensed account that no longer shows meaningful use.

Every human identity, non-human identity (NHI), and application account is correlated into a single record, enriched with HR status, IDP attributes, and per-application activity.
Oleria applies configurable dormancy windows (e.g., 30, 60, 90 days) against real application activity data — not just IDP signals — so the dormancy finding reflects actual usage.
Oleria surfaces which accounts carry active license assignments so teams can prioritize reclamation by cost impact, not just account count.
Service accounts, shared accounts, and OAuth app grants are included in dormancy detection, closing the blind spot that human-only audits miss.
Findings are packaged into Posture Campaigns with owner assignment, due dates, and workflow integration — so remediation is tracked, not just flagged.
Unlike point-in-time audits, Trustfusion re-evaluates dormancy daily, so the list stays current as joiners, movers, and leavers change the environment.
Step 1 — Ingesting Identity Data from HR & SaaS Applications
Oleria connectors pull identity records from HR systems (Workday, BambooHR), IDPs (Okta, Entra ID), and SaaS applications (Salesforce, GitHub, Snowflake, Microsoft 365, and more). License assignment data is ingested alongside access data.
Step 2 — Normalizing and Correlating the Oleria Access Graph
Records are deduplicated and correlated into the Access Graph. Each identity object — human or non-human — is enriched with employment status, account status, group memberships, role assignments, and last-activity timestamps at the application level.
Step 3 — Evaluating Multi-System Dormancy Thresholds
Oleria Trustfusion, an AI native Identity Security Platform applies the configured dormancy threshold against application-level activity signals. Accounts that have not performed any meaningful action within the window — and still hold a license assignment — are flagged as inactive-licensed.
Step 4 — Surfacing Security Findings and Initiating Remediation
Findings appear in the Access Inventory and Posture Dashboard. Security or IT owners can review them in the Identity 360 View, launch a Posture Campaign, assign ownership, and track revocation through to closure. An audit trail is maintained for compliance evidence.
A mature implementation of this use case produces measurable, repeatable outcomes across people, process, and technology:
· Zero surprise licenses. Every licensed account in every SaaS application is known to the identity security team, regardless of how it was provisioned.
· Dormancy SLA met. Inactive licensed accounts are identified within one business day of crossing the dormancy threshold and remediated within an agreed SLA (typically 5–10 business days).
· Offboarding completeness. When an employee is terminated, all downstream SaaS licenses are revoked automatically or flagged for review within 24 hours — with evidence captured for SOX/ISO 27001 audits.
· NHI included. Non-human identities (service accounts, OAuth grants, shared accounts) are part of the same dormancy workflow, not handled separately or ignored.
· License reclamation tracked. The number of licenses reclaimed per quarter is reported to finance and security leadership as a KPI, closing the loop between identity security and SaaS cost management.
· Audit-ready evidence. Each remediation action — who flagged it, who approved it, when it was revoked — is logged in Trustfusion and exportable for auditor review.

Yes. Service accounts, shared accounts, and application identities (OAuth grants, API keys, managed identities) are included in the Access Graph and subject to the same dormancy evaluation as human accounts. This is a significant gap in traditional ITAM and access review tools.
Trustfusion surfaces findings and initiates Posture Campaigns, which can be integrated with IDP workflows and ITSM tools (e.g., ServiceNow, Jira) for automated or guided remediation. The level of automation is configurable — most organizations start with guided remediation and move toward automation once confidence in the signal is established.
Dormancy is configurable per organization. The default threshold is 90 days of no recorded application-level activity. Admins can set different thresholds for different application risk tiers — for example, 30 days for privileged admin accounts and 90 days for standard SaaS users. Oleria uses real application activity signals, not just IDP last-login, which is often a poor proxy for actual use.
Oleria ingests license assignment data from SaaS connectors (e.g., Microsoft 365 E3/E5 SKUs, Salesforce license types, GitHub seats). Any account with an active license assignment is included in dormancy evaluation, regardless of how the license was allocated.
IDPs track authentication events, but they do not have visibility into application-level activity within SaaS tools, nor do they correlate license data across applications. A user who last authenticated to Okta last week but has not opened Salesforce in six months will appear "active" in the IDP. Oleria sees the full picture.
Most Oleria customers see their first inactive-licensed account findings within hours of completing connector setup. A full baseline — covering all applications, with dormancy calculations applied — is typically available within 24–48 hours of initial ingestion.
Yes. Both frameworks require evidence of periodic access reviews and timely deprovisioning. Trustfusion provides continuous monitoring (satisfying the "periodic" requirement with real-time currency) and a full audit trail of remediation actions, which auditors can review directly or export.