Reference · LeakTrace Intelligence Team
Departed employee retains SSO or SaaS access post-departure
A former employee's corporate SSO, individual SaaS accounts, or personal-device-linked corporate app access remains active after their departure date.
Pattern summary
- Category
- Insider threat
- Severity
- High
- Prevalence framing
- Common in firms without a formal offboarding checklist tied to the identity provider.
- Remediation effort
- Moderate
- Verticals affected
- All
Employee departure is a moment where identity hygiene routinely fails. HR closes the employment record; IT disables the primary SSO account; but the long tail of individual SaaS accounts, personal-device-linked apps, and cross-tenant integrations (Slack, project management, marketing platform, code hosting, e-sign) often survives for weeks or months.
## Why attackers exploit it
A departed employee with retained access is either a direct insider risk (if the departure was contentious) or an inherited attack surface (if the departed employee's credentials later leak in an unrelated breach and the attacker discovers they still work). Either path leads to a compromise no active-employee monitoring will catch.
## Remediation direction
A single offboarding checklist tied to the identity provider that enumerates every SaaS, every shared credential, every OAuth integration, and every personal-device-linked app — completed and signed off on departure day. Quarterly audit of the identity provider for accounts that have not been used in 60+ days.
Concerned this pattern touches your exposure surface?
LeakTrace runs continuous intelligence on principals, households, and advisor tenants across every observable public exposure surface. Discovery call under mutual NDA, first-touch reply within one business day from an authenticated LeakTrace address.
See services and pricing