Someone leaves the company on a Friday. By Monday their email account is shut off and their laptop is back in the pile. That part, every IT team gets right.
What nobody checks is the login to the project management tool they signed up for back in Q3, the cloud storage folder they shared with a contractor, or the CRM access left over from two roles ago. Three months later, those sessions are still live.
This is how a zombie account forms. Not through negligence, but through an offboarding process built around company hardware and email that no longer matches how people actually use software.
The average company now runs more than 100 SaaS applications. Most offboarding checklists were written when there were three. We see the gap nearly every time we take over an environment from a previous provider.
What a zombie account actually is
A zombie account is an active login that belongs to someone who no longer works for you. The name is informal. The risk isn’t.
What makes these accounts dangerous is that they’re valid credentials. There’s nothing to detect. The access was granted on purpose, so the system has no reason to question it. If a former employee walks back through that door, or their old credentials turn up in a breach, the access is sitting there waiting.
Research from SaaS management firm Josys found that 50% of companies have discovered former employees still reaching SaaS applications months after they left. For most of them, the discovery was an accident, not the result of an audit.
The three apps where access never gets removed
Cloud storage and collaboration tools
Google Drive, OneDrive, and Dropbox are where zombie access does the most immediate damage.
This is where offboarding gets messy. Files get shared with a departing employee’s personal account. Guest permissions granted for one project never get cleaned up. Folders set to “anyone with the link” stay bookmarked long after the person is gone.
The departure triggers a license removal in your identity system. The shared folders, external links, and personal-account shares go untouched.
Project management and CRM platforms
Asana, Monday.com, Notion, Jira, HubSpot, and Salesforce are usually set up by team leads, not IT. So the offboarding checklist never sees them.
A former account executive’s Salesforce login, or a project manager’s Notion workspace full of company strategy documents, can sit active for months with nobody noticing.
The tools IT didn’t know existed
This is the most dangerous group.
These are the tools people signed up for with their work email. A survey platform. An AI writing assistant. A reporting dashboard. They were never formally set up, so they never get formally shut off.
When the employee leaves, the account stays put, tied to a work address that may now just forward to a catch-all inbox.
Running the zombie SaaS audit
Step 1: Build your SaaS inventory
Start by pulling every SaaS application connected to your identity provider (the system that manages your company logins), whether that’s Microsoft Entra ID, Google Workspace, or Okta. Then cross-reference that against billing records, browser extension installs, and the email domains that keep sending login notifications.
Grip Security’s 2025 SaaS Security Risks Report, built from 29 million user accounts, identified 23,987 distinct SaaS applications across its customer base. That’s far more than any IT team tracks by hand, and 90% of them sat outside IT’s management entirely.
If you’re a smaller team without a dedicated identity platform, a 30-minute review of active subscriptions and recent login alerts will surface most of the high-risk tools.
Step 2: Cross-reference against your offboarding list
Take the last 12 months of departures and check each name against the inventory. For each application, ask:
- Does it have an admin console?
- Can you see who’s still active?
- When did this account last log in?
Access that’s months old and belongs to someone who has left is a zombie. Flag it for immediate removal, and write down what you find.
Step 3: Revoke, document, and set a review cadence
Pull the access. Record what you found and when. Then use the audit as the baseline for an offboarding checklist that covers more than the company email and laptop.
From there, turn on multi-factor authentication (MFA, a second verification step beyond the password) on every account that stays active, and put a SaaS access review on the calendar each quarter. That cadence turns a one-time cleanup into a control you can repeat.
Making offboarding a security process
Zombie accounts can’t be removed if nobody is looking for them. The SaaS offboarding audit is where you start treating offboarding as a security process rather than an HR formality.
Want to close the gaps in your SaaS offboarding? Contact us or schedule a consultation, and we’ll run a zombie SaaS audit and build a repeatable process your team can follow on every exit.
—