Back to the blog
SaaSSecurityProcesses

Former employees with access: the silent leak

August 22, 2026·6 min read·Diego Horvatti

Grab your phone and answer fast: how many people who no longer work with you can still get into the company Google Drive today? If you paused for two seconds, you already know the answer. A former employee with access to your systems is the kind of risk that makes no noise, triggers no alert, shows up in no report. It only shows up on the day it is already too late.

In August 2026 Apple went to court to say more former employees may have taken confidential material to OpenAI. Apple. The company with one of the most paranoid security teams on the planet, badge readers, compartmented buildings, people who cannot discuss their own project with the colleague at the next desk. If it happens there, your ten person office with thirty SaaS accounts is not immune. It is just less watched.

It is not about theft, it is about the door left open

Everyone pictures a leak like a movie: someone copying files to a thumb drive at three in the morning. In practice it is far more boring than that.

It is the salesperson who exported the client list to a personal Google Sheet back in March, because it was faster to work that way. Left in July. The spreadsheet is still there, in their account, with your 4,000 contacts and the average ticket for each one.

It is the freelance designer who is still a Figma admin. It is the intern still in the finance WhatsApp group. It is the email marketing account nobody disabled because nobody remembers who created it.

None of these people are villains. Most do not even remember they have that access. But the data is outside your control, and "outside your control" is the literal definition of a leak, intent or not.

Data that walks out does not come back. You cannot delete what already sits in someone else's cloud.

The real problem: you do not know how many accounts exist

Here is the uncomfortable part. Before you revoke access, you need to know where access exists. And almost no small company knows.

Try this. Pull the company card statement for the last 12 months and flag every charge in dollars with a strange name. Notion, Slack, Canva, Trello, Figma, Mailchimp, Calendly, some AI tool, a link shortener, that contract signing app. I did this with a client who swore they had "about 6 tools". We counted 31.

Thirty one doors. Each with its own user list, its own permissions panel, its own remove button hidden somewhere different. That is why offboarding is never complete: nobody has the list.

And there is a modern twist. Many tools today connect to others through "Sign in with Google". When you disable someone's Google account, some of those connections die with it, others do not. The ones with their own password stay alive, indifferent to the fact that the person handed back the badge.

What to do on the Friday someone leaves

You do not need expensive software or a consultant. You need a list and thirty minutes. Do it in this order:

  • Email first. Suspend the Google Workspace or Microsoft 365 account before anything else. It is the master key: almost every "forgot my password" on other tools runs through it. Suspend, do not delete, you will still want the files.
  • Then whatever holds money. Bank, payment gateway, ad accounts, invoicing. The damage here is immediate and measurable.
  • Then whatever holds clients. CRM, sales spreadsheets, email tools, WhatsApp Business. Your client base is worth more than you think, and it is the easiest thing to walk away with.
  • Then everything else. Design, project management, documentation, code repositories.
  • Last, the shared passwords. That single Canva login eight people use. Change it. If the person knew the password, they still know it.

One thing almost nobody does that changes the game: before suspending, transfer ownership of the Drive files to someone else. If you only suspend, the documents land in limbo and recovering them later is an absurd amount of work. Five minutes there saves an entire afternoon.

"But I trust my team"

Great, keep trusting them. The checklist is not about suspicion, it is about what happens when memory fails.

Think of it this way: you trust your accountant, and you still keep the receipts. You trust your team, and you still have signed contracts. Revoking access belongs to the same family. It is hygiene, not accusation.

And there is the side that protects the person themselves. If company data leaks and the former employee still had an active login, they become an automatic suspect, even having done nothing. Closing the door on the way out protects both sides.

A practical detail: make access revocation part of the offboarding process, right next to returning the laptop. Nobody returns a laptop "whenever they remember". They return it that day. Access should work the same way.

Where automation fits without becoming a six month project

You do not need an identity governance platform. You need two simple things.

The first is a living inventory. A spreadsheet is enough, honestly. Columns: tool, what it does, who pays, who is admin, who has access. Update it when you hire someone and when someone leaves. I have seen that spreadsheet save $250 a month in subscriptions nobody used anymore, which almost always pays for the effort of building it.

The second is making the computer remember for you. An offboarding form that fires the checklist automatically, creates the tasks, notifies whoever has to run them, and keeps nagging until everything is closed. That is a half dozen step automation, not a system. It runs on a tool you probably already pay for.

The gain is not technical, it is human. Offboarding is usually a heavy day, sometimes a tense one, and that is exactly when attention disappears. An automated process does not feel sorry for anyone and does not forget Figma.

The cost of doing nothing

Worth putting numbers on this, because nobody prioritizes abstract risk.

If your client base leaks to a competitor, what is that worth? If a confidentiality clause is broken through an access you left open, who answers for it? Privacy law does not ask whether it was careless. It asks whether you had control over who accessed personal data. "We forgot to remove their access" is not a good defense.

Apple has an entire team and is still arguing this in court. You will not have an entire team. You will have a spreadsheet and a checklist, and honestly, at your scale, that solves 90% of the problem.

If you want to map your company's tools and build an offboarding process that runs on its own, get in touch. It is usually faster than you imagine, and you sleep better afterwards.

LinkedIn summary

How many people who no longer work with you can still get into the company Drive today?

If you paused for two seconds, you already know the answer.

In August 2026 Apple went to court to say more former employees may have taken confidential material. Apple. Badge readers, compartmented buildings, a paranoid security team.

Your ten person office with thirty SaaS subscriptions is not immune. It is just less watched.

And it is almost never a spy movie. It is the client spreadsheet a salesperson exported to a personal Gmail in March, then left in July. It is the freelancer who is still a Figma admin. It is the shared Canva login eight people know by heart.

Nobody is a villain here. But data outside your control is a leak, intent or not.

You do not need expensive software. You need a list of your tools and thirty minutes on the Friday someone leaves.

Want help building that checklist before you need it? Get in touch.

#InformationSecurity #DataPrivacy #BusinessManagement #Automation #SmallBusiness