The report is the product. Read one.

Every audit produces the same artifact: a findings report with evidence, risk, actions, owners, and a sequenced plan your team can approve in one sitting. Below is a full sample. Every row uses illustrative data and is marked SAMPLE-001; real reports are specific to your environment and carry evidence references for every line.

SAMPLE-001 · Illustrative data throughout

Systems and Access Findings Report

Read-only audit of identity, access, sharing, connected apps, and automations. Prepared for approval: each finding is classified safe, approval-needed, or dependency-check-needed.

Client: Example Co (illustrative) Scope: Google Workspace + SaaS + automations Status: Awaiting owner approval

1 · Executive summary

The audit documented 38 accounts, 6 admin roles, 214 externally shared items, 27 OAuth grants, and 9 automations. Twelve findings need action: two critical, six review, four housekeeping.

The pattern behind most findings is a departure process that ends at "disable the account." Files, delegated inboxes, OAuth grants, and automations owned by leavers stay behind. The fix list below closes the current gaps; the offboarding workflow in section 5 stops them from rebuilding.

2 · Findings, in full detail

F-USR-01

Former employee account active 94 days after departure

Critical
Evidence
Directory export row 14: last sign-in 2026-05-02, status active, license assigned. Owns 212 files referenced by the finance team.
Risk
Live credentials for a person who no longer works here; mail continues to arrive and auto-forward.
Action
Transfer file ownership to finance lead, disable sign-in, reclaim the license.
Owner
Workspace admin. Dependency: ownership transfer must complete before the account is disabled.
Approval
Awaiting owner sign-off
F-APP-03

Abandoned scheduling tool retains full mailbox scope for 11 users

Critical
Evidence
OAuth grant list: scope mail.read mail.send calendar, last token use 143 days ago. Vendor contract ended last year.
Risk
A third party nobody pays anymore holds standing read and send access to 11 mailboxes.
Action
Revoke the grant org-wide after owner confirmation that no workflow depends on it.
Owner
Operations. Dependency: confirm the sales team's booking flow moved to the new tool.
Approval
Awaiting owner sign-off
F-AUT-02

Invoice sync runs under a former contractor's personal account

Review
Evidence
Workflow list: owner alex.g (external), 340 runs in 90 days, connected to accounting and email.
Risk
Breaks silently if the account is disabled first; the contractor retains access to invoice data until it moves.
Action
Recreate under a named service account, rotate the connected credentials, then remove the personal owner.
Owner
Operations with VXSec. Dependency: service account and credential rotation come first.
Approval
Approved 2026-07-14

3 · Findings table, remaining items

Remaining sample findings
RefFindingActionOwnerStatus
F-ADM-01Four global admins where one break-glass plus one owner is sufficientReduce roles, document break-glassIT leadReview
F-FIL-02Client folder shared to anyone with the link, edit accessRestrict to named users after client reviewAccount leadReview
F-AI-01Meeting bot with drive read scope, no inventory entry or approverAdd to inventory, narrow scope, assign ownerOperationsReview
F-LIC-04Six paid seats assigned to inactive accountsVerify, then reclaim after ownership transferFinanceApproved
F-USR-05No documented departure checklist; last three exits handled from memoryAdopt the workflow in section 5OperationsApproved

4 · Change log, running record

Sample change log
DateChangeApproved byReversal
2026-07-15F-AUT-02: invoice sync recreated under service account, credentials rotatedOwner, 2026-07-14Prior workflow retained disabled for 30 days
2026-07-15F-LIC-04: two seats reclaimed after ownership transfer confirmedOwner, 2026-07-14License re-assignable at any time

Every implemented change lands here: what changed, when, who approved it, and how to reverse it where reversal is practical.

5 · Offboarding workflow, output

The audit ends with a departure workflow written for the client's actual stack. Extract:

Departure checklist, first hour

Extract, 4 of 22 steps
  • Transfer ownership first. Files, shared drives, and automations move to named owners before anything is disabled.
  • End sessions and revoke tokens. Sign out everywhere, revoke OAuth grants and app passwords tied to the account.
  • Redirect, do not forward blindly. Route mail to the role inbox with a dated note, review delegates and rules.
  • Log every step. Date, actor, and system, so the record answers questions later.

SAMPLE-001 is illustrative from top to bottom. No real client data appears on this page.

What your team does with it

Approve in one sitting. Findings arrive pre-classified as safe, approval-needed, or dependency-check-needed, so the review meeting produces decisions instead of a follow-up meeting.

Get it fixed. Approve the plan and VXSec implements it in a cleanup sprint. Prefer in-house? Your team gets a sequenced list with owners and dependencies, not a PDF of vague concerns.

Fix the process. The included offboarding workflow turns the biggest recurring source of access debt into a routine.

Keep the record. The report is a dated baseline you own. Useful for clients, insurers, and diligence questions that ask how access is governed. Findings can be mapped to CIS-style baseline controls where applicable; the audit is not a compliance certification and does not claim to be one.