All resources Resources

The leftover logins former employees still have

Someone leaves the company on a Friday. By Monday their email is disabled and their laptop is back on the shelf. Job done, or so it seems.

What nobody checks is the login they created for that project tool back in the third quarter, the cloud folder they shared with a contractor, or the customer database they still have access to from a role they held two jobs ago. Three months later, those logins are still live. We call these leftover accounts, and they form not through carelessness, but because most offboarding checklists were built around the laptop and the email, not the way people actually use software today. The average company now runs more than 100 cloud apps; most offboarding checklists were written when there were three. Here's how we help businesses across the Denver area find and close them.

What a leftover account actually is

A leftover account is an active login belonging to someone who no longer works for you. The name is casual; the risk isn't. What makes these accounts so dangerous is that they're valid credentials, so there's nothing for a security tool to flag. The access was granted on purpose, so the system has no reason to question it. If a former employee decides to walk back in through that door, or if their old password turns up in a breach after they've gone, the access is sitting there waiting.

This isn't a rare edge case. Industry research has found that half of organizations later discovered former employees still able to reach company apps months after their departure, and for most, the discovery was an accident, not the result of a deliberate check.

The three places access never gets removed

Cloud storage and shared folders

Tools like Google Drive, OneDrive, and Dropbox are where leftover access does the most immediate damage, and where offboarding gets messiest. Files may have been shared to a departing person's personal account. Guest access handed out during a project never gets cleaned up. Folders set to "anyone with the link" stay bookmarked. The departure usually triggers a license removal in your main system, but those shared folders, external links, and personal-account shares go completely untouched.

Project and customer tools

Apps like Asana, Monday.com, Notion, Jira, HubSpot, and Salesforce are often set up by a team lead rather than handled centrally, which means the offboarding checklist never even knew they existed. A former salesperson's customer-database login, or a project manager's workspace full of company strategy notes, can quietly persist for months with nobody the wiser.

The tools nobody knew about

This is the most dangerous group. These are the apps people signed up for with their work email and a few clicks: a survey tool, an AI writing assistant, a chart maker. They were never formally set up and never formally shut off. When the person leaves, the account just sits there, tied to a work address that may now forward to a shared inbox. Our piece on finding unsanctioned tools goes deeper on how these accumulate.

Running a leftover-account audit

Step 1: Build a list of the apps you use

Start by pulling every cloud app connected to your main sign-in system: Microsoft, Google Workspace, or whatever you use to manage logins. Cross-reference that with billing records, installed browser extensions, and the login-notification emails that show up regularly. One 2025 report that analyzed 29 million accounts found nearly 24,000 distinct cloud apps in use across its customers (far more than any team tracks by hand) and 90% of them sat outside central management. For a smaller team, a focused 30-minute review of active subscriptions and recent login alerts will surface most of the high-risk ones.

Step 2: Check it against everyone who's left

Take the last 12 months of departures and check each name against that app list. For each app, ask:

  • Does it have an admin console where you can see who's active?
  • Can you tell when each account last logged in?
  • Is anyone on the list someone who no longer works here?

Access that's months old and belongs to someone who has left is a leftover account. Flag it for immediate removal and write down what you found.

Step 3: Revoke, document, and set a rhythm

Remove the access. Record what was found and when. Then use that audit as the starting point for an offboarding checklist that covers more than the email and the laptop. Going forward, turn on multi-factor authentication (that second sign-in step) for every account that stays active, and schedule a cloud-access review every quarter. That cadence turns a one-time cleanup into a control you can rely on.

Make offboarding a security step, not an afterthought

Leftover accounts can't be closed if nobody's looking for them. A cloud-access audit is the place to start, and building it into every employee exit keeps the gap from reopening. If you'd like a hand running that first audit and turning it into a repeatable process your team can follow on every departure, that's exactly the kind of work we do for businesses across the Denver area, in plain English, with no pressure. It pairs naturally with tightening up your new-hire setup on the other end.

Not sure who still has access to your apps?

Book a free IT check-up and we'll run a leftover-account audit and build an offboarding process your team can follow on every exit.

Get started