
What you can do with Group Hygiene
- Eliminate underutilized groups - identify and act on groups that are no longer needed, reducing your attack surface and simplifying access management.
- Manage inactive group members - identify and adjust access for accounts that have not used their group membership in more than 30 days.
- Review administrator groups - identify groups used for privileged tasks and tighten permissions where continual admin access is no longer justified.
- Remove unnecessary permissions - surface and clean up permissions accumulated through group membership over time.
Use cases
Inactive group account management
Organizations grant access to resources through groups. Over time, some users become inactive due to job changes, project completion, or disengagement - but their group memberships and associated permissions remain. These inactive accounts go largely undetected and create security risk if compromised. Oleria identifies all inactive group accounts based on access activity. Accounts that have been inactive for more than 30 days fall into the inactive category. Removing access to inactive members improves security and supports compliance.Compliance assurance for privileged groups
In regulated environments, organizations grant privileged access through group memberships. When employees change teams or leave, access removal from these groups is often overlooked - creating gaps in audit trails and compliance posture. Oleria monitors access activities of privileged account groups to detect and respond to suspicious or unauthorized access, safeguarding application security and audit integrity.Eliminating unused groups
Organizations accumulate groups over time as teams, projects, and structures change. Many become obsolete but remain in the access management system, creating clutter and security risk. Oleria analyzes group activity and utilization percentages to identify groups without active member accounts. This helps you safely eliminate unused groups, streamline access management, and reduce the potential attack surface.Optimizing groups used for privileged activities
When employees switch teams or leave, their privileged group memberships often go unreviewed. Over time, this leads to more people retaining admin-level access than necessary. Oleria helps identify privileged accounts and their access patterns, so you can assess whether continual privileged access is still justified and act to minimize risk.Utilization chart
The utilization chart shows the percentage of active accounts within each group. An account that has been inactive for more than 30 days is considered inactive.
Removing access to inactive accounts within a group improves security and supports compliance.
Group table
The group table lists all groups matching your current filters.
You can export the group table as a CSV file. When a group is exported, its members are also included in the export.
Group details page
Selecting a group opens the group details page.
Accounts

Groups

Owners


