Someone leaves the company on a Friday. By Monday, their email account has been disabled and their laptop returned. Everything appears to be wrapped up neatly.

But what about the project management platform they signed up for six months ago? The cloud storage folders they shared with contractors? Or the CRM access they retained from a previous role?

In many organizations, those accounts remain active long after an employee has left.

This is how zombie accounts are created—not through carelessness, but through offboarding processes that haven’t kept pace with the way modern businesses use software.

Today, the average organization uses more than 100 SaaS applications. Most offboarding procedures were designed when businesses relied on only a handful of systems. As software ecosystems grow, so does the risk of forgotten access lingering in the background.

What a Zombie Account Actually Is

A zombie account is an active user account belonging to someone who no longer works for your organization. The name may sound harmless, but the security risks are significant.

What makes zombie accounts particularly dangerous is that they represent legitimate access. Nothing appears suspicious because the permissions were granted intentionally, and the systems continue to recognize those credentials as valid.

If a former employee decides to log in—or if their credentials are compromised after departure—the access is still available and waiting.

Industry research shows that 50% of organizations have discovered former employees still accessing SaaS applications months after leaving the company.

Even more concerning, most of these discoveries happen by accident rather than through a structured security review.

The Three Apps Where Access Never Gets Removed

Cloud Storage and Collaboration Tools

Platforms like Google Drive, OneDrive, and Dropbox often create the greatest risk when offboarding is incomplete.

Files may be shared with a departing employee’s personal email address. Guest permissions granted during a project may never be removed. Shared links with “anyone can access” settings can remain active indefinitely.

While the employee’s primary account may be disabled, the shared folders, external permissions, and personal account access frequently remain untouched.

As a result, sensitive company information can continue to be available long after the employee has left.

Project Management and CRM Platforms

Applications such as Asana, Monday.com, Notion, Jira, HubSpot, and Salesforce are often managed by department leaders rather than IT.

That means these platforms may never appear on the official offboarding checklist.

A former salesperson may still have access to Salesforce records. A previous project manager could retain access to strategic planning documents inside Notion or Jira.

Without centralized visibility, these accounts can remain active for months without anyone realizing it.

The Tools IT Didn’t Know Existed

This category often presents the greatest risk.

Employees regularly sign up for software using their work email addresses. It might be an AI writing assistant, survey platform, analytics tool, design application, or reporting service.

These tools are rarely provisioned through IT, which means they are rarely included in offboarding procedures.

When the employee leaves, the account remains active. In some cases, the associated work email may even redirect to a shared mailbox, leaving those accounts vulnerable and unmanaged.

Running the Zombie SaaS Audit

Step 1: Build Your SaaS Inventory

Start by creating a comprehensive inventory of your SaaS applications.

If you use an identity provider such as Microsoft Entra ID, Google Workspace Admin, or Okta, review all connected applications and user accounts.

Next, compare that information against billing records, browser extension installations, and email notifications from software vendors.

According to Grip Security’s 2025 SaaS Security Risks Report, which analyzed 29 million user accounts, organizations collectively used nearly 24,000 distinct SaaS applications.

Even more surprising, 90% of those applications were operating outside of IT management and oversight.

For smaller businesses without a formal identity platform, a review of active subscriptions and login notifications can uncover many of the highest-risk applications in less than an hour.

Cross-Reference Against Your Offboarding List

Once you have a SaaS inventory, compare it against employees who have left the organization within the past 12 months.

For every application, ask the following questions:

  • Does the application provide an administrative console?
  • Can you identify active users?
  • When was the account last used?

If an account belongs to a former employee and still shows activity or available access, it should be flagged immediately.

Document every finding carefully. This information will help strengthen future offboarding procedures.

Step 3: Revoke, Document, and Set a Review Cadence

Once zombie accounts are identified, revoke access immediately and document the action.

Record what was discovered, which applications were affected, and when the access was removed.

Use the findings from your audit to expand your offboarding checklist beyond laptops and email accounts.

Moving forward, enforce multi-factor authentication (MFA) on all active accounts and schedule quarterly SaaS access reviews.

By reviewing access regularly, you transform a one-time cleanup project into an ongoing security control that protects your organization over the long term.

Don’t Let Former Employees Keep Access

Zombie accounts are one of the most overlooked security risks facing modern businesses. As organizations continue adopting more SaaS applications, traditional offboarding procedures often fail to keep up.

By creating a complete SaaS inventory, reviewing former employee access regularly, and implementing a repeatable audit process, you can eliminate hidden vulnerabilities before they become serious security incidents.

Need help identifying and securing forgotten SaaS accounts? Contact us today to assess your current environment and build a stronger offboarding process that keeps your data protected.

Article used with permission from The Technology Press.