banner-image
left hexagon image right hexagon image

The “Zombie” SaaS Audit: Finding the 3 Apps Your Former Employees Still Access 

Most businesses are quick to disable a departing employee’s email account. The laptop gets returned, passwords are reset, and the person is removed from Microsoft Teams or Slack. 

But that is rarely the full picture anymore. 

What often gets missed are the dozens of SaaS applications employees use every day outside the core IT stack. The project management platform they signed up for themselves. The shared cloud storage folder is connected to a personal account – the CRM access from a previous role. 

Months later, those accounts can still be active. 

These are known as “zombie accounts”, dormant but valid logins that remain accessible long after someone has left your business. And in a cloud-first workplace, they represent one of the easiest security gaps to overlook. 

According to the Verizon Data Breach Investigations Report, the human element continues to play a major role in security breaches, particularly where valid credentials are involved. 

For UK businesses relying heavily on cloud platforms and SaaS tools, offboarding can no longer stop at email access and device returns. 

Why Zombie Accounts Happen

Zombie accounts are rarely caused by poor intent or reckless behaviour. More often, they are the result of outdated offboarding processes that were designed for a very different IT environment. 

Years ago, businesses may have relied on a handful of centrally managed systems. Today, the average organisation uses dozens, sometimes hundreds, of SaaS applications across departments. 

Marketing teams sign up for analytics tools. Sales teams onboard CRM platforms. Project managers create Notion workspaces or Asana boards. Employees test AI tools, browser extensions, and automation platforms using their work email address. 

Many of these systems are never formally documented by IT. 

So when someone leaves the business, the obvious accounts are disabled, but the long tail of SaaS access remains untouched. 

The result is a growing collection of forgotten accounts, active sessions, API tokens, guest shares, and permissions that nobody realises still exist. 

What Makes Zombie Accounts Dangerous?

The risk with zombie accounts is simple: the credentials are legitimate. 

There is no suspicious login pattern to trigger alarms. No obvious malware signature. No brute-force attack. 

The account was originally approved and trusted. 

If those credentials are reused, compromised, or intentionally accessed after an employee leaves, the platform itself often sees nothing unusual. The door is already unlocked. 

This becomes particularly risky when former employees still retain access to: 

  • Customer data 
  • Internal documents 
  • Financial information 
  • Company strategy files 
  • Shared cloud storage 
  • AI tools containing business prompts or uploaded data 
  • And because many SaaS applications operate outside the main IT environment, businesses may not even realise the exposure exists until something goes wrong.
     

The Three Places Zombie Access Usually Hides 

Cloud Storage and Collaboration Platforms 

Services like Google Drive, Microsoft OneDrive, Dropbox, and WeTransfer are some of the biggest sources of lingering access. 

Shared folders are often granted quickly during projects and rarely reviewed afterwards. External sharing links may remain active indefinitely, and employees sometimes connect business files to personal accounts for convenience. 

Even when an employee’s Microsoft 365 or Google Workspace account is disabled, the external sharing permissions can remain in place. 

That means someone outside your organisation could still access sensitive company files long after leaving. 

For businesses handling client data or regulated information, this becomes both a security and compliance concern. 

Project Management and CRM Systems 

Platforms like Asana, Monday.com, Jira, Notion, HubSpot, and Salesforce are frequently managed by departments rather than central IT teams. 

That creates a visibility problem. 

An account manager may still have CRM access months after changing roles. A contractor could retain access to project boards containing operational information. A former team member may still receive notifications from systems nobody remembered to review. 

Because these platforms often sit outside the core identity provider, they can easily fall through the cracks during offboarding. 

The SaaS Tools Nobody Knew Existed 

This is often the most overlooked category. 

Employees regularly sign up for tools using their work email address without formal approval. AI writing assistants, survey platforms, automation tools, design software, browser extensions, or reporting dashboards can all become part of daily workflows without ever appearing on an IT asset register. 

When the employee leaves, those accounts stay active because nobody knew they existed in the first place. 

In some cases, the work email tied to the account may even redirect to a shared inbox or IT catch-all address, unintentionally keeping access alive indefinitely. 

 

How to Run a Zombie SaaS Audit 

  1. Build a SaaS Inventory

Start by identifying which SaaS platforms are actually being used across the business. 

If you use Microsoft Entra ID, Google Workspace, or Okta, review connected applications and active integrations first. 

Then expand your visibility by checking: 

  • Billing and subscription records 
  • Browser extension usage 
  • Login notification emails 
  • Expense claims for software purchases 
  • Team-managed platforms outside IT 

This process often uncovers far more applications than expected. 

The goal is not to eliminate every tool immediately. It is to understand where company access exists and who controls it. 

  1. Cross-Reference Former Employees

Take a list of staff departures from the last 12 months and compare those names against your SaaS inventory. 

For each platform, review: 

  • Whether the account is still active 
  • Last login activity 
  • Shared folders or guest permissions 
  • API keys or tokens connected to the account 
  • Multi-factor authentication status 

Any account belonging to someone who has left the business should be treated as a priority review. 

If the access still exists, revoke it immediately and document the action taken. 

  1. Turn the AuditIntoa Repeatable Process

The most effective SaaS audits are not one-off clean-ups. They become part of a repeatable offboarding process. 

That means: 

  • Reviewing SaaS access during every employee exit 
  • Enforcing multi-factor authentication across platforms 
  • Removing shared or generic logins where possible 
  • Running quarterly SaaS access reviews 
  • Giving IT visibility into department-managed tools 

Offboarding today is no longer just an HR task. It is a security control. 

 

Why This Matters More in 2026

Modern businesses no longer operate inside a single network perimeter. 

Your data now lives across dozens of cloud platforms, AI tools, collaboration systems, and browser-based services. Employees work remotely, across devices, and often outside traditional office controls. 

That flexibility brings productivity benefits, but it also creates hidden exposure if access is not properly managed. 

Zombie accounts are one of the clearest examples of how yesterday’s offboarding process no longer matches today’s technology environment. 

Making SaaS Offboarding Part of Your Security Strategy

Zombie accounts cannot be removed if nobody is actively looking for them. 

A structured SaaS audit helps businesses identify where former employee access still exists, close unnecessary permissions, and build a repeatable process for future exits. 

At Sedcom, we help UK businesses improve visibility across cloud platforms, strengthen offboarding processes, and reduce the hidden risks created by unmanaged SaaS access. 

If you want to review your current offboarding process or identify unknown SaaS exposure across your organisation, get in touch with our team for a security review. 

 

Related News & Blogs

Why Human Behaviour Is Still Your Biggest Cybersecurity Risk 

Cybersecurity conversations often focus on sophisticated attacks, advanced malware, and complex technical vulnerabilities. In reality, many breaches begin with something far more…
Read More

Clean Desk 2.0: Why Your Home Office Is Now a Security Risk

In the traditional office, a “clean desk” policy was simple. Lock away sensitive documents, clear down paperwork, and never leave…
Read More

The Legacy Debt Audit

The Risk You’re Avoiding Might Be the One That Causes the Problem In many server rooms, there’s always one system…
Read More