Zombie Accounts Are Hiding in Your SaaS Stack
Someone leaves the company on a Friday. By Monday, their email is disabled and their laptop is back in the pile. What nobody checks is the project management tool they signed up for last quarter, the cloud storage folder they shared with a contractor, or the CRM login left over from a previous role. Three months later, those sessions are still active.
These are zombie accounts, and they form through an offboarding process built around corporate assets rather than how people actually use software. The average business now runs more than 100 SaaS applications. Most offboarding checklists were written when there were three.
What makes a zombie account so dangerous is that it uses valid credentials. There is nothing suspicious to detect. The access was granted intentionally, and the system has no reason to question it. Industry research has found that half of all organizations have discovered former employees still reaching into SaaS applications months after their departure date, and for most of them, the discovery was accidental.
Three categories account for the majority of leftover access. Cloud storage and collaboration platforms like Google Drive, OneDrive, and Dropbox top the list, where guest permissions, personal-account shares, and open link settings survive long after the license is removed. Project management and CRM tools such as Asana, Notion, Jira, HubSpot, and Salesforce come next, since they are often provisioned by team leads rather than IT. The riskiest group is the shadow tools nobody registered at all, signed up for with a work email and never formally revoked.
The fix starts with a SaaS inventory. Pull every application connected to Microsoft Entra ID, Google Workspace Admin, or Okta, then cross-reference billing records, browser extensions, and login notification emails. One 2025 industry report analyzing 29 million user accounts identified nearly 24,000 distinct SaaS applications across its customer base, with 90 percent sitting outside IT management. For smaller teams, a focused 30-minute review of active subscriptions will surface most of the high-risk tools.
Next, take the last twelve months of departures and check each name against that inventory. Any access that belongs to someone who has left is a zombie. Revoke it, document what you found, and use those findings as the baseline for a stronger checklist. From there, enforce multi-factor authentication on every remaining account and schedule a SaaS access review each quarter so a one-time cleanup becomes a repeatable control.
Zombie accounts cannot be closed if nobody is looking for them. Cyclone 365 helps Gulf Coast businesses run a full zombie SaaS audit and build an offboarding process that holds up on every exit. Contact us to schedule a consultation. Call or Email us today!