Systems and Access Findings Report
Read-only audit of identity, access, sharing, connected apps, and automations. Prepared for approval: each finding is classified safe, approval-needed, or dependency-check-needed.
1 · Executive summary
The audit documented 38 accounts, 6 admin roles, 214 externally shared items, 27 OAuth grants, and 9 automations. Twelve findings need action: two critical, six review, four housekeeping.
The pattern behind most findings is a departure process that ends at "disable the account." Files, delegated inboxes, OAuth grants, and automations owned by leavers stay behind. The fix list below closes the current gaps; the offboarding workflow in section 5 stops them from rebuilding.
2 · Findings, in full detail
Former employee account active 94 days after departure
Critical212 files referenced by the finance team.Abandoned scheduling tool retains full mailbox scope for 11 users
Criticalmail.read mail.send calendar, last token use 143 days ago. Vendor contract ended last year.Invoice sync runs under a former contractor's personal account
Reviewalex.g (external), 340 runs in 90 days, connected to accounting and email.3 · Findings table, remaining items
| Ref | Finding | Action | Owner | Status |
|---|---|---|---|---|
| F-ADM-01 | Four global admins where one break-glass plus one owner is sufficient | Reduce roles, document break-glass | IT lead | Review |
| F-FIL-02 | Client folder shared to anyone with the link, edit access | Restrict to named users after client review | Account lead | Review |
| F-AI-01 | Meeting bot with drive read scope, no inventory entry or approver | Add to inventory, narrow scope, assign owner | Operations | Review |
| F-LIC-04 | Six paid seats assigned to inactive accounts | Verify, then reclaim after ownership transfer | Finance | Approved |
| F-USR-05 | No documented departure checklist; last three exits handled from memory | Adopt the workflow in section 5 | Operations | Approved |
4 · Change log, running record
| Date | Change | Approved by | Reversal |
|---|---|---|---|
| 2026-07-15 | F-AUT-02: invoice sync recreated under service account, credentials rotated | Owner, 2026-07-14 | Prior workflow retained disabled for 30 days |
| 2026-07-15 | F-LIC-04: two seats reclaimed after ownership transfer confirmed | Owner, 2026-07-14 | License re-assignable at any time |
Every implemented change lands here: what changed, when, who approved it, and how to reverse it where reversal is practical.
5 · Offboarding workflow, output
The audit ends with a departure workflow written for the client's actual stack. Extract:
Departure checklist, first hour
Extract, 4 of 22 steps- Transfer ownership first. Files, shared drives, and automations move to named owners before anything is disabled.
- End sessions and revoke tokens. Sign out everywhere, revoke OAuth grants and app passwords tied to the account.
- Redirect, do not forward blindly. Route mail to the role inbox with a dated note, review delegates and rules.
- Log every step. Date, actor, and system, so the record answers questions later.