Why You Should Audit Your Software Permissions Quarterly

Former employees with active accounts. Contractors with admin access. Interns who can see payroll. Quarterly permission audits catch these risks.

By The StackMatch Research Team

Former employees retain access for 6+ months in 30% of SMBs, quarterly audits close the security gap

30%of SMBs have active former employee accounts
6+ moAverage time orphan accounts remain active
30 minPer-tool review time for a quarterly audit

Former employees with active accounts, contractors with admin access, quarterly permission audits catch these risks.

30 min
per tool for quarterly permission audit
A quarterly audit takes 30 minutes per tool but prevents costly incidents.

Quarterly permission review

  • Does this person still work here?
  • Do they still need this level of access?
  • Are there duplicate accounts?
  • Are there shared logins that should be individual?

The most common permission failure is offboarding. Verify all accounts are revoked within 24 hours of departure.

Software permissions are the most neglected security control in small business.

Software permissions are the most neglected security control in small business. When an employee leaves, their accounts...

The quarterly permission ritual

24
hours
Relevant metric for this section.

Every quarter, review access for every tool. List every user account and ask: does this person still work here? Do they still need this level of access? Are there duplicate accounts for the same person? Are there shared logins that should be individual? This review takes 30 minutes per tool but prevents the incident that costs thousands to remediate. The key is making it routine: when permission auditing is a quarterly habit, it never becomes an emergency.

The offboarding gap

The most common permission failure is offboarding. When an employee leaves, HR processes the termination but IT doesn't know which accounts to deactivate. The fix is a simple offboarding checklist: for each departing employee, list every tool they access and verify that access is revoked within 24 hours of departure. This requires coordination between HR and operations — but the alternative is an ex-employee who can still download customer lists six months after leaving.

Former employees with active accounts. Contractors with admin access. Interns who can see payroll. Quarterly permission audits catch these risks.

Run the free audit to see which tools in your stack have the most user accounts — and which are most likely to have orphaned permissions from former employees.

Run your own audit
More from the blog