Free checklist · PDF

The ghost hunting checklist.

Finding the access that outlived its reason: a field guide for teams running manual user access reviews.

What’s inside

Eight places ghosts hide, and how to find them.

A ghost is any account, credential, or permission that has outlived the person, system, or business reason it was created for. Manual reviews catch the obvious cases. These are the quieter ones they structurally miss.

  • Terminated employeesCross-check a year of HR terminations against every system, starting with the ones that get forgotten: legacy apps, vendor portals, VPN, and shared drives.
  • Contractors & vendorsMatch each account to its contract or SOW end date, and flag any that was never given an expiration date at all.
  • Role-change leftover accessCompare current title and department against the full access list, looking for combinations that don't belong together, like finance approval rights on someone now in HR.
  • Service & system accountsInventory every account not tied to a named person, and confirm each has an owner, a known purpose, and a recently rotated password.
  • Shared & generic credentialsFind convenience logins passed around in docs and wikis, and check whether they were rotated after the last person who knew them left.
  • Decommissioned systemsConfirm access to anything retired or replaced in the last three years was formally revoked, not just abandoned.
  • Break-glass & emergency accessReview a year of elevated-access grants and confirm each was time-boxed and revoked once the incident closed.
  • Dormant & duplicate accountsFlag anything with no login in 90 days, and search for near-duplicate usernames left behind by rehires, name changes, and typos.

Also in the guide

A red-flag threshold for every category, and seven process changes that keep ghosts from coming back, from quarterly review cadence to time-boxed break-glass access.