The Leaver Who Still Had Access Three Weeks Later

Someone left a company I support. Laptop handed back, farewell drinks done, name off the org chart.

Three weeks later, their account was still active. Email working. Client folders still syncing to a personal machine. Their login still sitting in a password manager nobody had audited.

Nobody did this on purpose. There was simply no process. “IT offboarding” meant collecting the hardware, and everything else lived in someone’s head.

This is normal in companies of twenty to fifty people. It is not negligence. It is what happens when IT belongs to whoever is least busy that week.

Why growing teams end up here

A company of eight people does not need an IT process. Everyone knows everyone, accounts get created by whoever has admin rights, and nothing goes badly wrong.

Then the team doubles. New tools arrive. Freelancers come and go. Clients start asking security questions in their contracts. The informal system that worked at eight people is still running at forty, except now nobody can see the whole picture.

The signals are usually easy to spot. Nobody can produce a list of who has access to what. Accounts are created ad hoc, so they are removed ad hoc too. Shared logins exist for tools that cost too much per seat. Offboarding is a message in a chat channel rather than a checklist.

None of these cause an incident on their own. Together, they are how a former employee keeps access to client data for three weeks.

What the risk actually looks like

For an agency, the exposure is client trust. Access to shared drives means access to client campaign material, contracts, and sometimes their social accounts. A leaver does not need bad intentions for this to become a problem. A lost laptop or a reused password is enough.

For a company selling to larger clients, the exposure is commercial. Security questionnaires and audits ask directly how access is granted and removed. An honest answer of “informally” slows deals down or loses them.

And there is a cost that never appears on any risk register. Every hour spent working out who has access to what is an hour not spent on client work.

The fix is smaller than people expect

This is not a project. It is a checklist and one conversation with whoever handles HR.

Start with an access inventory. List every system in use and who can get into it. Most companies find tools nobody remembered paying for.

Then agree a single trigger. The day a contract ends is the day access ends. That trigger has to come from HR, not from a manager remembering to send a message.

Then write the offboarding checklist itself. Identity provider account disabled first, because that usually cascades. Email converted or delegated rather than deleted. Device wiped or reassigned. Shared credentials rotated, since those do not disappear when an account does. Any tool outside single sign-on handled by name.

Finally, make it repeatable. The same checklist runs every time, and someone signs it off. A record of who left and what was revoked is exactly what an auditor asks for later.

Wiring this properly takes an afternoon in most small companies. Keeping it working takes almost nothing, because the process runs off a date that HR already tracks.

The uncomfortable question

Ask yourself who owns this at your company right now. Not who would fix it if it broke, but who owns it as part of their job.

If the answer is a name, you are fine. If the answer is a pause, that pause is the actual finding.

Most companies at this stage do not need a full time IT hire. They need someone who owns identity, access, and device management for a few hours a month, and who leaves behind processes the team can run without him.

That is the work I do. If the pause above sounded familiar, I am happy to talk it through, with no expectation attached.

zlefterov.com
itops.zlefterov.com

Leave a Comment

Your email address will not be published. Required fields are marked *