Failure PatternDecision layer

The Offboarding Gap: Why IAM & Access Control Collapses After Agency Staff Turnover

Symptom: A departing account manager's credentials still authenticate into three client SaaS tenants 45 days after their last day. Root cause: Agency staffing churns faster than client contracts, so identity lifecycle events (hire, role change, exit) outpace the manual provisioning and deprovisioning processes most agencies run.

By InnovaAI ResearchPublished Updated

How do you recognize it?
  • •A departing account manager's credentials still authenticate into three client SaaS tenants 45 days after their last day
  • •Client procurement asks for a user access review and nobody can produce a current list of who touched the account in the last quarter
  • •Contractors retained on a project basis keep SSO sessions alive because nobody owns the deprovisioning step
  • •Agencies discover shared logins in a spreadsheet during a client security questionnaire, not during an internal audit
Why does it happen?
  • •Agency staffing churns faster than client contracts, so identity lifecycle events (hire, role change, exit) outpace the manual provisioning and deprovisioning processes most agencies run
  • •Access is granted per client engagement rather than per role, which means every new retainer adds a new set of credentials that no single system tracks
  • •Non-human identities (API keys, service accounts, AI agent tokens) are created for delivery work and never inventoried, so they survive every human offboarding cycle
How do you fix it?
  • •Run a 30-day access reconciliation across every client tenant and revoke anything tied to a person who has left or changed roles, starting with admin-level accounts
  • •Move client credentials into a platform with SCIM provisioning and automated deprovisioning, so an HR event triggers access removal instead of a Slack reminder
  • •Assign one named owner per client account for access reviews, with a quarterly sign-off that gets attached to the retainer deliverable