Why Old Employees Should Never Keep Access

Why Old Employees Should Never Keep Access

Ethical & Authorized Use Only. This content is provided strictly for educational and defensive security purposes. Only test systems that you own or have explicit written permission to assess. Unauthorized access is illegal. See our Terms & Disclaimer for details.

Introduction

Six months after Priya left her job at a mid-sized logistics company, she got an email notification on her phone. It was an automated Slack digest from her old workplace.

She hadn't logged in on purpose. Nobody had. Her account had simply never been switched off. Her email forwarding was still active, her VPN credentials still worked, and she still had read access to a shared drive containing vendor contracts and pricing sheets.

Nothing malicious happened. Priya wasn't the type to snoop, and she deleted the notification without a second thought. But that's not the point. The point is that for six months, a former employee held the keys to systems she had no business touching and nobody in HR or IT even knew.

This kind of story is far more common than most business owners want to admit. It rarely makes headlines because, most of the time, nothing goes wrong. The former employee doesn't log in. The dormant account just sits there, quietly, like an unlocked back door in a building nobody checks anymore.

But "usually fine" is not a security strategy. Every unlocked door is an opportunity, and it only takes one person with the wrong intentions or one attacker who discovers the account first to turn a forgotten login into a full-blown breach.

The uncomfortable truth is that employee offboarding is one of the most underfunded, under-processized corners of cybersecurity. Companies pour money into firewalls, endpoint protection, and security awareness training, then let departing employees keep access to core systems for weeks or months because nobody owns the process end to end.

This article breaks down exactly why old employees keep access longer than they should, what that actually puts at risk, and how to build an offboarding process that closes the gap for good.

 

What Happens When Former Employees Keep Access?

When someone leaves a company, their digital footprint doesn't disappear with their badge. It lives on across dozens of systems, and if offboarding isn't thorough, that footprint stays active.

Here's where lingering access typically hides:

  • Email accounts – Former employees can still receive sensitive internal communications, password reset links, or client correspondence if their inbox stays live.
  • Microsoft 365 / Google Workspace – These are often the biggest blind spots, since they connect to calendars, shared drives, Teams or Chat, and dozens of connected apps through single sign-on.
  • VPN access – A still-valid VPN credential means someone can quietly connect to the internal network from anywhere in the world.
  • CRM systems – Sales and customer relationship platforms often hold contact details, deal history, and pricing — valuable to competitors and easy to export.
  • Cloud storage – Google Drive, Dropbox, SharePoint, or similar tools may still be accessible, exposing contracts, financial records, or product roadmaps.
  • Internal documentation – Wikis, Notion pages, and Confluence spaces often contain sensitive internal processes and credentials that were never meant to outlive an employee's tenure.
  • Git repositories – Developers who retain repo access can view, and in some cases modify, proprietary source code long after their last commit.
  • Finance systems – Accounting software, payroll platforms, and expense tools are high-value targets if access isn't revoked immediately.
  • HR software – Ironically, HR platforms themselves are often overlooked, potentially exposing other employees' personal data.
  • Customer databases – Perhaps the most damaging of all, since exposure here can trigger real compliance and legal consequences.

Multiply this across every SaaS tool a modern business uses and most companies now run 50, 100, sometimes 200+ apps and it becomes clear how easily a former employee's access can slip through the cracks.

 

Why This Happens

Nobody sets out to leave a former employee with system access. It happens because of process gaps, not bad intentions. A few patterns show up again and again.

Poor Communication Between HR and IT

In many companies, HR handles the "people" side of an exit final paycheck, exit interview, benefits paperwork while IT handles the "systems" side. If these two departments don't talk to each other on a fixed schedule, there's often a lag between someone's last day and the moment their accounts are actually shut down.

Manual Offboarding

If disabling accounts means someone manually clicking through a dozen different admin panels, mistakes are inevitable. One missed platform, one skipped checkbox, and access lingers.

Forgotten SaaS Accounts

Modern teams sign up for new tools constantly, often without formal IT approval. A marketing coordinator might have admin rights to a scheduling tool or design platform that IT doesn't even know exists which means it's never included in the offboarding checklist.

Shared Credentials

Some teams still share logins for convenience a shared social media account, a shared analytics dashboard. When one person on that shared account leaves, the password often doesn't change because nobody wants to coordinate resetting it for everyone else.

Lack of Inventory

You can't revoke access to something you don't know exists. Many companies have no centralized list of who has access to what, which makes complete offboarding nearly impossible to verify.

Weak Identity Management

Without a proper identity and access management system tying every account back to a single employee identity, IT teams are left guessing which of the dozens of tools in use actually need attention when someone exits.


Real Business Risks

It's tempting to treat this as a minor administrative oversight. It isn't. Here's what's actually at stake.

Data Theft

A disgruntled former employee with lingering access can copy client lists, source code, or financial data before anyone notices. This isn't hypothetical it's one of the most common insider threats organizations face, and it's entirely preventable through timely deprovisioning.

Accidental Data Exposure

Not every incident is intentional. A former employee might still have a saved login on a personal device, which could be compromised through malware or a lost laptop, exposing company systems through no fault of their own.

Insider Threats

The risk isn't limited to people who leave on bad terms. Even employees who part ways amicably remain a risk simply because their access was never designed to be permanent and permanence is exactly what happens when nobody revokes it.

Compliance Violations

Regulatory frameworks across industries require organizations to control who has access to sensitive data. Failing to promptly deprovision former employees can put businesses out of step with these obligations.

GDPR Implications

Under GDPR and similar data protection laws, organizations are expected to apply appropriate technical and organizational measures to protect personal data  and that includes controlling access. A former employee retaining access to customer or employee personal data can represent exactly the kind of gap regulators look for during an investigation. (Businesses should verify current GDPR guidance directly through official regulatory sources, as requirements and enforcement approaches are updated over time.)

Financial Losses

Beyond regulatory fines, breaches tied to lingering access can trigger incident response costs, legal fees, and lost business. Rather than citing a specific figure, it's worth simply verifying current breach-cost research (such as reports published by IBM or Verizon) if you need numbers for an internal business case.

Reputational Damage

Clients and partners expect their data to be handled responsibly. A breach traced back to "we forgot to remove an old employee's access" is a difficult story to explain  and an even harder one to walk back publicly.

Customer Trust Issues

Once trust is broken, it's rarely fully restored. Even a minor incident can cause long-term hesitation among customers and prospects who now wonder what else might have been overlooked.


A Realistic Example

Consider a fictional but entirely plausible scenario.

A mid-sized marketing agency, let's call it Northfield Creative, lets go of a senior account manager named Daniel after a rocky final quarter. HR processes his termination paperwork the same day. IT is notified but only through a general email that gets buried under dozens of other messages.

Three weeks pass. Daniel's email account is eventually disabled, but nobody thinks to check his access to the agency's CRM, which he used daily to manage client relationships. His login still works.

Two months later, Daniel joins a competing agency. Curious and perhaps a little bitter he logs into the old CRM one evening. He browses through client contact details, contract values, and renewal dates. He doesn't do anything overtly illegal. But armed with that information, his new employer starts approaching Northfield's clients with suspiciously well-timed pitches, undercutting pricing right before renewal dates.

Northfield eventually notices the pattern of client churn but has no way to prove where the leak came from. Their CRM's audit log shows Daniel's login activity weeks after his termination date, but by then the damage lost clients, lost revenue, a shaken sense of trust with the sales team is already done.

How this could have been prevented:

  • A same-day, cross-checked offboarding process covering every system Daniel had access to, not just email
  • A centralized access inventory so IT knew the CRM was in scope
  • Immediate password rotation and session termination, not just account "disabling"
  • Routine audit log reviews that would have flagged the anomalous login the moment it happened

 

Best Practices for Secure Employee Offboarding

A strong offboarding process treats access removal as a coordinated, checklist-driven event — not an afterthought.

  • Immediate account deactivation — Disable core accounts (email, SSO, VPN) on the employee's actual last day, ideally the moment their final meeting ends.
  • MFA removal — Revoke multi-factor authentication devices and backup codes tied to the departing employee.
  • Password rotation — Reset shared or service account passwords the employee had access to.
  • VPN revocation — Remove VPN certificates and credentials so remote network access is cut immediately.
  • Cloud account review — Check Microsoft 365, Google Workspace, and any connected third-party apps for lingering sessions or tokens.
  • API token revocation — Rotate or delete API keys and personal access tokens issued under the employee's identity.
  • SSH key removal — Strip any SSH keys tied to the employee from servers and Git platforms.
  • Badge deactivation — Disable physical access badges alongside digital ones; physical and digital security should move in lockstep.
  • Device collection — Retrieve company laptops, phones, and hardware tokens, and confirm local data has been wiped or secured.
  • Email forwarding policy — Decide in advance whether departing employees' emails will be auto-forwarded to a manager (with clear limits) rather than left open indefinitely.
  • Audit logging — Keep a record of when access was removed, by whom, and confirm no login activity occurs afterward.
  • Backup ownership transfer — Reassign ownership of shared files, calendars, and automated workflows before the account is deleted.
  • Documentation — Log every step of the offboarding process for accountability and future compliance reviews.
  • Final security checklist — Use a standardized checklist for every departure, regardless of role or seniority, so nothing depends on memory

The Importance of HR and IT Collaboration

Offboarding often fails because it's treated as two separate, disconnected processes: HR handles the "people" side, IT handles the "systems" side, and the handoff between them is informal.

The fix isn't complicated  it just requires structure. HR should notify IT the moment a termination date is confirmed, not after the fact. IT should maintain a real-time list of every system tied to an employee's identity so nothing is missed. And both departments should treat offboarding as a shared responsibility with a shared checklist, not a relay race where the baton sometimes gets dropped.

This is where HR and IT collaboration becomes a genuine security control, not just a nice-to-have. When both teams work from the same process, with the same visibility, the gap between "employee leaves" and "access removed" shrinks from weeks to minutes.

 

Employee Offboarding Checklist

A practical, at-a-glance checklist your team can adapt:

  • Confirm termination date and time with HR
  • Disable email and SSO account
  • Revoke VPN and remote access credentials
  • Remove MFA devices and backup codes
  • Rotate shared or service account passwords
  • Review and revoke CRM access
  • Review and revoke cloud storage access
  • Revoke Git and code repository access
  • Revoke API keys and personal access tokens
  • Remove SSH keys from servers
  • Disable finance and payroll system access
  • Disable HR software access
  • Deactivate physical access badges
  • Collect company devices and hardware tokens
  • Set up email forwarding policy (if applicable)
  • Transfer ownership of shared files and workflows
  • Confirm no active sessions remain
  • Document completion and sign off

Common Mistakes Companies Make

Even well-intentioned organizations tend to fall into the same traps:

  • Treating "disabled" as "deleted." A disabled account can sometimes still be reactivated or may retain active sessions if not fully terminated.
  • Only removing email access. Email is the most visible account, so it's often the only one addressed  while CRM, cloud storage, and other systems are left untouched.
  • No process for contractors and freelancers. Temporary workers often get access without the same offboarding rigor applied to full-time staff.
  • Assuming small businesses aren't targets. Smaller organizations often have fewer safeguards, making forgotten accounts an easier target, not a lower risk.
  • No periodic access audits. Even a well-run offboarding process can miss something. Without regular reviews, those gaps go undetected indefinitely.
  • Relying entirely on memory. If offboarding depends on a manager or IT admin "remembering" every system, it will eventually fail.

Building a Security-First Offboarding Culture

Fixing this issue isn't about one heroic effort  it's about building habits and systems that make forgetting nearly impossible.

Start with least privilege as a default principle: employees should only have access to what their role actually requires, which naturally shrinks the offboarding surface area when they leave.

Layer in zero trust security principles, where access isn't assumed based on network location or a single login, but continuously verified. This limits the damage even if an old credential somehow remains active.

Automate what you can. Identity and access management platforms can tie account provisioning and deprovisioning directly to HR systems, so when someone's employment status changes, access changes with it  automatically, not manually.

Finally, run regular audits. Quarterly (or even monthly, for larger organizations) reviews of active accounts against current employee rosters catch the accounts that slip through even a solid process.

None of this requires a massive security budget. It requires consistency, ownership, and a habit of treating account deprovisioning as seriously as account creation.

Frequently Asked Questions

How quickly should access be removed after an employee leaves? Ideally, core access (email, SSO, VPN) should be disabled on the employee's last day, timed to coincide with their final meeting or exit conversation.

Should email accounts be deleted immediately? Not necessarily deleted, but they should be disabled immediately. Many organizations retain the account temporarily for business continuity (forwarding important client emails) before archiving or deleting it according to their data retention policy.

What about contractors and freelancers? Contractors should follow the same offboarding rigor as employees. In many cases, their access should be even more tightly scoped from the start, given typically shorter engagements.

What is account deprovisioning? Account deprovisioning is the process of removing a user's access rights and, where appropriate, deleting or archiving their accounts across all business systems once they no longer need access.

Is disabling an account enough, or should it be deleted? Disabling stops active login, which is the urgent first step. Whether to later delete or archive the account depends on your data retention and compliance requirements.

How often should inactive accounts be audited? Many organizations aim for quarterly audits at minimum, with more frequent reviews for privileged or high-risk accounts.

What are privileged accounts, and why do they need special attention? Privileged accounts have elevated permissions, such as admin rights to servers, databases, or financial systems. Because of their broader access, they pose a greater risk if left active after an employee departs.

Does this only matter for large enterprises? No. Small and mid-sized businesses are often more exposed, since they typically have fewer dedicated IT resources and less formal offboarding structure.

Who should own the offboarding process, HR or IT? Both. HR initiates and confirms the departure; IT executes the technical deprovisioning. The process works best when it's a shared, documented workflow rather than the sole responsibility of one department.

What's the difference between offboarding and access review? Offboarding is triggered by a specific event (an employee leaving). Access review is an ongoing practice of periodically checking that current access levels still match current roles and employment status  it catches what offboarding might miss.


Conclusion

Priya's story, and Daniel's, aren't outliers. They're what happens by default when offboarding isn't treated as a formal, coordinated security process. Most former employees will never misuse the access they're left with  but "most" isn't a standard any responsible business should be comfortable building its security around.

The good news is that this is one of the more fixable problems in cybersecurity. It doesn't require new technology in most cases  it requires a documented process, clear ownership between HR and IT, and the discipline to run it every single time someone leaves, regardless of role or circumstances.

Take a moment this week to ask a simple question inside your own organization: if someone left tomorrow, do you know exactly what it would take to remove every trace of their access  and how long it would actually take?

If the answer isn't immediate, that's your sign. Audit your employee access management process today, before a forgotten account becomes tomorrow's headline.

Written by The StreetKnowledgeWisdom Team

StreetKnowledgeWisdom is an independent cybersecurity education project run by practitioners who write about ethical hacking, defensive best practices, and open-source security tooling. Everything we publish is intended for lawful, authorized, and educational use. Learn more about us or get in touch.