Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Insider threat
Reference · Pattern

Departed employee retains SSO or SaaS access post-departure

Severity HighKind Insider threatEffort to fix ModerateUpdated 29 Sep 2026By LeakTrace
Definition

A former employee's corporate SSO, individual SaaS accounts, or personal-device-linked corporate app access remains active after their departure date.

What it is

Employee departure is a moment where identity hygiene routinely fails. HR closes the employment record; IT disables the primary SSO account; but the long tail of individual SaaS accounts, personal-device-linked apps, and cross-tenant integrations (Slack, project management, marketing platform, code hosting, e-sign) often survives for weeks or months.

Why it matters

A departed employee with retained access is either a direct insider risk (if the departure was contentious) or an inherited outside exposure (if the departed employee's credentials later leak in an unrelated breach and the attacker discovers they still work). Either path leads to a compromise no active-employee monitoring will catch.

How anyone can check it

Compare your list of active sign-ins in email and shared tools against current staff.

Remediation direction

A single offboarding checklist tied to the identity provider that enumerates every SaaS, every shared credential, every OAuth integration, and every personal-device-linked app, completed and signed off on departure day. Quarterly review of the identity provider for accounts that have not been used in 60+ days.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →