Compare the leaver list against live application entitlements, then look for accounts that remain active in SaaS tools, shared workspaces, and delegated admin systems. Prioritise systems with local access management because they are the most likely to drift away from central governance.
How teams spot offboarding gaps in live systems
Finding missed accounts is mostly an exercise in reconciliation. The useful question is not whether someone has left on paper, but whether their access still exists anywhere that can act independently from HR or the central IAM layer. That means checking application-level users, delegated admin roles, shared workspaces, and local exceptions where entitlements drift fastest.
Teams usually get the best results when they start with the authoritative leaver list, then compare it to current entitlements and active sessions across each platform. The gaps often appear in places that were set up quickly, inherited from another team, or never fully connected to the central joiner-mover-leaver process.
A practical discovery approach is to scan for accounts that still have working permissions after the leaving date, especially in SaaS tools with their own admin console, collaboration systems, and niche platforms owned by business teams. Those systems often hold orphaned users because they do not always inherit deprovisioning automatically from upstream identity workflows.
Where missed accounts usually hide
Missed accounts are rarely confined to one system. They often cluster in places where access was granted outside the main provisioning path, such as delegated administration, locally managed groups, service-style shared accounts, or shadow integrations created for convenience. The more autonomy a platform has over its own access model, the more likely it is to retain stale access after offboarding.
Security teams also look for signs that access is still usable even if the account looks inactive in the HR record. A user may have lost primary corporate access but still retain permissions in a SaaS application, a shared workspace, or a delegated admin panel. That is why reconciliation has to cover both named user accounts and the entitlements attached to them.
Systems with local access management deserve special attention because they can diverge from central governance. If an application maintains its own admins, local groups, or manual invite process, offboarding can fail silently unless someone independently reviews the live access state.
What makes offboarding drift persistent
Offboarding drift persists when the organisation treats deprovisioning as a one-time event instead of an access lifecycle check. Accounts can survive because of incomplete source data, delayed sync, manual exceptions, or ownership ambiguity over who is responsible for revoking access in each platform.
Another common cause is fragmented entitlement visibility. If the team can see directory accounts but not application-level permissions, it can miss accounts that are no longer active centrally but still effective in the target system. That is especially common in SaaS estates where admin rights, sharing permissions, and delegated roles are managed locally.
Reconciliation works best when teams maintain a system inventory, know which platforms have local admin control, and periodically compare access lists to the leaver feed. The objective is not just to remove users, but to prove there are no surviving access paths that outlive the offboarding event.
Risk and Threat Considerations
Missed offboarding accounts create standing access that can be abused after the person has left, or after the account should have been disabled. The practical risk is that old entitlements remain valid in systems where central identity controls no longer enforce removal, which expands the blast radius of a stale credential or overlooked admin role.
Failure mechanism: A leaver record is updated centrally, but the downstream platform keeps a local user, group membership, shared workspace membership, or delegated admin right active. If the account is reused, shared, or compromised, the attacker or former user still has working access.
Impact: Unreconciled accounts can enable unauthorised data access, privilege misuse, persistence, and delayed incident detection, especially in systems that hold sensitive documents, operational workflows, or administrative controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Offboarding gaps are an account lifecycle control problem. |
| Recommendation — Review and remove stale accounts and entitlements on a recurring schedule. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Missed offboarding often leaves usable credentials or tokens behind. |
| AC-2 — Account Management | Finding missed accounts depends on inventorying and reviewing active accounts across systems. | |
| Recommendation — Track and revoke credentials promptly when a user leaves. Reconcile active accounts against authoritative leaver data and disable leftovers. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | The question is about locating identities that should no longer exist. |
| A.5.18 — Access rights | Missed accounts are ultimately unreleased access rights in target systems. | |
| Recommendation — Maintain a complete identity inventory and remove access at offboarding. Review and revoke access rights that remain after termination. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The core failure mode is leaving non-human or delegated accounts active after departure. |
| Recommendation — Verify every leaver has no remaining live access in downstream systems. | ||
Practitioner Guidance
What to prioritise: Start with systems that can create the most damage if they drift, especially SaaS admin consoles, collaboration platforms, finance tools, and any application with local role management. Those are the places where missed accounts often remain active long after the central directory says the person has left.
What to verify: The useful evidence is a three-way match between the leaver list, the current entitlement inventory, and the live access state in each target system. If you cannot prove that the person no longer has effective access, treat the account as unresolved rather than assumed removed.
Practitioner takeaway: Offboarding detection is strongest when teams hunt for effective access, not just deleted accounts, and give special scrutiny to platforms that can bypass central governance.