Monthly Okta access review to reclaim unused licenses
Every month, find the accounts and app seats nobody has used in 60 days, then hand your team a review-ready list of licenses to reclaim.
On the first Monday of every month, run an access review of our Okta org so we can reclaim licenses we are paying for but not using. This is a read-only review. Do not deactivate any account and do not remove any app assignment. Everything you find goes into a spreadsheet and a Slack summary for a human to approve.
Start by using Okta List Applications to walk our app integrations, focusing on the active ones. For each app, use Okta List Application Users to pull the people assigned to it. Also use Okta List Users to pull profile details like account status, department, and job title, since that context is what lets you tell a real person apart from a service account.
Then use Okta List System Log Events to find each person's most recent successful sign-in. Query the log with explicit start and end times and page through the results. Okta keeps System Log history for 90 days by default, so the lookback window has to stay inside 90 days. If somebody has no successful sign-in event anywhere in the window, treat that as dormant rather than an error, and record it as no sign-in in the last 90 days instead of failing the run.
Flag two things. First, any account with no successful sign-in in the last 60 days. Second, any assignment where the person has never actually signed in to that specific app during the window, even if they are signing in to Okta generally. The 60-day threshold is the main knob in this workflow, so keep it in one obvious place that is easy to change to 30 or 90 days.
Then use judgement to separate genuinely reclaimable seats from accounts that are quiet for a good reason. Break-glass and emergency admin accounts are supposed to sit unused. Service accounts and integration users often never sign in interactively at all. People on parental or medical leave will look dormant but should keep their access. Use naming patterns, job titles, departments, and account status to make the call, and when a case is ambiguous say so instead of guessing. Give every flagged item a clear recommendation such as reclaim, keep, or needs review.
Append one row per flagged item to the review tab of our access review spreadsheet using Google Sheets Append Values. Each row should capture the review date, the person's name and email, the app, the days since their last successful sign-in, whether this is a dormant account or an unused app assignment, your recommendation, and a one-line reason. Append to the existing tab and do not overwrite what is already there, since the history of past reviews is the point.
Finally, post a summary to our IT channel with the Slack Send a Message action. Lead with the estimated number of reclaimable seats, since that is the number people care about. Then break it down by app, call out the biggest single opportunities, note how many items you set aside as expected quiet accounts and why, and point to the spreadsheet for the full detail. Close by making clear that nothing has been changed and that a human needs to approve the reclaims.
Example output
What does this prompt do?
- Walks every app connected to your Okta account once a month and lists who is assigned to each one.
- Checks when each person last signed in, and spots people holding a seat on an app they have never actually opened.
- Separates real savings from accounts that are quiet for a reason, like emergency admin logins, service accounts, and people on leave.
- Logs every flagged seat in a spreadsheet and posts a Slack summary that leads with how many licenses you could reclaim.
What do I need to use this?
- An Okta account with admin access, so the review can see your apps, your people, and your sign-in history.
- A Google Sheets spreadsheet with a tab for the review, which the workflow adds a row to each month.
- A Slack workspace and a channel where the monthly summary should land.
- Nothing else. The review only reads and reports, it never removes anyone's access.
How can I customize it?
- Change the 60-day threshold. Thirty days is aggressive and good for expensive tools, ninety days is gentler for software people only use occasionally.
- Change when it runs. The first Monday of each month is the default, but quarterly works well if your license renewals are quarterly.
- Tell it which accounts to always leave alone, such as your break-glass admin logins, shared service accounts, and anyone currently on leave.
FAQs
Will this deactivate anyone automatically?
How far back can it look?
What about our service accounts and emergency admin logins?
What if someone is on parental or medical leave?
Do I need a separate compliance tool to run access reviews?
Related templates
When your flight moves, your calendar times get corrected automatically and you get a Slack note naming the meetings you're about to miss.
Every 15 minutes, forwarded phishing reports get traced back to the server that really sent them, with a verdict in Slack and the worst senders reported.
Every Monday, check every S3 bucket for public exposure, missing encryption and weak backup settings, then get the risks ranked in Slack.
Every weekday at 7am, sign in to the tender portals you track, filter new notices against your bid criteria, and open a deal for the ones worth chasing.
Every weekday at 4pm, spot the threads that went quiet, stage a ready-to-send nudge in your mailbox, and get a ranked Slack recap.
Every Monday, rank the week's matches by expected demand, put the big ones on your venue calendar, and post a rota-ready summary to Slack.
Stop paying for seats nobody uses.
Run a monthly access review that tells you exactly which licenses you can reclaim, and leaves the final call to you.