How to conduct access audits when SaaS permissions for offboarded employees haven't been revoked?
While performing an offboarded account review this week, I discovered that two individuals who had already left the company according to the HR system still retained read-only permissions in a project management SaaS. The permissions weren't high, but the system contained client project names and attachments, so it shouldn't be treated lightly from a security perspective. During the…