FlagshipRead-only firstFixed fee

Systems and Access Cleanup

A fixed-fee cleanup of who and what can access your systems. Phase one is a read-only audit that documents everything with evidence. Phase two implements the fixes you approve. You keep the report, the change log, and an offboarding workflow that stops the mess from rebuilding.

Fee
Audit from $750 single system, from $1,500 multi-system. Sprint $2,500 to $12,000. Fixed in writing.
Access
Read-only for the audit: exports, screen share, or temporary least-privilege roles.
Output
Findings report with evidence, a sequenced cleanup plan, a change log, and an offboarding workflow.

Phase one: the read-only audit

The audit answers three questions with evidence: who has access, what has access, and whether each of them still should. Nothing is changed during this phase, so there is no risk to production systems. What gets checked:

  • Stale users: ex-employees, finished contractors, and dormant accounts that can still sign in or hold licenses.
  • Admin role sprawl: super admins, delegated admins, and privileged roles measured against actual jobs.
  • External sharing and ownership: files shared outside the organization, anyone-with-the-link access, and documents owned by departed users.
  • Shared inboxes: delegates, forwarding rules, and send-as permissions nobody remembers granting.
  • OAuth and connected apps: third-party grants to mail, files, calendars, and CRMs, including abandoned tools.
  • SaaS seats across the stack: Slack, Shopify, HubSpot, GitHub, and the rest, matched to real people and real jobs.
  • Automations and API keys: Zapier, Make, and n8n workflows, service accounts, and tokens with unclear owners.
  • AI tools: assistants, agents, and meeting bots connected to business data, inventoried with their scopes.
  • Cloud accounts where in scope: AWS and Azure access, keys, and billing owners.
  • Offboarding gaps: what your current departure process misses, written up as a repeatable checklist.

What you get from the audit

  • Findings table: every finding with evidence, risk level, recommended action, effort, owner, and dependencies.
  • Executive summary: what is urgent, what can wait, and what needs approval, in plain language.
  • Sequenced cleanup plan: quick wins separated from approval-needed changes. VXSec executes it, or your team runs it in-house.
  • Offboarding checklist: a repeatable departure workflow for your actual stack.
  • The license list: paid seats you can stop paying for, with the evidence behind each one.
The cleanup guarantee. If the audit does not surface real access risk worth fixing, you do not pay the audit fee, and you keep the findings report either way. The guarantee covers the audit fee. It is not a promise that any system is fully secure or that every possible issue is found, which no honest review can promise.

Phase two: the Cleanup Sprint

The audit found it. The sprint fixes it. VXSec implements the approved change list:

  • Disable or remove confirmed stale users, guests, contractors, and external collaborators.
  • Reduce admin roles to what jobs actually require, and document who holds privileged access and why.
  • Transfer ownership of files, shared drives, inboxes, and automations before any account is touched.
  • Restructure groups and permission tiers so access follows roles instead of history.
  • Revoke risky OAuth grants and connected apps, and rotate exposed API keys and tokens.
  • Move automations off personal accounts onto named service accounts with documented owners.
  • Set AI tool access controls: inventory, allowed scopes, approval steps, and offboarding tasks.
  • Write the offboarding workflow so the next departure is a checklist, not a scramble.

Sprint pricing

Cleanup Sprint pricing tiers
TierScopeFee
Small sprintOne system or a short list of low-dependency changes$2,500 to $3,500
Standard sprintMulti-system cleanup with owner approvals and documentation$5,000 to $7,500
Advanced sprintAgency stacks, cloud, automations, or multiple owner groups$8,000 to $12,000

Change control, in practice

Every sprint runs from an approved change list. Each change is classified before work starts: safe to execute, approval-needed, dependency-check-needed, or out of scope. Changes that could affect data, billing, production systems, client access, or integrations wait for explicit sign-off. Every change is logged with what changed, when, why, and how to reverse it where reversal is practical.

Sprints usually follow a VXSec audit, but they can also run from a partner's findings or a clear internal backlog, as long as the change list can be verified before work starts.

What is excluded

Helpdesk tickets, device support, custom app development, broad procurement, and destructive changes without written approval. If new findings surface mid-sprint, they are documented and quoted separately rather than absorbed silently. Where the fix is structural rather than janitorial, identity projects like SSO and MFA rollouts, Microsoft Entra ID and Google Cloud Identity configuration, and offboarding automation are scoped as their own engagements after the audit.

Get the full access picture

The scope check confirms systems and team size and gives you a fixed fee in writing. The audit itself is read-only, so there is no risk to production systems.

Book a scope check