The zombie SaaS audit starts with a simple question: how many of your former employees can still log into your software? Someone leaves the company on a Friday. By Monday, their email is disabled and their laptop is back in the pile. The offboarding checklist is complete.
What nobody checked: their login to the project management tool they signed up for in Q3. The cloud storage folder they shared with a contractor during that client engagement. The CRM access they’ve had since two roles ago. Three months later, those sessions are still active — and nobody knows.
This is how zombie accounts form — and it’s exactly what a zombie SaaS audit is designed to uncover. Not through negligence exactly, but through an offboarding process built around corporate IT assets that no longer reflects how people actually use software. The average company now runs more than 100 SaaS applications. Most offboarding checklists were written when there were three.
What a Zombie SaaS Audit Actually Finds
Running a zombie SaaS audit is a systematic review of every active login and permission in your software stack, cross-referenced against who actually still works for you. The name is informal. The risk is not.
What makes zombie accounts particularly dangerous is that they are valid credentials. There is nothing for a security system to detect — the access was granted intentionally, and the platform has no reason to question it. If a former employee walks back in through that door, or if their credentials are compromised after they leave, the access is there waiting.
Grip Security’s 2025 SaaS Security Risks Report, analyzing 29 million user accounts, found that 90% of SaaS applications in use across its customer base remained outside IT’s management — and identified nearly 24,000 distinct applications in active use. Industry research consistently finds that roughly 50% of organizations have discovered former employees still accessing SaaS applications months after their departure, typically by accident rather than through a deliberate audit.
The 3 App Categories Where Access Never Gets Removed
1. Cloud Storage and Collaboration Tools
Google Drive, OneDrive, and Dropbox are where zombie access causes the most immediate damage — and where offboarding gets genuinely messy.
Files may be shared with a departing employee’s personal account during a project. Guest permissions granted for a client engagement may never get cleaned up. Folders set to “anyone with the link” access may still be bookmarked. When the departure triggers a license removal in the identity provider, the shared folders, external links, and personal-account shares go untouched.
The most common result: a former employee who can’t log in through the corporate SSO can still access a shared Google Drive folder directly because nobody revoked the file-level permission.
2. Project Management and CRM Platforms
Tools like Asana, Monday.com, Notion, Jira, HubSpot, and Salesforce are frequently provisioned by team leads rather than IT. That means the offboarding checklist has no visibility into them at all.
A former account executive’s Salesforce login — with full access to the pipeline and client contact data — can persist for months without anyone noticing. The same applies to a project manager’s Notion workspace containing company strategy documents, or a HubSpot account with access to customer communication history.
These platforms were never added to the IT asset list because IT never provisioned them. CISA recommends organizations maintain an inventory of all authorized software — a baseline most businesses haven’t extended to SaaS applications provisioned outside of IT. When offboarding happens, only the IT asset list gets checked.
3. Shadow SaaS — The Tools IT Never Knew Existed
This is the most dangerous category and the one a zombie SaaS audit is specifically designed to find.
These are the tools employees signed up for using their work email — a survey platform, an AI writing assistant, a data visualization tool, a competitor research subscription. They were never formally provisioned, and they were never formally revoked. When the employee leaves, the account sits there attached to a work email address that may now redirect to an IT catch-all, with no one aware it exists.
How to Run a Zombie SaaS Audit
Step 1: Build Your SaaS Inventory
Start by pulling a list of all SaaS applications connected to your identity provider — Microsoft Entra ID, Google Workspace Admin, or Okta, if you use one. Cross-reference with billing records, browser extension installs, and email domains showing regular login notifications from third-party platforms.
For smaller teams without a dedicated identity platform, a structured review of active subscriptions, credit card statements, and recent login notification emails will surface most of the high-risk tools within a few hours. The goal at this stage is breadth, not perfection — you’re building the inventory that makes the zombie SaaS audit actionable.
Step 2: Cross-Reference Against Your Offboarding Records
Take the last 12 months of employee departures and check each name against the SaaS inventory. For each application, ask: Does this platform have an admin console? Can you see who is still active? When did this account last log in?
Access that is months old and belongs to someone who has left is a zombie. Flag it for immediate revocation. A completed zombie SaaS audit documents what was found, what was revoked, and when — the documentation matters for the audit trail and for building your ongoing process.
Step 3: Revoke, Document, and Set a Review Cadence
Remove the access. Record what was found, what was revoked, and when. Then use the audit as the baseline for an offboarding checklist that covers more than the corporate email and laptop.
Going forward, enforce multi-factor authentication on all remaining active accounts as part of your zombie SaaS audit follow-through and schedule a SaaS access review quarterly. Quarterly is a reasonable baseline for most businesses. Any employee exit should also trigger an immediate SaaS review as part of the offboarding procedure, not just the next scheduled audit.
The IBM Cost of a Data Breach Report 2025 identifies compromised credentials as the most common initial attack vector — a risk zombie accounts amplify directly by leaving valid credentials active long after they should have been revoked. That cadence converts a one-time cleanup into a repeatable control — which is what makes the difference between an organization that does this once and one that actually stays clean.
Zombie Accounts Are Already in Your Stack
A zombie SaaS audit is not a precautionary exercise for organizations with sophisticated security programs. It’s a practical necessity for any business that has hired and lost staff in the last two years — and the zombie SaaS audit process takes hours, not weeks — which is every business.
The access exists. A zombie SaaS audit answers the question of where it is and who still has it. If you’d like help running a zombie SaaS audit for your Southeast Texas business, our managed IT services include SaaS access reviews and offboarding process builds — schedule a free IT checkup to get started.
Frequently Asked Questions: Zombie SaaS Audit
How do zombie accounts differ from ordinary inactive accounts? A zombie account belongs to someone who has actively left the organization — meaning there is no legitimate reason for the access to continue. An inactive account may belong to a current employee who simply doesn’t log in often. Both carry risk, but zombie accounts carry the additional exposure of belonging to someone entirely outside the business who may have no remaining obligation to protect what they can access.
What is the fastest way to identify zombie accounts? Start with your identity provider. Microsoft Entra ID, Google Workspace Admin, and Okta all allow you to filter active users and connected applications by account status. Cross-referencing those lists against HR exit records from the past 12 months will surface most of the obvious gaps within a few hours. Shadow SaaS applications — the hardest category a zombie SaaS audit has to find; tools IT didn’t provision — require the additional step of reviewing billing records and login notification emails.
Do shared or team SaaS accounts create zombie access too? Yes, and they’re harder to clean up because the original access is difficult to attribute to a single person. Shared logins should be replaced with individual accounts wherever a platform allows it — both for the audit trail and for clean offboarding. A shared login that five people used cannot be selectively revoked when one of those five leaves.
How often should a SaaS access audit run? Quarterly is a reasonable baseline for most businesses. Any employee exit should also trigger an immediate SaaS access review as part of the offboarding checklist, rather than waiting for the next scheduled audit. The combination of event-triggered reviews and a quarterly cadence closes most of the gap that zombie accounts exploit.
What should be on a SaaS offboarding checklist? At minimum: disable the identity provider account, revoke licenses in IT-managed platforms, review file-sharing permissions in cloud storage, check project management and CRM access, and search for shadow SaaS by reviewing login notifications sent to the departing employee’s email address. A completed checklist for each departure creates the documentation trail that makes future audits significantly faster.
Every zombie SaaS audit we run for Southeast Texas businesses surfaces access that surprised the business owner. The accounts are there. The question is whether you find them before someone else does.
Article used with permission from The Technology Press.
