ComplianceSeptember 30, 20266 min

The security risk nobody sees: active access from people who no longer work with you

A banking client in Colombia sent manual tickets to deactivate employees who no longer worked there: 10–15% of its monthly volume, urgent by nature. Automating detection of the offboarding email and triggering deactivation via API eliminated that risk and that volume — and the same pattern later automated onboarding of new employees.

A banking client in Colombia sent manual tickets to deactivate employees who no longer worked with them — between 10% and 15% of its monthly ticket volume, urgent by nature because every delay meant a former employee with active access to the platform. Automating detection of the offboarding email and triggering deactivation via API, without manual intervention, eliminated that risk and that ticket volume — and the same pattern was later reused to automate onboarding of new employees.

The access that stays open after the last day

A former employee's access, active one day longer than necessary, isn't an administrative detail — it's one of the most common findings in SOC 2 and ISO 27001 audits, and one of the easiest to prevent if the process doesn't depend on someone remembering to send the ticket on time.

How common is this risk, really?

2026 identity governance studies place orphaned accounts among the top three SaaS security concerns for 89% of surveyed CISOs, on par with privilege escalation and shadow IT. And in a recent industry analysis, 27% of cloud breaches involved misuse of inactive credentials — many of them accounts belonging to people who should no longer have access.

How was the automation designed?

We met with the client to understand their offboarding process and the exact format of their notification emails. From there we designed an automated flow: when an email arrived from an approved sender containing certain keywords, an agent triggered an API call that updated the user's status directly on the platform, with no manual handling. We then applied the same pattern to automate initial setup of new employees.

What changes when automation replaces the ticket?

We eliminated manual handling of those tickets entirely, cutting that account's monthly volume by 10–15% and removing the risk of delayed deactivation. We also freed Level 1 to focus on higher-value cases. What I'd do differently today: require the same email format from the start, so Level 1 never receives these cases through the manual path — the automation should be the only route, not a shortcut running in parallel with the manual fallback.

The lesson I take

The average cost of a data breach is around $4.45 million USD according to IBM (2024) — and part of that risk lives in something as simple as an access that should have been closed the same day someone stopped working with you. Automating that closure isn't an efficiency improvement; it's basic access control.

Data sources: 2026 identity governance studies (orphaned accounts among the top three SaaS security concerns for 89% of surveyed CISOs); industry analysis on cloud breaches (27% involved misuse of inactive credentials); IBM Cost of a Data Breach Report 2024 ($4.45 million USD global average).

Frequently asked questions

How do you automate access revocation without relying on manual tickets? By designing a flow that detects the offboarding event (for example, an email from an approved sender with certain keywords) and automatically triggers an API call that updates the user's status on the platform, with no human intervention.

What is an orphaned account? A user account that remains active with system access after the person left the organization or changed roles. It's a frequent finding in SOC 2 and ISO 27001 audits and a common vector in data breaches.

Related article: information security for fintechs in Colombia — what the SFC requires in 2026Related article: how much does ISO 27001 certification cost and take in Mexico?
#AccessControl#ISO27001#SOC2#IdentityGovernance#Automation#Colombia#Fintech#OrphanedAccounts
Share:LinkedIn
Quick answerDetail

How do you automate access revocation without relying on manual tickets?

A banking client in Colombia sent manual tickets to deactivate employees who no longer worked with them — between 10% and 15% of its monthly ticket volume, urgent by nature because every delay meant a former employee with active access to the platform. Automating detection of the offboarding email and triggering deactivation via API, without manual intervention, eliminated that risk and that ticket volume — and the same pattern was later reused to automate onboarding of new employees.

Written and reviewed by Rogelio Barajas González — certified Lead Auditor ISO 27001:2022 and ISO 9001:2015, with direct experience in SOC 1 Type 2 and SOC 2 Type 2. Founder of Barajas Advisory.

Company names, people, and some minor identifying details have been generalized to protect the confidentiality of the organizations involved. The facts, figures, and lessons narrated remain faithful to what happened.

Verify his credentials on LinkedIn:linkedin.com/in/rogelio-barajas-gonzalez

Last updated: September 2026

This is one of nine real cases

Cicatrices de Nube — do you want the rest of the stories?

All nine documented cases —FinOps, Release Management, Service Delivery, Compliance, and AI governance— with a self-assessment checklist per chapter and an overall scorecard.

Download the free playbook

Does this resonate?

If you lead operations, technology, or teams at a SaaS company and recognize these situations, let's talk. No strings attached.

Schedule your diagnosis