The problem
Inactive accounts are a quiet liability. Departed contractors, abandoned test users, and forgotten service logins keep their access until someone goes looking, which usually only happens during an audit.
What AscendCore does
On demand from Slack or Teams, AscendCore scans the active accounts in Okta and posts a single review card listing the longest-inactive ones, those whose last sign-in is past your threshold, capped per review. One approval suspends the reviewed set. Every account is re-verified at execution: an account that signed in after the card was posted is refused rather than suspended, and suspension is reversible from the Okta console. Accounts with no recorded sign-in are counted on the card but never proposed, because missing sign-in data is not evidence of dormancy. The decision and per-account outcomes land in the audit chain.
Status
Live in production. Runs against a real Okta tenant today from Slack and Teams; it scans active accounts, posts the longest-inactive set past your threshold on one review card, and on approval suspends the reviewed accounts, re-verifying each at execution so an account that signed in after the card was posted is refused rather than suspended (and suspension stays reversible from the Okta console). The decision and per-account outcomes land in the audit chain. The inactivity threshold is configurable per review (30 to 365 days, default 90).
