---
title: "Orphaned access: what removal leaves behind"
description: The risks of orphaned access in user provisioning and deprovisioning, highlighting the importance of full removal processes to protect sensitive systems.
image: https://riskinsights.com.au/hubfs/Orphaned%20access%20what%20removal%20leaves%20behind.png
---

[Skip to content](https://riskinsights.com.au/blog/orphaned-access-what-removal-leaves-behind#main-content)

[![Risk Insights - Logo - (RGB, Horizontal, Small)](https://riskinsights.com.au/hs-fs/hubfs/Risk%20Insights%20-%20Logo%20-%20(RGB%2c%20Horizontal%2c%20Small).png?width=200&height=40&name=Risk%20Insights%20-%20Logo%20-%20(RGB%2c%20Horizontal%2c%20Small).png)](https://riskinsights.com.au)

- [Articles](https://riskinsights.com.au/blog)
- [Approach](https://riskinsights.com.au/approach)
- [About](https://riskinsights.com.au/about)
- [Contact](https://riskinsights.com.au/contact)

Open main navigation

Close main navigation

- [Articles](https://riskinsights.com.au/blog)
- [Approach](https://riskinsights.com.au/approach)
- [About](https://riskinsights.com.au/about)
- [Contact](https://riskinsights.com.au/contact)

---

 09 Jul 2026

# Orphaned access: what removal leaves behind

![Picture of Yusuf Moolla](https://riskinsights.com.au/hs-fs/hubfs/Yusuf_Moolla_Headshot-transformed.png?width=50&name=Yusuf_Moolla_Headshot-transformed.png) [Yusuf Moolla](https://riskinsights.com.au/blog/author/yusuf)

Share: [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://riskinsights.com.au/blog/orphaned-access-what-removal-leaves-behind) [envelope icon](mailto:?body=https://riskinsights.com.au/blog/orphaned-access-what-removal-leaves-behind)

**TL;DR**

• Granting access to a system can be several steps, across systems.

• Removing access, when someone leaves or changes roles, can sometimes reverse only one of those steps.

• The leftovers are dormant: at risk of reactivation with a rehire or re-engaged contractor.

 

Granting access to an application often takes more than one step. That's true for modelling systems, and just as true for the systems we rely on every day: loan application systems, fraud management platforms, claims workbenches and pricing engines.

Removing access should take the same number of steps. It often doesn’t, and this creates risk.

We've written before about [deprovisioning user access](https://riskinsights.com.au/blog/security_deprovisioning). This is one specific gap worth checking even where a deprovisioning process already exists.

 

## More incentive to follow up when requesting than when removing

If an onboarding step is missed, the user can't do their job, and they'll follow it up.

Offboarding doesn't have that same pressure. Unless offboarding is automated (well), removal is often at one of the layers, not everything that was done to grant access. So someone might remove access inside the app; the rest remains, unnoticed, because it’s not immediately affecting anyone.

 

## Two examples

### **App provisioning vs. app access**

Some systems require an application to be installed before a user can access it. This could be through a company portal. Getting a new starter working then takes more than one action: provision the app through the portal, then grant them access inside it.

When the user leaves or changes roles, we need to remove both the access within the app, and access to the app in the portal.

### **App access vs. network-level access**

Many modern systems use single sign-on (SSO). Access is enabled by adding the user to a network group, separate to access within the app itself. If the app only allows SSO, there’s no access without this step.

Again, when the user leaves or changes roles, we need to remove both the access within the app, and the network group membership.

 

## The dormant risks

I see each of these often (probably too often) when reviewing access controls:

### **1. Returning users**

Mature organisations don't reissue a leaver's ID to a different person, and that's the right control. But rehires and re-engaged contractors can get their old identity back. Any previously leftover access may then be re-activated. This can happen without a new approval, and without anyone realising it was there.

### **2. Clutter, or obfuscation**

Regular reviews of system access are hard enough. When the list is filled with these orphaned records that don’t map to current users, it’s easy to ignore them because there’s no immediate risk. We have other priorities.

Bith risks matter more here than for ordinary office tools, because these systems decide things about customers. Someone with leftover access to a lending system might see or touch applications they no longer have any business reason to.

 

## What to check

If we don’t have automated cross-system deprovisioning, we should map provisioning properly: list every system and layer touched when someone gets access, not just the main request. Then:

- Every step in provisioning should have a matching removal step.
- Don't assume your periodic user access review catches this. They’re often done per application, against the app's own user list. Network groups and portals are sometimes, but not always, included.
- Take a sample of departed or rehired users and check against the various access lists, including network groups (for SSO).

 

---

Disclaimer: The info in this article is not legal advice. It may not be relevant to your circumstances. It was written for specific contexts within banks and insurers, may not apply to other contexts, and may not be relevant to other types of organisations.

---

 

 

<iframe style="border-image: initial; height: 100%; width: 100%; border: medium none currentcolor;" title="Form" xml="lang" src="https://js.hsforms.net/ui-forms-embed-components-app/frame.html?_hsPortalId=44032070&amp;_hsFormId=cb36bab6-3ff8-4e12-b808-12e547e8356b&amp;_hsIsQa=false&amp;_hsHublet=na1&amp;_hsDisableScriptloader=true&amp;_hsDisableRedirect=true&amp;_hsInstanceId=c9d23009-d527-4291-bcea-642506264012&amp;_preview=true&amp;benderPackage=InpageEditorUI&amp;cacheBust=1783231166652&amp;cssPath=bundles%2Fapp.css&amp;inpageEditorUI=true&amp;localAssets=false&amp;portalId=44032070&amp;preview_key=cETtlwVh&amp;scriptPath=bundles%2Fapp.js&amp;staticVersion=static-1.85919&amp;preview_theme=true&amp;env=prod&amp;injectedScripts=react-dlb%2Cbundle.production.js%2Cfalse%2Cstatic-1.81&amp;hsSmartContentDefault=true&amp;hsEditorApp=blog_post&amp;sessionId=504130f3-3cc9-4515-b386-fc5fa64d832c" scrolling="no" data-test-id="embedded-form-cb36bab6-3ff8-4e12-b808-12e547e8356b"></iframe>

## Related posts

[![Business person writing What Are The Rules on a whiteboard](https://riskinsights.com.au/hs-fs/hubfs/Business%20Person%20writing%20What%20are%20the%20rules%20on%20a%20whiteboard-1.jpg?height=200&name=Business%20Person%20writing%20What%20are%20the%20rules%20on%20a%20whiteboard-1.jpg)](https://riskinsights.com.au/blog/dont-wait-for-legislation)

## [Algorithm Integrity: Don't wait for legislation](https://riskinsights.com.au/blog/dont-wait-for-legislation)

 09 Oct 2024

TL;DR • Legislation and standards are helpful but not sufficient for ensuring algorithmic...

[Read more](https://riskinsights.com.au/blog/dont-wait-for-legislation)

[![Old Ways Wont Open New Doors sign with beach background](https://riskinsights.com.au/hs-fs/hubfs/Old%20Ways%20Wont%20Open%20New%20Doors%20sign%20with%20beach%20background.jpeg?height=200&name=Old%20Ways%20Wont%20Open%20New%20Doors%20sign%20with%20beach%20background.jpeg)](https://riskinsights.com.au/blog/accuracy-outcome-focused-approach)

## [Algorithm Accuracy Reviews – Choosing the Right Approach](https://riskinsights.com.au/blog/accuracy-outcome-focused-approach)

 27 Nov 2024

TL;DR • Outcome-focused accuracy reviews directly verify results, offering more robust assurance...

[Read more](https://riskinsights.com.au/blog/accuracy-outcome-focused-approach)

[![Reviewing service and generic accounts](https://riskinsights.com.au/hs-fs/hubfs/Reviewing%20service%20and%20generic%20accounts.png?height=200&name=Reviewing%20service%20and%20generic%20accounts.png)](https://riskinsights.com.au/blog/reviewing-service-and-generic-accounts)

## [Reviewing service and generic accounts](https://riskinsights.com.au/blog/reviewing-service-and-generic-accounts)

 06 Aug 2026

TL;DR • User access reviews typically focus on human users. • Service and generic accounts are...

[Read more](https://riskinsights.com.au/blog/reviewing-service-and-generic-accounts)

We acknowledge Aboriginal and Torres Strait Islander peoples as the Traditional Custodians of the lands on which we live and work.   
We pay our respects to Elders past and present, and honour the rich diversity of the world's oldest living cultures.

[View our LinkedIn page](https://www.linkedin.com/company/riskinsightsap) [email us](mailto:info@riskinsights.com.au) [Call us](tel:+61408946143)

2026 Risk Insights Pty. Ltd. | [Privacy](https://riskinsights.com.au/privacy-policy) | [Disclaimer](https://riskinsights.com.au/disclaimer)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Yusuf Moolla",
    "url" : "https://riskinsights.com.au/blog/author/yusuf"
  },
  "dateModified" : "2026-07-08T20:30:00.361Z",
  "datePublished" : "2026-07-08T20:30:00.000Z",
  "headline" : "Orphaned access: what removal leaves behind",
  "image" : [ "https://riskinsights.com.au/hubfs/Orphaned%20access%20what%20removal%20leaves%20behind.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://riskinsights.com.au/blog/orphaned-access-what-removal-leaves-behind",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://riskinsights.com.au/hubfs/Risk%20Insights%20-%20Logo%20-%20(RGB%2c%20Horizontal%2c%20Small).png"
    },
    "name" : "Risk Insights Pty. Ltd."
  }
}
```