Skip to main content
Home/Services/Access Reviews & Offboarding Audits
Security Testing

Access Reviews & Offboarding Audits

Verify terminated employees no longer have access to your systems

SOC 2 ISO 27001 NIST 800-53 HIPAA PCI-DSS GDPR
engagement log Access Reviews & Offboarding Audits testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingActive Accounts After Terminationcritical
day 03findingOrphaned Service Accounts and API Keyshigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
2-5 daystypical duration $3,000fixed scope, from 8deliverables 8methodology stages
Scope

What this engagement covers

The service

When employees leave - especially those terminated under difficult circumstances - their access needs to be fully revoked across every system, SaaS tool, cloud account, and code repository. Our Access Review service audits your offboarding process and validates that former employees have zero residual access to your environment.

What we test

We audit access across your entire technology stack: Active Directory and Entra ID accounts, email and collaboration tools (Google Workspace, Microsoft 365, Slack), cloud consoles (AWS, Azure, GCP), source code repositories (GitHub, GitLab, Bitbucket), SaaS applications, VPN and remote access, API keys and service accounts, SSH keys, CI/CD pipelines, and shared credential stores. We also review whether MFA was properly deprovisioned and whether any personal devices retained corporate access.

Method

How we run it

We work with your HR and IT teams to identify recently departed employees and contractors, then systematically verify that every access point has been revoked. We cross-reference identity providers with individual application access, check for orphaned accounts, review shared credentials that may need rotation, and validate that offboarding procedures are being followed consistently.

01

Identity provider account status verification

02

Email and collaboration platform access audit

03

Cloud console and IAM access review

04

Source code repository access validation

05

SaaS application access enumeration

06

VPN, SSH, and remote access checks

07

API key and service account review

08

Offboarding process and policy assessment

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Complete access audit report per departed employee
  • Residual access findings with risk ratings
  • Orphaned and dormant account inventory
  • Shared credential rotation recommendations
  • Offboarding process gap analysis
  • SaaS and cloud access verification matrix
  • Policy and procedure improvement recommendations
  • Executive summary for leadership and compliance
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Active Accounts After Termination Orphaned Service Accounts and API Keys Unrevoked SSH Keys and Certificates Retained Access to Source Code Repos Active SaaS Licenses for Former Staff Shared Passwords Not Rotated Post-Departure Personal Devices Still Enrolled in MDM Incomplete Offboarding Checklists
Fit

Who this is for

Companies After Layoffs or Restructuring
Organizations with High Employee Turnover
Businesses Handling Sensitive Data
Companies Preparing for Compliance Audits
Teams with Complex SaaS Environments
Organizations After Contentious Terminations
Standards this supports

Findings are mapped to SOC 2, ISO 27001, NIST 800-53, HIPAA, PCI-DSS, GDPR, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!