Access Reviews & Offboarding Audits
Verify terminated employees no longer have access to your systems
What this engagement covers
The service
When employees leave - especially those terminated under difficult circumstances - their access needs to be fully revoked across every system, SaaS tool, cloud account, and code repository. Our Access Review service audits your offboarding process and validates that former employees have zero residual access to your environment.
What we test
We audit access across your entire technology stack: Active Directory and Entra ID accounts, email and collaboration tools (Google Workspace, Microsoft 365, Slack), cloud consoles (AWS, Azure, GCP), source code repositories (GitHub, GitLab, Bitbucket), SaaS applications, VPN and remote access, API keys and service accounts, SSH keys, CI/CD pipelines, and shared credential stores. We also review whether MFA was properly deprovisioned and whether any personal devices retained corporate access.
How we run it
We work with your HR and IT teams to identify recently departed employees and contractors, then systematically verify that every access point has been revoked. We cross-reference identity providers with individual application access, check for orphaned accounts, review shared credentials that may need rotation, and validate that offboarding procedures are being followed consistently.
Identity provider account status verification
Email and collaboration platform access audit
Cloud console and IAM access review
Source code repository access validation
SaaS application access enumeration
VPN, SSH, and remote access checks
API key and service account review
Offboarding process and policy assessment
What you receive
Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.
- Complete access audit report per departed employee
- Residual access findings with risk ratings
- Orphaned and dormant account inventory
- Shared credential rotation recommendations
- Offboarding process gap analysis
- SaaS and cloud access verification matrix
- Policy and procedure improvement recommendations
- Executive summary for leadership and compliance
What we usually find
The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.
Who this is for
Findings are mapped to SOC 2, ISO 27001, NIST 800-53, HIPAA, PCI-DSS, GDPR, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.
Scope it in one call
Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.