Zombie Licensing

From Detection to Remediation

Most SaaS management platforms stop at finding the waste. Lojycal closes the loop — every dormant seat is traced, verified, previewed, executed and kept reversible, with an auditor-grade entry written for every action.

Finding waste is the easy part

Every SaaS estate carries a long tail of dormant seats — licences provisioned for joiners who never logged in, contractors that left, teams that migrated tools, free trials silently upgraded into paid tiers. The discovery dashboard fills up. The invoice keeps arriving.

The reason this waste survives is not detection — it is fear of the wrong revoke. Cut the wrong seat and you break a live workflow, lock a director out mid-quarter, or wipe a licence that turned out to be in active use under a service account.

So the dormant list grows. Spend grows with it. And nobody owns the action because nobody can prove the action is safe.

~22%
of typical SaaS seats are dormant
5-figure
annual % of spend trapped in zombie licences
weeks
time-to-detect in spreadsheet-driven estates
days
time-to-safe-revoke without a controlled path

The solution is Lojycal

Detection without remediation is just a dashboard. Lojycal turns the dormant list into a controlled, reversible, audited workflow.

The five-step remediation ledger

Step 1 · Trace

Originating identity, app and entitlement

Every flagged seat is linked back to its IdP user, app assignment and the entitlement chain that granted it. No anonymous deletions, no orphan rows — the lineage of the licence is part of the record before anyone touches it.

Step 2 · Verify

Inactivity threshold + assignment history

Lojycal verifies last sign-in, last meaningful action, assignment provenance and service-account markers against the configured threshold. A seat is only classified as dormant once the evidence holds up against the policy you set.

Step 3 · Preview

Full dry-run of the de-provisioning workflow

Before any state change, the exact API calls that will execute against the connected system are rendered in advance, with the diff against current state. The administrator sees the plan, not a promise.

Step 4 · Execute

Revoke, reconcile, record

On approval Lojycal revokes access, removes application entitlements, reconciles the asset against procurement records and writes a WORM audit entry directly into the operational ledger. One action, one durable record.

Step 5 · Reversible

Signed rollback token retained

Every remediation keeps a signed rollback token inside the retention window, so the action can be reversed cleanly if context changes. A controlled remediation path — never a blind deletion event.

Eliminating waste is where the value is created

Lojycal closes the loop end-to-end — from the moment a seat goes dormant to the audited, reversible action that frees the spend. The dormant list stops growing because somebody can finally act on it.

  • Every revoke ties back to its IdP grant and entitlement chain.
  • Dry-run preview before any state change against the connected system.
  • WORM audit entry written for every executed action.
  • Signed rollback token retained inside the configured retention window.
  • Reconciled against procurement records — the ledger stays in sync.
  • No blind deletions. Ever.

That's proper Lojyc.

Start being Lojycal today.