The offboarded account that tried to log in eleven months later
Anomaly monitoring flagged an access attempt from a departed employee's still-active account before anything was touched, and the access review that followed closed nine other stale permissions nobody had noticed.
Who, what, and how long
Professional Services
Ongoing retainer
Ongoing retainer
Client name withheld under NDA. Engagement details are shown to the extent our agreement permits.
What went wrong, and when
A departing employee's account had been deactivated in the HR system but never removed from the platform's own access list, and nobody would have known until it was used.
The HR system and the platform's access list were never connected, so deactivating a leaver in one had no effect on the other. Eleven months after that employee left, someone tried to sign in to their account with the right password. Monitoring refused the session before any application opened; without it, the next signal available to anyone would have been whatever was subsequently done with it, which is a kind of discovery no organization wants to be first to make.
We wired up access and log monitoring that flagged the login attempt from the stale account as an anomaly within minutes, then ran a full access review that surfaced nine other orphaned or over-broad permissions accumulated over two years, alongside a CVE triage process to keep dependency patching on a cadence going forward.
Phase by phase
Phase 1: Instrument
Logs worth watching
Wired continuous log and access-pattern monitoring across the platform so behavior could be compared against a norm.
- Log pipeline
- Baseline patterns
Phase 2: Detect
The stale account's attempt
Flagged the offboarded account's login attempt as an anomaly in real time, before anything was accessed.
- Detection rules
- Alert routing
Phase 3: Review access
What else was still open
Ran a full access review, surfacing nine other stale or over-broad permissions accumulated over two years.
- Access review report
- Revocation list
Phase 4: Sustain
Keep the window short
Set up CVE triage and a patch cadence so exposure doesn't quietly re-accumulate.
- Triage process
- Patch schedule
That night in order: blocked at 02:14:06, an analyst paged eleven seconds later, acknowledged inside four minutes, the account disabled by 02:31, with nothing opened and a full access review opened the next morning.
The numbers, before and after
Under 4 minutes
Time to flag the anomaly
10 accounts
Stale permissions closed
100% triaged weekly
Known CVEs now on patch cadence
Time to flag is measured from the authentication attempt to the alert being raised. Ten accounts is the one caught plus the nine the subsequent review found. The CVE figure describes the process now in place (feeds triaged weekly against the real dependency inventory), not a count of vulnerabilities closed.
Client name withheld under NDA. Figures are approximate, drawn from the engagement’s own reporting.
The engagement
There was no continuous security monitoring in place. Access was granted on hire and, in practice, rarely revisited, with offboarding a manual checklist that occasionally got missed.
A professional services firm with access granted on hire and, in practice, revisited only when someone remembered. Offboarding was a manual checklist covering the systems the leaver's manager knew about. There was no continuous monitoring at all, so the first sign of trouble would have been a consequence, not an alert.
Security Monitoring & Access Review
How it was handled
- 01
Wired continuous log and access-pattern monitoring across the platform
Monitoring went in before any access review, which is why the review happened at all: the caught attempt is what prompted anyone to look.
- 02
Flagged the offboarded account's login attempt as an anomaly in real time
A dormant account authenticating after eleven months is an unambiguous deviation, which is why it surfaced in minutes instead of at the next quarterly review.
- 03
Ran a full access review, surfacing nine other stale or over-broad permissions
Every identity was reconciled against the HR leaver list and every grant against its business justification, which turned up nine more standing permissions.
- 04
Set up CVE triage and a patch cadence to keep exposure windows short going forward
CVE feeds are now triaged weekly against the real dependency inventory and scored on exploitability in this environment, not on severity in the abstract.
Real-time anomaly flags
An out-of-pattern login surfaced within minutes, long before the next quarterly review.
Identity provider audit logs were shipped into the SIEM and scored against each account's own baseline (usual hours, usual geography, usual applications), so an out-of-pattern authentication raises an alert in minutes instead of waiting for a quarterly review to notice the account shouldn't exist. The stale account that triggered this had been dormant for eleven months, which made the deviation unambiguous.
- Identity provider logs streamed into the SIEM
- Scored per account against its own behavioral baseline
- Dormant-then-active flagged in minutes, well ahead of any review
What counts as out of pattern: the departed account's baseline of usual hours, places and applications against what arrived at 02:14, the nine rules and what each compares against, and the escalation ladder underneath.
The review that followed: ten grants, the one caught and nine found, with how each was originally issued, how long it had been dormant and what was done with it, down to the migration admin rights never withdrawn.
A full access review
Nine further stale or over-broad permissions found once the first one prompted a look.
One orphaned account is rarely alone. A full review reconciled every identity against the HR leaver list and every permission grant against its business justification, and turned up nine more: leavers never deprovisioned, contractor accounts left standing, and standing admin rights granted for a migration two years earlier and never withdrawn. Each was removed with the grant path that created it documented.
- Every identity reconciled against the HR leaver list
- Nine further stale or over-broad grants found
- Each removal documented with the grant path that created it
A patch cadence
The weekly advisory triage: each exposure marked reachable or not from the code actually running, priority set by exploitability here instead of CVSS alone, and the window measured from triage to patch.
CVE triage on a schedule, so exposure windows stay short by default.
Dependency patching moved from ad hoc to a cadence: CVE feeds are triaged weekly against the actual dependency inventory, scored on exploitability in this environment instead of on CVSS alone, and anything critical is patched inside a stated window. The point is a short exposure window by default, so there's no scramble whenever a vulnerability makes the news.
- Weekly CVE triage against the real dependency inventory
- Scored on exploitability here, not CVSS in the abstract
- Stated patch window for critical findings
Working inside their operation
A cross-functional team of 5 worked on an ongoing retainer, covering Log & anomaly monitoring, Access review, CVE triage & patching. We ran daily standups with their own lead in the room, and a demo at the end of every sprint. Scope changed twice during the engagement, and both times the change was priced and agreed before work started.
An ongoing retainer, not a project, because access decays continuously and a one-off review is correct for about a week. The full access review was triggered by the single anomaly, not scheduled, which is the argument for the monitoring: one caught attempt is what prompted the look that found the other nine.
What changed in the runbook
- 01
Offboarding that revokes the obvious accounts still leaves the ones nobody remembers issuing.
The checklist covered what the manager knew about. The standing admin grant from a migration two years earlier wasn't on anyone's list to revoke.
- 02
The single caught attempt paid for the monitoring; the nine findings behind it paid for the review.
One anomaly is worth the monitoring and is also the prompt for the review. Nobody schedules an access audit; they run one after something makes it necessary.
- 03
Access decays. Without a cadence it decays back to where it started within a year.
A cadence is the only durable answer: grants accumulate through ordinary work, so a cleaned-up access list decays back within a year without one.
02:14, replayed
The password was right. Everything around it was eleven months out of pattern.
The one blocked sign-in among 9,418 ordinary ones: how it was detected, the page and what the analyst checked, the ten grants the review closed, and the account disabled by 02:31. Switch tabs, or use the arrow keys once one is focused.
The password was right. What was wrong was everything around it. Each signal compares t.hollis@pendryvale.com with its own history, not with everyone else’s, so a sign-in that looks ordinary for the firm is plainly out of pattern for this account. 9,418 other sign-ins that night scored under the log line.
Recorded: 02:14:06, paged eleven seconds later, acknowledged inside four minutes, disabled by 02:31. Seconds between those points, weights and thresholds are illustrative.
From an audit event to a person looking at it
Monitoring went in before any access review, which is why the review happened at all. The caught attempt is what prompted anyone to look.
- 01 · SourceIdentity provider audit logsEvery authentication is logged, including one whose password is right for an account that should no longer exist.
- 02 · IngestionContinuous log streamLogs are shipped into the watch as they happen, never pulled for a quarterly review.
- 03 · EnginePer-account baseline scoringEach sign-in is compared with that account's usual hours, geography and applications, so dormant-then-active stands out in minutes.
- 04 · StateAccess list and grant pathsIdentities reconciled against the HR leaver list; every removal stored with the grant path that created it.
- 05 · DeliveryAlert routing to an analystAn out-of-pattern authentication pages a person. The one caught here was flagged in under four minutes.
What a forgotten account can reach
Offboarding gaps & standing access
A leaver's account can't sign in unnoticed
Audit logs are scored against each account's own baseline, so a dormant account authenticating raises an alert in minutes. The one that did was flagged in under four minutes, before anything was touched.
Access is reconciled, never left to memory
Every identity is checked against the HR leaver list and every grant against its business justification, which reaches the standing admin rights no offboarding checklist would list.
Exposure windows stay short by default
CVE feeds are triaged weekly against the real dependency inventory, scored on exploitability in this environment, with critical findings patched inside a stated window.
Would you know tonight if a leaver’s account signed in? Scope your build in 3 minutes.
Scope your buildNearby engagements
AI & AutomationA private legal assistant grounded in verified precedents
A private knowledge assistant that searches internal case files and precedents, providing cited answers legal teams can verify in seconds.
Legal & Law Firms · 14 weeks
Product DesignAn onboarding flow that guides trial users to value
A redesigned SaaS trial onboarding experience with progressive checklists, sample data, and inline guidance that turns signups into active subscribers.
Professional Services · 10 weeks
Product DesignA design system that brought speed and consistency to 4 product teams
A token-based design system in Figma and React that eliminated component duplication across 4 product squads and cut the time from design handoff to merged frontend.
Professional Services · 14 weeks
Let's talk
Running a large platform, shaping a first MVP, or getting a product ready for a funding round? Tell us where you are. We'll shape the process around it, and stay with you after launch.














