People Ops Buyer.

Identity governance / SaaS operations / Product assessment

ToriiIdentityCheck which app accounts it can remove

People Ops Buyer research desk · US-led evaluation · Microsoft Entra estate · Updated

Compare Torii Identity if employees have app accounts that your identity provider cannot find or remove. For a 500-person Entra employer, first test what Entra can already revoke, then trial Torii on the accounts left behind.

Check the app itself: Torii says an “offboarded” status does not always mean access was removed. Its documented real-time triggers list Google Workspace, Okta and BambooHR; ask it to demonstrate the Entra connection you would buy.

This is a researched buying assessment of Torii Identity and adjacent Torii SMP scope, not a hands-on product review, security audit, vendor score or claim that every integration behaves the same.

In this assessment
  1. Who should buy Torii Identity?
  2. What does “offboarded” actually prove?
  3. Can an Entra-led employer rely on a real-time exit?
  4. Check access between employee departures
  5. What should a Torii quote contain?
  6. Five account-removal tests to run before buying
  7. When should the buyer choose something else?

Who should buy Torii Identity?

Torii combines identity governance with discovery signals from direct integrations, identity and SSO systems, finance data and an optional browser extension. Its discovery help explicitly distinguishes discovering a user's app account from observing usage. A browser visit does not prove that the employee has an account in that app.

It is a weaker purchase if Entra already manages the relevant accounts and app owners can show that departing employees lose access. It is also a poor buy for an organisation that will not appoint app owners, resolve unknown accounts or maintain offboarding methods as the organisation adds and removes apps.

Torii's current pricing page separates Identity Governance & Administration, SaaS Management and AI Management scopes. Ask which products the quote includes: access governance, SaaS discovery and renewals, or both. A feature shown in the demo may belong to a separately priced product.

What does “offboarded” actually prove?

Torii's IGA product page makes a broad last-day revocation promise. Its offboarding help describes what each offboarding method actually does. An owner can mark a task done without removing the app account.

For each high-risk app, test the removal action, the resulting account state and any session opened before the employee left. If Torii ignores an app, assign someone to remove access through another system.

Interpret Torii's documented offboarding methods before buying
MethodWhat Torii can recordWhat the buyer still has to prove
Automatic actionConfigured action executed successfully.That the selected action actually removes the required app access and session, where relevant.
Delegated taskOwner marks a request done or a monitored Jira status reaches its configured end; some other tickets count when opened.The owner disabled or deleted the account in the app.
IgnoreNo Torii removal action; the user leaves Torii's current app-user list.The external identity or app owner completed revocation and can show its evidence.

Can an Entra-led employer rely on a real-time exit?

Torii's real-time offboarding guide names Google Workspace, Okta and BambooHR for its App Event trigger. It says integrated-app information otherwise syncs every 24 hours and state-based workflow triggers can take up to an hour even when some attributes update in real time.

For BambooHR, the immediate-termination event is a beta path; future-dated terminations follow a different route.

That document does not list Entra as an App Event source. Other Entra integrations or custom methods may exist; this document does not establish them.

In an Entra-based trial, make Torii demonstrate the exact HRIS-to-Entra-to-Torii event and elapsed time with your proposed licences. Keep an emergency directory and app-side revocation route outside the scheduled workflow until it passes. Microsoft itself says Entra cannot directly revoke a token issued by another application.

Check access between employee departures

Torii's Access Governance instructions can compare intended access with connected app roles or IdP group membership, show deviations, assign app owners and choose monitoring, tasking or automatic remediation. Use this to find employees whose current app permissions differ from your policy, including those who have changed jobs internally.

For an app without a direct integration, governance may be based on IdP groups or uploaded data rather than the app's own role state. A deviation can close because a policy is changed, disabled or its integration disconnected, not solely because somebody's access changed.

Torii's remediation guide says automatic group-based fixes may fall back to a task for manually assigned app access. For a policy-deviation task, Torii checks the policy again after the owner marks it done. Confirm that this check applies to the workflow you are buying.

We would roll out governance with remediation set to None, validate deviations with app owners, then use tasks before enabling app-by-app automatic fixes. That sequence follows Torii's documented recommendation. Start with one sensitive app: change a test employee’s role, run the fix and check their permissions in the app.

What should a Torii quote contain?

Torii does not publish a price for this 500-person Identity purchase.

Its subscription guide ties Basic licensing to employee count, but Professional and Enterprise billing can differ. Request the counting rules for the Identity package you would buy.

Request the complete annual price and renewal terms for 500 employees plus the actual contractor and inactive-user treatment.

Have the quote list each included product and service:

  • Identity Governance and any SMP discovery, finance or renewal features.
  • Browser extension deployment, app integrations, action rights and custom actions.
  • Data import, implementation, support and extra environments.

Ask who maintains each connector and the cost of an integration that needs work beyond the standard action. Estimate how much time your app owners will spend maintaining these actions, then add that work to the software cost.

Five account-removal tests to run before buying

Use fictional identities and test content only. Capture event time, Torii action log, app account state, session result and exception owner. These are proposed tests; we have not run them in Torii.

Torii Identity trial for a 500-person Entra employer
Test recordEvidence to requestReason to hold
T01 · immediate Entra exitTimestamp HRIS event, Entra block, Torii trigger and receiving app change using the contracted connection.Only a scheduled sync or a green Torii badge is shown.
T02 · shadow appShow where the app came from, who owns it, which account belongs to the test person and the executable removal method.A browser sighting is sold as proof of a removable user account.
T03 · delegated ticketOpen the named ticket system, complete the task and verify the app account independently.Opening a ticket is scored as revoked access.
T04 · role driftGive a mover excess rights; inspect policy evaluation, remediation level, action log and app role after the change.The deviation vanishes only because policy, group or integration changed.
T05 · direct app sessionUse a harmless test session established before termination, then check the app's own invalidation behaviour.The team assumes directory sign-in block destroys an app-issued session.

If Torii finds accounts but cannot remove them, ask for a separate discovery and governance quote. If Entra and changes within the apps pass all five tests, keep that setup.

When should the buyer choose something else?

For a mostly Microsoft-managed estate with limited unmanaged SaaS, test Entra ID Governance first and fill app-side gaps; Torii may add cost without removing any more accounts.

For a Google-centred team buying workflow automation and file governance, put BetterCloud User Automation into the same trial.

If one small IT team owns device assignment and access, compare Josys.

Our seven-route offboarding guide covers the broader shortlist. Buy Torii if the trial shows it can find and remove app accounts that your existing tools miss.

Questions buyers ask

Is Torii Identity an identity provider?

No. Torii describes itself as a governance layer that sits above an existing identity provider such as Entra or Okta. It does not replace the directory or its authentication controls.

Does Torii Done mean the SaaS account was revoked?

Not necessarily. Its documentation says a configured action may complete without terminating access, some delegated tickets can count when opened, and Ignore performs no Torii removal action. Check the account in the app itself.

Does Torii publish a usable 500-person Identity price?

The current top-level pricing page lists IGA, SMP and AI Management product scopes but no amount for this configuration. Ask for an edition-specific quote and billing population in writing.

Can Torii trigger real-time offboarding from Entra?

The reviewed Torii real-time offboarding help names Google Workspace, Okta and BambooHR App Event sources, not Entra. Ask Torii to demonstrate your exact Entra trigger and emergency route rather than inferring its behaviour from that list.

Sources and research scope

Official Torii, Microsoft, BetterCloud and Josys material inspected 2 October 2026. Supplier claims are attributed. The 500-person estate and five identities are fictional decision inputs. No product login, customer interview, quote, performance test, rating or EOR Atlas score is claimed.

  1. Torii Identity productMarketing scope, IdP relationship and broad lifecycle promise.
  2. Torii current pricingSeparate IGA, SMP and AI Management scopes; no usable 500-person price.
  3. Torii subscription managementBasic employee-count licensing; higher-plan terms may differ.
  4. Torii discovery and usageDiscovery sources and user-versus-usage distinction.
  5. Torii offboarding methodsAutomatic, delegated and Ignore meanings; Done badge semantics.
  6. Torii real-time offboardingNamed App Event sources, daily sync and state-trigger timing.
  7. Torii Access GovernancePolicy scopes, remediation levels and reasons a deviation can close.
  8. Torii automatic remediationTask re-evaluation, IdP group assumption and fallback.
  9. Torii actions audit logWhat actions the Torii log records.
  10. Microsoft access revocationExternal app-issued session boundary.
  11. Microsoft Lifecycle WorkflowsIncumbent alternative for directory-owned leaver steps.
  12. BetterCloud product documentationConditional Google-led workflow alternative.
  13. Josys automated offboarding helpConditional app-and-device alternative scope.