Short, honest answers. If something's missing, the team replies the same day.
We look at the things that actually matter: last login, last real action in the app, whether premium features ever get used, and whether the same person is already covered by a duplicate tool. Every verdict — Green, Yellow, or Red — shows exactly which signal triggered it, so you can defend the call before anyone loses access. No black-box scoring, no AI guesswork.
Every reclaim has a 24-hour bypass window. The seat owner and their manager get a Slack and email heads-up with a one-click 'keep it' button that cancels the revoke instantly. You can also mark anyone as protected, run in dry-run for as long as you want, and require manual approval on any rule before it touches a seat.
Yes. Every reclaim is logged with the user, the app, the rule that fired, and the original permissions. One click in the audit log re-provisions the seat with the same access they had before.
Connect Slack, Google Workspace, GitHub, or any of our 240+ integrations, and your first audit runs in about two seconds. No data migration, no agents to install, no IT ticket. You can stay in dry-run mode for the first week to sanity-check verdicts before anything changes.
We cross-reference members across overlapping categories — Slack and Teams, Zoom and Meet, Notion and Confluence — to surface people paying for two of the same thing. For premium seats, we check whether each license is actually using premium features. Premium licenses with zero premium activity are usually the fastest dollars to recover.
Yes. Every scan, verdict, approval, bypass, and revoke is written to an immutable log with timestamp, actor, and reason. Export to CSV for finance, or hand it straight to a SOC 2 auditor — the format is built for review.
Connect your identity provider and SaaS apps, set how often you want audits to run (daily, weekly, or on-demand), and we do the rest. We measure 'inactive' by real signals — last login, last meaningful action, premium-feature usage — not just whether someone opened the tab. Anything that crosses your reclaim rule (say, 30 days idle on a paid seat) lands in a review queue. You approve, and the reclaim runs with a built-in bypass window so nothing breaks.
Yes, when the workflow is built around it. We default to a 24-hour warning with a one-click bypass for the user and their manager, a protected list for execs and on-call staff, dry-run mode for the first week, and optional manual approval on any rule. Nothing is destructive — every revoke is logged with the original permissions, so it can be re-provisioned in one click.
Shared logins, service accounts, and API users look 'inactive' but they're critical. We auto-detect them from naming patterns, OAuth scopes, and bot tokens, then quarantine them as Protected so they never enter the reclaim queue. You can mark anything — an account, a group, a whole domain — as protected manually, and those protections survive audits, rule changes, and reconnects.
Every reclaim is staged in an approval queue with the rule that fired, the evidence (last login, usage signals, projected savings), and the proposed change. Approve, defer, or protect in one click. Stay in dry-run forever if you want. Require multi-person approval on rules above a spend threshold. Nothing changes in the connected app until someone clicks execute.
Most teams recover 15–35% of their SaaS spend in the first 30 days — mostly from ghost seats, premium licenses no one is using, and duplicate tools like Slack and Teams or Zoom and Meet. Every reclaim is tracked as monthly cost × seats reclaimed and rolled into a savings ledger you can export. Most teams pay SeatMap back in under two weeks.