Employee Offboarding: Why Former Staff Still Access Your SaaS Tools
Most businesses have a hiring checklist. Far fewer have a real offboarding one, and that gap is quietly one of the biggest security risks in modern SaaS-heavy workplaces. This sits alongside other overlooked SaaS risks, like free trial billing traps and vendor shutdowns, that most businesses only think about after something goes wrong. This guide covers how widespread the problem actually is, why it happens even at well-run companies, and the specific steps that close the gap.
How Common Is This Problem, Really?
A survey of 500 US-based IT decision-makers by OneLogin found that 50% of former employees’ accounts remain active for longer than a day after they leave, 48% of organisations admit former employees can still access corporate applications, and 32% said it takes over seven days to fully de-provision a departed employee. Separately, a Wing Security study found 63% of businesses currently have ex-employees who still hold access to corporate data.
The Real Cost of Getting This Wrong
About 1 in 5 data breaches involve a former employee within six months of their departure, according to industry research. This isn’t always malicious: a forgotten account with a weak, reused password becomes an easy target for outside attackers long after the original employee has moved on.
Why the Damage Can Be Deliberate, Not Just Accidental
Over 90% of malicious insider incidents are preceded by an employee’s termination or layoff. In one widely reported case, a departing Yahoo engineer took a job at a competitor and, before leaving, copied 570,000 pages of confidential technical designs and algorithms to benefit his new employer. Not every case is this dramatic, but it illustrates why prompt access revocation matters even when a departure seems amicable.
Why This Keeps Happening: The Root Causes
Access accumulates gradually and informally. A manager grants a tool without notifying IT. A team signs up for a SaaS product using a personal or shared login. A contractor gets project-based access that nobody remembers to review once the project ends. None of this is deliberate negligence; it’s simply what happens when SaaS adoption outpaces access governance.
Shadow IT Makes This Worse
The explosion of easily accessible, low-cost SaaS tools means employees often sign up for software using a company email address without IT’s knowledge at all. When that employee leaves, an account IT never knew existed simply continues running, invisible to any standard offboarding checklist.
What Good Offboarding Actually Looks Like
Effective offboarding starts the moment a departure is confirmed, not on the employee’s last day. Coordinating IT, HR, and the departing employee’s direct manager at that point, rather than after they’ve already left the building, closes most of the timing gap that creates risk.
Building a Complete Access Inventory First
You cannot revoke access to a system you don’t know an employee had. Before offboarding can be reliable, a business needs a documented inventory covering every SaaS tool, shared account, and third-party integration each employee actually uses, not just the obvious ones like email and the primary CRM.
The Same-Day Revocation Checklist
- Disable the employee’s single sign-on (SSO) account first, which cuts off access to every connected application simultaneously
- Change or rotate any shared passwords the employee had access to, since these cannot be tied to an individual account
- Revoke VPN and remote network access separately, as this is sometimes managed outside the main identity system
- Redirect the employee’s email and reassign any active client or project communications
- Audit for shadow IT: check for SaaS tools or premium accounts signed up for using the employee’s corporate email
- Retrieve and wipe company-owned devices, and confirm no company data remains on personal devices
Why Single Sign-On Solves Most of This
Businesses using a centralised SSO provider can disable dozens of connected SaaS accounts with a single action, rather than manually logging into each tool individually. For businesses relying on individual logins per tool, offboarding inevitably takes longer and is far more prone to something being missed.
Handling High-Access Roles Differently
Executives, finance staff, and IT administrators typically hold broader, less documented access than a standard employee, sometimes including passwords or permissions never recorded anywhere else. These roles deserve dedicated extra attention during offboarding rather than the standard checklist alone.
A Formal Exit Agreement Helps
A written exit agreement that explicitly covers data handling, return of company property, and confidentiality obligations creates legal clarity and accountability that an informal, verbal handover does not.
Frequently Asked Questions
How quickly should employee access actually be revoked?
Ideally, on the employee’s final day or immediately upon confirmed termination, since research shows a large share of organisations take a week or longer, a window during which real damage can occur.
Does this only matter for employees who leave on bad terms?
No. Even employees who leave amicably can create risk through forgotten accounts with weak passwords, which become easy targets for outside attackers regardless of the departing employee’s intentions.
Conclusion
Employee offboarding is a SaaS security problem as much as an HR process. Given how many organisations admit former employees retain access for days or weeks, a documented access inventory paired with a same-day revocation checklist closes one of the most overlooked security gaps in most small and mid-sized businesses.