# Account expansion for identity management software

> Identify a justified next use of identity management software after the account has demonstrated value in its current scope. A practical procedure with a worked scenario, category-specific checks and an editable worksheet.

Source: https://saas-marketing.net/industries/identity-management/account-expansion/
Topic: SaaS Customer Marketing
Type: field-guide
Published: 2026-09-17
Last updated: 2026-09-17
Publisher: SaaS Marketing (saas-marketing.net)
License: CC BY 4.0. Quote or republish with attribution and a link to https://saas-marketing.net/industries/identity-management/account-expansion/

## Short answer

Before proposing expansion, verify whether authorized access changes follow approved identity lifecycle rules. An account that has not established the initial routine may need implementation support rather than a larger contract.

## Key takeaways

- Start with achieved value, not an unused feature.
- Look for an adjacent workflow with a real owner.
- Check the value metric and commercial effect.
- Expansion should wait when an integration badge does not prove every permission or deprovisioning path works has not been resolved in the original implementation.

---

This field guide uses an IT team with an authoritative identity source as its working context. The buying conversation involves the IT identity lead, while the IT administrator needs to grant and revoke access consistently across applications. Adapt the scope when those roles, dependencies or operating conditions differ.

## Start with achieved value, not an unused feature

Before proposing expansion, verify whether authorized access changes follow approved identity lifecycle rules. An account that has not established the initial routine may need implementation support rather than a larger contract. Ask the IT administrator which work is going well and which remaining task is worth addressing. The IT identity lead should be able to connect a proposed increase in scope with a customer-owned objective rather than a vendor's quarterly target.

## Look for an adjacent workflow with a real owner

An expansion opportunity can involve another team, a broader operating unit or a related capability. Identify the new owner and the specific work they need to perform. Do not assume that success in one department transfers automatically to another. Access to HRIS, directory and SaaS applications, approval requirements and user expectations may differ. Record those differences before reusing the first implementation plan.

## Check the value metric and commercial effect

If the commercial model uses managed user, show how the proposed expansion changes quantity, capability and expected cost. Explain thresholds, required packages and any additional implementation effort. A customer should be able to forecast the effect before agreeing to the change. Separate adoption of an already-purchased feature from a commercial upgrade so the team does not confuse product engagement with expansion revenue.

## Use a bounded second proof exercise

Adapt a joiner, mover and leaver test with break-glass recovery to the new team or scope. Keep the original acceptance method where it remains valid, but add the requirements that changed. A reference from the first team can create confidence, yet it does not replace the second team's own evaluation. The concern "A failed rollout could lock users out of business systems" may return in a different form when more people or systems are involved.

## Coordinate outreach with the account relationship

Check support issues, renewal timing and the customer's current priorities before launching an expansion sequence. The person receiving the message should understand why it is relevant to their role. Avoid several teams approaching the same account with conflicting offers. A useful expansion brief records the existing outcome, the proposed new outcome, the stakeholders and the dependency that could stop the plan.

## Report expansion with its costs and boundaries

Track added recurring revenue separately from new-logo revenue, and record concessions or services required to obtain it. Review whether the expanded scope remains adopted after the initial agreement. An upgrade that is later reversed may reveal a weak value case. Feed that result back into the qualification criteria so the program favors durable customer value over short-lived contract movement.

## Category-specific review

Provisioning, role changes and removal can behave differently across connected applications. A directory integration may not cover every permission or session behavior. Ask which system is authoritative and what recovery path exists if a rollout affects access unexpectedly.

Use synthetic joiner, mover and leaver cases with a supported application. Verify the resulting access rather than only the provisioning log. Keep a clearly approved recovery route and do not treat an integration logo as evidence that every access scenario is handled.

## Worked situation

An account has established the initial workflow and wants to add a second team. The commercial model uses managed user, but the second team also needs access to HRIS, directory and SaaS applications. Before proposing a larger contract, identify the new owner and repeat the relevant acceptance exercise. If the second team's requirement is outside verified scope, the original success does not justify an expansion promise. Keep a record of the additional work and the expected outcome so the account can later judge whether the broader deployment was useful.

## Working worksheet

| Working item | Category-specific starting point | Question to resolve |
| --- | --- | --- |
| Current value | authorized access changes follow approved identity lifecycle rules | Has the initial scope succeeded? |
| New owner | IT identity lead | Who approves the additional work? |
| Commercial unit | managed user | What changes on the invoice? |
| Second proof | a joiner, mover and leaver test with break-glass recovery | What is different in the new scope? |
| Dependency | HRIS, directory and SaaS applications | Which access or integration must change? |

Add your evidence, owner and next action to each row. Read the [worksheet instructions](/resources/#using-worksheets) before completing the file.

## Run the review with the people who do the work

Bring the IT administrator into the review of a joiner, mover and leaver test with break-glass recovery. Ask them to identify the input they would actually have, the exception they expect to encounter and the person who receives the output. Then ask the IT identity lead which unresolved issue could change the decision. Keep the two answers separate until the team understands whether the obstacle is workflow fit, implementation readiness or commercial priority.

Record any dependency on HRIS, directory and SaaS applications beside the affected worksheet row. A dependency should have an owner and an observable completion condition. If it changes the scope of the offer, revise the public description before the next campaign. This prevents a useful planning exercise from turning into a promise the delivery team cannot meet.

## When to change the plan

Expansion should wait when an integration badge does not prove every permission or deprovisioning path works has not been resolved in the original implementation.  If new evidence changes the audience, required workflow or acceptance conditions, update the brief and explain why. Compare later results against the version of the plan that was actually used.

## Continue with the next decision

Use the [partner marketing guide](/industries/identity-management/partner-marketing/) when that is the next unresolved task, or return to the [identity management software marketing overview](/industries/identity-management/) to choose a different route. The [saas customer marketing hub](/saas-customer-marketing/) provides the broader method.

## Reference and scope

The [primary category reference](https://developer.okta.com/docs/) is a starting point for checking product terminology and current capabilities. This page provides an original planning framework. It does not imply a vendor endorsement, firsthand product test, original market survey or guaranteed commercial result.

## Frequently asked questions

### Where should account expansion for identity management software start?

Identify a justified next use of identity management software after the account has demonstrated value in its current scope. Confirm the customer situation and the evidence needed for the next decision before selecting a channel, format or tool.

### What category-specific concern should the team investigate?

The concern "A failed rollout could lock users out of business systems" needs an observable test or a clear limitation. Also account for the dependency on HRIS, directory and SaaS applications; do not assume it is already resolved.

### What does the worksheet include?

It contains the working items and category-specific starting points shown on this page. Add your own evidence, owner, status and next review decision. The examples are constructed, not reported results or industry benchmarks.

### How does this connect to customer value?

The customer needs to grant and revoke access consistently across applications. A meaningful first checkpoint is to provision a test user and verify access removal across a supported app; the ongoing condition is that authorized access changes follow approved identity lifecycle rules. Choose the stage appropriate to this piece of work rather than combining all three into one metric.
