The licence that outlived the employee
Three short stories from small organisations I have worked with.
Someone left a business in January. Nice person, better opportunity, no drama. In June, during a review, I found her account still active, still licensed and still able to sign in. HR had updated its records, payroll had been stopped and the leaving card had been signed. Nobody had told Microsoft 365.
A web agency had been given access to a SharePoint folder while it built a new website in 2022. The website went live, the project closed and everyone moved on. The access didn't. When I found the guest account, it hadn't been used for 26 months, but it could still have been.
A client called me because their Canva account was locked. Not hacked, locked: the one person with administrator rights had left the business. Two years of templates and brand material were out of reach, and getting them back took days of back and forth with the supplier.
Nobody in any of these organisations did anything wrong. Each department did its own part of the job, and that, on reflection, was the problem.
A control with no owner
People arriving, changing role and leaving is often called joiners, movers and leavers. It touches HR, finance, line managers, IT and whoever looks after suppliers. Each has a piece of it. In many organisations, nobody owns the whole thing from start to finish, so it is nobody's job to check that the pieces joined up.
The costs are easy to underestimate. A licence left running is a modest waste of money. An account that can still sign in, or a supplier who can still read your files two years later, is an open door. A tool that only a former employee can administer is a continuity risk that looks like a password problem.
What I would ask as a board member
I wouldn't ask whether there is a leavers' process. There almost always is. I would ask for evidence that it works:
- For everyone who left in the last year, how many days after their last day was their access removed?
- Which suppliers and partners can get into our systems today, and who approved each one?
- Which of the tools we rely on are administered by a single person, or by someone who no longer works here?
- Who owns the process from end to end, and when was it last tested?
These are cheap questions to answer and uncomfortable ones to ignore. Two of the three problems above took minutes to fix once somebody looked. The difficulty was that nobody's job description said "look".