Former agencies and contractors can remain active in marketing tools long after the business relationship ends. That leaves live access paths open to people who no longer need them, and it creates a control gap when no one can prove the account was intentionally removed.
What formal offboarding is supposed to break
Formally offboarding agency access should break the relationship between a third party and the systems they used on your behalf. That means removing active sign-in paths, disabling lingering approvals, and revoking anything that still lets the old account operate as if the relationship were current. The goal is not just removal, but proof that access no longer exists.
When that step is missed, the system often still looks “owned” even though the business relationship has ended. The account can remain usable, delegated permissions can survive, and nobody may be able to show who approved the lingering access or when it was intentionally removed. That is a lifecycle failure, not just an admin miss.
In practice, the break should cover both the account and the authority behind it. A contractor or agency user may leave behind shared logins, API keys, tokens, or cached sessions, so effective offboarding has to revoke the full access path, not only mark the relationship as closed in a spreadsheet or procurement record.
Why stale agency access creates a control gap
The main control failure is loss of accountability. If former agencies can still enter marketing platforms, the organisation no longer has a clean answer to who can act, who can approve changes, or who is responsible if data is altered or exported. That is exactly why identity lifecycle and offboarding need to be managed as governance, not just administration.
Stale access also expands the attack surface. A dormant account can be reused, sold, phished, or inherited by someone outside the original business arrangement. Even if nothing malicious happens, the organisation loses assurance that access is still limited to the intended party, which undermines least privilege and access review discipline.
For third-party and contractor relationships, this is especially common when access is created for a campaign, a platform rollout, or an external service provider and then forgotten. A good offboarding process should end with a verifiable entitlement removal, not a hoped-for cleanup. The strongest lifecycle programs treat that as part of the same control path as onboarding and review, not as an afterthought.
What actually remains exposed after offboarding fails
What remains exposed is usually broader than one login. Former agencies may retain visibility into analytics, ad accounts, CRM tools, shared workspaces, or connected apps, and those systems often contain customer, campaign, or business data that should no longer be visible. If the account still has API access or linked tokens, the exposure can persist even after password changes elsewhere.
That persistence is why offboarding failures are often discovered late, through audit, incident response, or a complaint from the business owner. A clean deprovisioning process should remove the person, the account, the delegated role, and any credential material that outlives the relationship. Joiner-Mover-Leaver controls are the usual operational model for making that sequence repeatable.
Where agencies use their own staff, the risk can multiply because access tends to be shared across multiple people and sometimes across multiple clients. That makes ownership harder to track and increases the chance that one stale entitlement survives long after the contract ends. In those cases, the right question is not whether the agency still “has” access, but whether any active path still exists from that relationship into production tools.
Risk and Threat Considerations
Stale agency access is risky because it leaves a live path from an ended business relationship into systems that may still contain sensitive data or operational control. The longer that access persists, the more likely it is to be reused, abused, or simply forgotten during an incident or audit.
Failure mechanism: The offboarding event closes the contract but does not fully revoke the account, its delegated permissions, or any tokens and sessions tied to it, so the old path remains functionally alive.
Impact: An unauthorised former user, or anyone who gains that identity, can still act inside the environment, creating data exposure, unauthorised changes, and a gap between policy and actual access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Former agency access often persists through unrecovered credentials, tokens, or sessions. |
| AC-2 — Account Management | The question is about removing active accounts when the business relationship ends. | |
| AC-6 — Least Privilege | Residual agency access is a privilege exposure problem when old permissions remain live. | |
| Recommendation — Revoke and rotate authenticators when third-party access ends. Disable or remove external accounts at contract end and confirm closure. Limit third-party entitlements to the minimum needed and remove extras on exit. | ||
| CIS Controls v8 | CIS-5 — Account Management | Offboarding failure is fundamentally stale account and entitlement management. |
| Recommendation — Inventory, disable, and remove dormant third-party accounts promptly. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | The issue is whether access rights are revoked when the relationship ends. |
| A.5.15 — Access control | The answer depends on controlling who can still reach business systems after offboarding. | |
| Recommendation — Review and withdraw access rights when agencies no longer need them. Enforce access control so external users lose entry when contracts end. | ||
Practitioner Guidance
What to verify: Treat offboarding as complete only when you can show that the external identity, its group memberships, and any surviving token or session material are gone. If the business cannot produce evidence of removal, the access should be treated as unresolved rather than assumed closed.
Decision rule: If the agency ever had access to production, customer, or campaign systems, require explicit deprovisioning evidence before closing the ticket. If the relationship was shared across multiple tools, verify each system independently instead of relying on a single “vendor offboarded” status.
Common mistake: Teams often remove the named user but leave behind shared credentials, connected apps, or service accounts that the agency also used. That creates a false sense of closure because the visible account is gone while the real access path survives.
Practitioner takeaway: The right measure of offboarding is not whether the contract ended, but whether every practical route back into the environment was revoked and can be demonstrated as revoked.