CPS-128 · Impact

When Former Employees Still Have System Access — and the Cost of Incomplete Offboarding

Offboarding is incomplete when payroll ends but accounts, tokens, shared credentials, devices or third-party access remain active.

Mellorca Impact·Security & Operations·4 September 2026

The tolerated pain

Access is often created across SaaS tools, cloud platforms, shared mailboxes, VPNs, devices and vendor portals over months or years. A single HR departure event does not automatically revoke all of it.

Operational consequence

The organisation loses confidence in who can reach sensitive systems and data. Investigations, audits and incident response become slower because account ownership is uncertain.

How it becomes money

The immediate cost may be licence waste, but the larger exposure is conditional: an orphaned account can create investigation, containment, recovery, legal or customer-service costs if it is misused or compromised. Do not invent a generic breach value; measure the systems, privileges and data actually exposed.

Commercial triggerIf the business cannot produce a reliable list of departed users and prove access revocation across critical systems, offboarding is not a completed control.

Resolution

  1. Maintain a current inventory of identity-bearing systems.
  2. Trigger offboarding from an authoritative employment event.
  3. Revoke identity, sessions, tokens and shared-secret access.
  4. Recover or secure business devices.
  5. Transfer ownership of files, workflows and service accounts.
  6. Verify completion and preserve evidence.

Bottom line

Offboarding should end access as deliberately as onboarding creates it. Anything less leaves a control gap that becomes more expensive to reconstruct later.