A client called us in a panic last spring because their Stripe dashboard showed a refund they didn't authorize. Not a huge one — $340 — but nobody on the current team remembered issuing it. We pulled the activity log. The refund came from an account belonging to a contractor who'd stopped working with them four months earlier.
Nobody had done anything malicious. The contractor had just forgotten he still had access, logged in out of habit to check something unrelated, and fat-fingered a refund. That's the boring, unglamorous truth about most access-related incidents: it's rarely a hacker in a hoodie. It's an ex-employee who still has a working password and no reason to think twice about using it.
Offboarding a person and offboarding their access are two different jobs
When someone leaves — an employee, a contractor, an agency you fired — the HR part is quick. Final paycheck, exit interview, laptop back in a box. The access part is where things fall apart, because access isn't in one place. It's scattered across Google Workspace, AWS, your CRM, the shared Dropbox, the WordPress admin panel, Slack, the domain registrar, QuickBooks, and probably a Figma account nobody remembers creating in 2023.
We ask new clients a simple question during onboarding: "If your ops person quit today, could you list every system they can log into?" Maybe one in five can answer confidently. The rest guess, and guessing is how you end up with a bookkeeper who left eighteen months ago still technically able to see your bank feed.
Why this stays broken
It's not that owners don't care about security. It's that access sprawl happens gradually and offboarding happens all at once, under time pressure, usually while someone is also trying to hand off actual work. Revoking access feels like a task you can get to later, because nothing bad has happened yet. Then eighteen months pass and nothing bad has happened yet becomes the whole strategy.
The fix isn't a security audit — audits are a snapshot, and access sprawl is a moving target. What actually works is boring: one document, kept current, that lists every system with an owner, and a rule that offboarding isn't done until every line on that list is checked off. Not "IT will handle it eventually." Checked off, same day, by name.
We build this list for clients as part of our managed IT engagements because it's the single highest-leverage security thing a small business can do, and it costs nothing but discipline. No new tooling, no vendor to evaluate, no budget line. Just a list and a habit.
The takeaway
You don't need a security team to fix this. You need to know, right now, whether you could name every system your last departed hire can still open. If the honest answer is "probably most of them, I think," that's not a security posture — it's a lottery ticket you're hoping doesn't come up. Go make the list before you need it, not after a $340 refund tells you it exists.