Former employee access is system or facility access that remains functional after someone has left an organization. It is one of the most common findings in any access review, and one of the few security problems where the cause is almost always administrative rather than technical.
The account was not overlooked because it was hard to find. It was overlooked because nobody was assigned to look, or because the system it belonged to was outside the process that handles departures.
The primary network account is usually disabled promptly. What persists sits outside the central identity system.
Vendor-managed accounts are the largest category. When an employee registered directly with an outside platform using their work email, that account is governed by the vendor. Disabling the mailbox does not necessarily disable the account, and password reset flows sometimes remain functional through recovery addresses the employee controls.
Departmentally provisioned tools adopted by a team without central involvement have no connection to the offboarding process at all.
Shared credentials cannot be revoked by disabling an account, because knowledge of a password does not expire. If a departing employee knew a shared login, the only meaningful response is rotation — which organizations routinely skip because it inconveniences everyone still using it.
Self-service portals often remain open deliberately, so former employees can retrieve pay statements and tax documents. That is a legitimate need, but it frequently leaves accounts with full modification capability rather than read-only access.
Physical access persists through uncollected badges and keys, particularly at secondary sites, and through door codes that are never changed.
Mailbox forwarding and delegated access can keep information flowing to a former employee long after their own account is closed, since the mechanism lives in someone else's mailbox.
Most former employees have no interest in their old accounts. The exposure concentrates in a smaller set of circumstances that are usually identifiable in advance.
Involuntary separations, particularly contentious ones, carry elevated risk. So do departures to a direct competitor, where the value of retained access is obvious. Employees who held administrative or financial access represent higher consequence regardless of circumstances. And any account that survives long enough may be compromised by someone else entirely — a dormant, unmonitored account with valid credentials is an attractive target precisely because nobody is watching it.
That last scenario is worth emphasizing, because it does not depend on the former employee doing anything at all. The account is a liability independent of the person's intentions.
Three structural causes account for most instances. There is no inventory of what access a given role holds, so revocation depends on someone remembering. There is no verification step, so a checklist marked complete is never checked against reality. And there is no periodic reconciliation, so accounts that slipped through are never found.
The absence of reconciliation is the decisive one. Every offboarding process has failures; what distinguishes organizations is whether those failures are discovered in weeks or never.
A periodic comparison of active accounts across every system against the current employee roster is the control that catches what the process missed. Run quarterly, it converts an indefinite exposure into one bounded by a few months.
The exercise usually produces uncomfortable results the first time — accounts belonging to people who left years earlier, service accounts nobody can account for, and administrative access held by former staff. That discomfort is the point. Each finding represents a process failure that would otherwise have remained invisible.
Reconciliation must extend to vendor-managed platforms, which requires knowing which platforms exist. Where a full inventory does not exist, building one is a prerequisite — and is itself worth the effort, since the same list is needed for vendor risk management and for breach response.
That final point prevents a different failure. Deleting an account can destroy business records or data subject to preservation obligations, so preservation should precede revocation rather than follow it.
Employer's Guardian helps employers build separation processes and access reviews that close these gaps through outsourced HR services.
This article provides general educational information, not legal advice. Requirements vary by jurisdiction. Consult qualified counsel regarding record retention and preservation obligations.