When someone leaves your company, you probably collect their keys, take back the laptop, and shut off their email. Job done, right?
Not quite.
Over the years, most employees pick up access to more systems than anyone tracks. There’s Microsoft 365, your accounting software, your CRM, cloud storage, payroll, vendor portals, remote access tools, and shared mailboxes.
Then there are the accounts nobody remembers: a Canva login someone set up for marketing, a Facebook page a former employee managed, a Dropbox folder shared with a manager years ago, an app someone connected to their Microsoft 365 account and forgot about.
The employee leaves, their email gets disabled, and everyone assumes their access went with it. It often doesn’t.
What is access creep
Access creep happens when employees pick up new permissions as they change roles, but the old ones never get removed.
Someone starts in customer service, moves to sales, and eventually becomes a manager. Each job change adds new access. Rarely does anyone go back and take the old access away.
After five years, that employee may be able to reach far more of your business than their current job requires. When they leave, all of that access leaves the building with them, at least on paper. In reality, it usually stays right where it was.
Offboarding needs to be a process, not a checklist item
Turning off someone’s email is a start, but it only closes one door. What about the cloud app they logged into with a separate password? The vendor site where their account is still active? The shared password they know? The company social media account they had the keys to?
Offboarding works best when it starts before the employee’s last day.
Someone should know which systems they can reach, which devices they hold, which passwords or codes they know, and whether they have access to any shared accounts.
From there, equipment gets returned, individual accounts get disabled, shared passwords get changed, remote access gets pulled, and email forwarding or delegation gets reviewed.
Don’t forget the accounts your IT provider doesn’t manage directly. Your bookkeeper may have logins for banking or payroll.
A salesperson might hold customer portal credentials. Whoever runs your marketing may control social media accounts, your website, ad platforms, or your email marketing tool. Those accounts need the same attention.
The account nobody is watching is the one that gets hacked
Most former employees have no interest in logging back into your systems. That’s not the real risk. The real risk is that their old account is still sitting there, active and unused. If that account gets compromised months or years later, an attacker may find it still opens the door to your business. Nobody notices, because nobody remembers the account exists. That makes forgotten accounts an easy target.
Don’t wait until someone leaves
Access should match the job. When someone’s role changes, their access should change with it.
A periodic review of who can reach what often turns up old accounts, admin permissions nobody needs anymore, forgotten vendor logins, and software nobody uses. You might be surprised by what’s still active.
Ask yourself this: if you made a list today of everyone who can access your company’s systems and data, could you say for certain that everyone on that list still belongs there?
If your honest answer is “I think so,” it’s worth a closer look.
Give us a call for a no-charge, no-obligation review of your user accounts and access, and we’ll help you build a process that covers employees joining, changing roles, and leaving for good.
