The SSO tax, measured: what small teams actually pay to offboard
SSO and SCIM deprovisioning are gated to enterprise tiers, so small teams pay the "SSO tax" in manual labor and unprovable offboarding instead. Here's the honest arithmetic — and the pragmatic way out.
We spent a week last month writing down the "right" way to remove someone's access from 22 SaaS tools. For a depressing number of them, the right way was a tier we couldn't afford.
We were building the offboarding catalog for AccessExit — a per-app list of the exact steps to close someone's access when they leave. The plan was boring and mechanical: for each tool, find the clean, official way to deprovision a user and write it down. For a handful of tools, the clean way is a single toggle. For a lot of them, that toggle lives behind an "Enterprise" tier priced for a company ten times the size of the ones this product is for.
That gap has a name — the SSO tax — and once you've stared at it tool by tool, it stops being an abstract complaint and starts looking like a bill. So we tried to add it up.
The clean path is real. It's just not for you.
To be fair to the vendors: SSO and SCIM are genuinely the right way to do this. When a tool supports SCIM and you've paid for it, removing a departing person is one action in your identity provider — the account is deprovisioned everywhere, with a log to prove it. That's the world identity platforms assume you live in.
Most small teams don't. The community-maintained SSO Wall of Shame (sso.tax) tracks vendors that gate SSO to a tier more than 10% above their standard price, and the list is long and familiar. As we write this, GitHub's SAML SSO sits in its Enterprise tier, and Slack's SCIM API is limited to its Business+ and Enterprise Grid plans — a team on a standard Slack plan cannot SCIM-deprovision at all. (Tiers move, so check the vendor's current pricing before you quote them.)
You're not imagining that this feels backwards. CISA's Secure by Design guidance argues SSO should be a baseline feature, not an upsell — and even 1Password, a vendor themselves, has written about the backlash to the SSO tax. The point isn't that vendors are villains. It's that the pricing pushes the automatable path out of reach for exactly the teams with the least slack to do it by hand.
So what do you actually pay?
There are only two ways to pay the SSO tax: cash or labor.
The cash version is to upgrade every gated tool to the tier that unlocks SSO or SCIM. Nobody does this. The upgrade isn't a per-departure cost you pay once — it's a permanent line item, across dozens of tools, often at a multiple of what you're paying now, bought so you can cleanly remove the occasional leaver. For a 30-person team running 40-plus tools, that math never closes. So you don't pay cash. You pay labor.
The labor version is that offboarding becomes a manual scavenger hunt, every single time. And here the one number we trust most is someone else's: Nudge Security's survey of 375 IT professionals found teams spend roughly five hours per departing employee cleaning up cloud and SaaS access, and that 69% use three or more sources just to find everything a person had access to. That's a survey figure, not a law of nature — but it matches what the catalog work implied. When the clean path is gated, "close their access" quietly means "open fifteen admin panels and hope you remembered all of them."
Here's the honest arithmetic, clearly labeled as an estimate: if a single offboarding eats something in the neighborhood of those five hours, mostly because the long tail is manual, then a team doing even one departure a month is spending a full working week a year just clicking through admin panels to remove people — plus whatever it costs when they miss one.
“That's the tax. It isn't the SSO upgrade price on the invoice — it's the manual work you do instead of paying it.”
The part that actually bites
The hours are annoying but survivable. The cost that bites is quieter: when the path is manual, you usually can't prove you did it.
A SCIM deprovision leaves a log. A person clicking "remove" across fifteen tools leaves, at best, a memory. And retained access after departure is common enough that "I'm pretty sure I got everything" is a genuinely risky sentence — reported prevalence ranges from about 25% to 63% across studies, depending on how you define "retained access" and who's counting. Wide range, secondary-sourced, directional — but even the low end says this slips through more than it should.
The bill for that arrives later, and from an unexpected direction. It's the security questionnaire from a prospect's procurement team. It's the SOC 2 auditor asking for evidence of your last offboarding. It's the cyber-insurance form. At that point the five hours you spent don't count for anything — only the evidence does, and a scavenger hunt doesn't produce evidence.
You can't buy your way out at this size. So change the goal.
The trap is spending energy resenting the tax, or waiting for a budget that lets you automate your way around it. At 5–100 people, that budget isn't coming — and cheaper SSO, even if CISA's pressure eventually delivers it, won't cover the accounts a team lead bought on a personal-ish login that never reached a central list anyway.
That's the bet AccessExit is built on: treat a manual task with captured evidence as a first-class, audit-valid outcome, not a second-class fallback. Though we'll undercut our own pitch — you can get most of the way there with a shared sheet that has a "how we verified" column and the discipline to actually fill it in. The part that's hard to fake yourself is the receipt at the end that refuses to say "all access removed" unless every item is genuinely accounted for. That refusal is the whole reason we're building this instead of telling you to make a better spreadsheet.
If you're doing this by hand
Before your next departure, do the cheap version of what we did with the catalog: list your tools and mark the ones where the clean, automated offboarding path is gated behind a tier you don't pay for. That list is your real offboarding surface — the tools where "remove access" will always be manual, and therefore the tools where you have to decide, now, how you'll prove you did it.
Whether you track that in a sheet or something fancier matters less than deciding it before someone asks. Because the day the questionnaire lands, the hours won't count. Only the evidence will.
If it'd help, we're putting together free, no-signup offboarding checklists for the tools that gate SSO — the same steps the catalog encodes. (Planned, not live yet; we'll link them here when they ship.)