For IT, Operations & Security

Give access on day one.
Take it back on the last.

Role-based software stacks on arrival, licenses reclaimed when usage stops, and access removed the moment someone leaves.

Role-based provisioning
Offboarding in one action
Idle-seat reclamation
controlpanel.nicklpass.com
Nicklpass control panel showing users, applications, and license assignment
The Problem

Access is granted carefully and removed by memory

Onboarding is a checklist somebody wrote two years ago. Offboarding is whoever remembers which tools the person had. The seats that fall through stay on the invoice for a year.

What gets left behind
1st day

when access should already be right, not requested

12months

a forgotten seat keeps billing after someone leaves

Based on Nicklpass customer deployments

Every orphaned account is two problems: a license you pay for and a door you left open.

Idle licenses and inactive seats flagged for reclamation in Nicklpass
What You Get

One record from joiner to leaver

Nicklpass connects identity, role, access, and usage, so the software someone has always matches the job they are doing.

Provisioning decides what someone can open. Usage decides whether they still need it. Lifecycle is what keeps the two in step.

01

Provisioning

The right stack on day one, without a ticket queue.

Provision applications based on role and department
Create approved software stacks for each team
Assign the right licenses automatically during onboarding
Standardize access across similar employee roles
Role-based application stacks assigned during onboarding
02

Ongoing right-sizing

Access that keeps up with what the person actually does.

Track which applications each employee can access
Monitor whether provisioned applications are actually used
Identify access that is no longer required
Reclaim idle licenses when usage stops
Assigned applications checked against real usage
03

Deprovisioning

Departures close cleanly, and the license comes back.

Remove SaaS access during employee offboarding
Recover licenses immediately after departures
Reduce orphaned accounts and former-employee access
Keep application access aligned with employee status
Maintain a clear record of provisioning and deprovisioning actions
Connect lifecycle actions with usage and license utilization
Reclaimed licenses and removed access recorded in Nicklpass
How It Works

Built on the identity system you already run

Nicklpass reads roles and status from your workspace, then acts on the seats attached to them.

01

Sync identity and roles

Users, groups, and departments come from Google Workspace or Microsoft 365, so role changes and departures are reflected without a second source of truth.

Google WorkspaceMicrosoft 365
02

Define stacks by role

Set the approved application list for each team and role once. New joiners get it automatically, and similar roles stop drifting apart.

Approved stacks
03

Let usage drive the rest

The extension shows whether provisioned tools are actually opened, so idle seats surface on their own instead of waiting for an audit.

Browser Extension
Identity and status
Google Workspace Connected
Users, groups, departments, and status changes sync automatically.
Import
Microsoft 365
Sync users and access granted through Microsoft Entra.
Connect
Access and usage
Browser extension Connected
Shows whether provisioned applications are being opened, at domain level only.
Force install
Approved stacks Active
Role and department software lists applied at onboarding.
Edit
Licenses and cost
Plaid Connected
Reclaimed seats valued against what the subscription actually costs.
Manage

The offboarding nobody finished

Nicklpass agents remove access when people leave, reclaim seats that have gone idle, and keep a record of every action taken. Each one is logged with the license it recovered and the access it closed.

The Result

People get what they need, and only while they need it

Fewer tickets on the way in, no loose ends on the way out.

Assignthe right stack automatically by role and department
Standardizeaccess so similar roles stop drifting apart
Monitorwhether provisioned tools are actually opened
Reclaimidle seats without waiting for a renewal
Removeaccess the day someone leaves
Recordevery provisioning and deprovisioning action
Lifecycle is a security control as much as a cost one

A former employee with a live account is a standing risk, and an unused seat is a standing charge. They are usually the same account. Handling both in one record means the security review and the software budget stop telling different stories about who has access to what.

Questions

Straight answers

Does this replace our identity provider?

No. Google Workspace or Microsoft 365 stays the source of truth for who works here. Nicklpass handles the SaaS seats attached to those people, which is the part identity providers do not price or reclaim.

What happens when someone changes role?

Their access is compared against the approved stack for the new role. What is missing gets assigned, and what is no longer needed is flagged for removal rather than pulled silently.

Can access be removed automatically on departure?

Yes. Offboarding can remove SaaS access and recover licenses as soon as status changes, with every action recorded. Teams that prefer a review step can require approval instead.

How do you know a seat is genuinely idle?

From usage, not assumptions. Sign-in activity plus the browser extension show whether a provisioned tool has been opened, and over what period, before anything is reclaimed.

Will employees notice the extension?

No. It installs from the admin console and reads domain-level metadata only. Never page content, keystrokes, or personal credentials.

Onboarding at volume, or under audit?

Talk to sales about deploying with your SSO or MDM system, approval workflows, and exportable records of provisioning and deprovisioning actions.

Up to
30%

average savings on subscription spend

Lifecycle control is where usage data turns into money back. Seats stop outliving the people they were bought for, and access stops outliving the job.