Skip to content
Calcrivo

Identity Lifecycle Calculator

Score identity lifecycle hygiene from deprovisioning delay, orphan accounts and dormant identities across your estate.

Inputs

people
people
people
days
accounts
accounts

Lifecycle Hygiene Score

84/ 100

Rating

B — Good

Orphan Identities Live Right Now

36

Orphan Application Accounts

504

Exposure per Year

12,960account-days

Orphan Rate

0.26%

Dormant Account Rate

3.04%

Step by step

  1. Values used

    Employees = 12,000 people; Contractors and third parties = 1,800 people; Leavers per month = 180 people; Average delay from exit to disable = 6 days; Application accounts per identity = 14 accounts; Accounts unused past the dormancy threshold = 420 accounts

  2. Identity Lifecycle

    orphan identities live at any moment = leavers per day × average deprovisioning delay, and each drags its application accounts with it.

  3. Annual exposure

    exposure = leavers per year × delay, expressed in account-days of unowned live access.

  4. Lifecycle Hygiene Score

    = 84 / 100

  5. Rating

    = B — Good

  6. Orphan Identities Live Right Now

    = 36

  7. Orphan Application Accounts

    = 504

  8. Exposure per Year

    = 12,960 account-days

  9. Orphan Rate

    = 0.26

How it works

Deprovisioning delay converts a leaver rate into a standing population of orphan accounts, in the same way arrival rate times service time gives queue length. The score penalises that population, the dormant tail and the delay itself, because a long delay is a risk even in a month with few leavers. Orphan and dormant accounts are the credentials nobody will notice being used — no owner to report a phish, no manager to spot the login, and frequently no MFA either.

Formulas

Identity Lifecycle

orphan identities live at any moment = leavers per day × average deprovisioning delay, and each drags its application accounts with it.

leavers per day
Monthly leavers ÷ 30
deprovisioning delay
Days between the last working day and the account actually being disabled
orphan account
A live account with no active owner

Annual exposure

exposure = leavers per year × delay, expressed in account-days of unowned live access.

account-days
One live orphan account for one day — the unit auditors and attackers both care about

Frequently Asked Questions

How is Identity Lifecycle calculated?

orphan identities live at any moment = leavers per day × average deprovisioning delay, and each drags its application accounts with it. Deprovisioning delay converts a leaver rate into a standing population of orphan accounts, in the same way arrival rate times service time gives queue length. The score penalises that population, the dormant tail and the delay itself, because a long delay is a risk even in a month with few leavers.

Why does Identity Lifecycle matter?

Orphan and dormant accounts are the credentials nobody will notice being used — no owner to report a phish, no manager to spot the login, and frequently no MFA either.

What values do I need to enter?

This calculator takes 6 inputs: Employees, Contractors and third parties, Leavers per month, Average delay from exit to disable, Application accounts per identity, Accounts unused past the dormancy threshold. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

What is a realistic deprovisioning target?

Same-day disable for employees and within the hour for involuntary terminations, driven by HR being the authoritative source rather than by a ticket. Contractors need an explicit end date on the account at creation, since nobody files a leaver ticket for a contract that simply lapses.

How is a dormant account different from an orphan?

An orphan has no valid owner at all; a dormant account has an owner who has stopped using it. Both are unmonitored attack surface, but dormancy is also a signal for right-sizing — an account unused for 90 days usually indicates access that was never needed.

You might also need