Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. We Have No Idea Who Still Has Access to Our Systems, Servers and Accounts. How Do We Find Out and Get Control?
Problems We Solve

We Have No Idea Who Still Has Access to Our Systems, Servers and Accounts. How Do We Find Out and Get Control?

Don't know who has access to your systems, cloud and tools? How access sprawls, and how SpiderHunts audits it, removes what is stale and keeps it tidy.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

When you don't know who has access to your systems, the fix is an access audit followed by a simpler setup: one company identity per person through single sign-on, access granted by role, removal on leaving through a checklist, and a regular review. SpiderHunts audits cloud accounts, servers, code repositories and SaaS tools, removes stale access and sets up that routine.

A list nobody has

Someone asks who can log into the AWS account and the answer is a shrug. The GitHub organisation has members nobody recognises. A contractor who finished last year still appears in the Google Workspace admin panel. The CRM has shared logins used by several people. The office manager suspects a former employee still gets alerts from the website's hosting account.

Nobody made a mistake exactly. Access was added whenever someone needed it and rarely taken away.

How access sprawls

  • New tools are signed up by whoever needs them, with personal or shared logins.
  • Contractors and agencies are given access for a project, and nobody removes it at the end.
  • Leavers have their email closed, but their accounts in other tools stay active.
  • Admin rights are granted to fix one problem and never taken back.
  • Service accounts and API keys are created for integrations, and nobody knows which are still used.

The deeper cause is that there is no single place where identity lives. Each tool has its own users, so each tool has to be cleaned separately, and nobody has time to do all of them.

Why it matters

SituationRisk
Former staff with live accountsAccess to customer data, finances or systems after they have left
Former suppliers with admin rightsTheir security becomes your security
Shared loginsNo record of who did what, and no way to remove one person
Too many adminsMore accounts that can do serious damage if compromised
Forgotten API keysIntegrations with access nobody is watching

It also shows up when someone asks. Customers, insurers and auditors increasingly want to know how you control access and remove it when people leave. Without a list, the answer is a description of good intentions rather than evidence.

Most of these accounts will never be misused. The trouble is that you cannot tell which ones, and an account nobody watches is exactly what an attacker looks for after stealing a password.

How we audit access and keep it tidy

  1. List your systems. We build an inventory of cloud accounts (AWS, Azure, Google Cloud), servers, code repositories, domain and DNS, email, and the SaaS tools the business uses, including the ones signed up informally.
  2. Export every user and permission from each system, including service accounts, API keys and SSH keys.
  3. Match accounts to people and roles with your team, marking leavers, former suppliers, shared logins and excessive admin rights.
  4. Remove or reduce what is stale, after confirming with the owner, and rotate credentials that former people may know.
  5. Centralise identity. Where tools support it, we connect them to single sign-on through Microsoft Entra ID or Google Workspace, so one account per person controls access to many systems, with multi-factor authentication enforced.
  6. Grant access by role rather than by individual request, so a new starter gets the right set and a leaver loses all of it together.
  7. Set up the routine: a joiner and leaver checklist, and a regular access review where each system owner confirms who should still be there.

We keep this proportionate. A small business does not need an enterprise identity programme; it needs a list, fewer admins, single sign-on where it is easy, and a habit of checking.

After the clean-up

You can answer who has access to what, for each important system. When someone leaves, disabling their company identity removes most of their access in one step, and the checklist covers the rest. Admin rights are held by a small number of named people. And a regular review stops the sprawl returning.

Quick self-check

  • You could not produce a list of who can access your cloud account today.
  • Former employees or suppliers may still have working logins.
  • Several people share one login for important tools.
  • Many people have admin rights they do not use.
  • There is no checklist for removing access when someone leaves.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Do we need an expensive identity platform?

Usually not. Most small businesses already have Microsoft 365 or Google Workspace, which can provide single sign-on and multi-factor authentication for many tools.

What about tools that do not support single sign-on?

They go in the inventory with a named owner and are covered by the leaver checklist and access review, with logins stored in a team password manager.

Will removing access break anything?

It can if a service account turns out to be in use, which is why we confirm with owners first and disable before deleting.

How often should access be reviewed?

Regularly enough that stale access does not build up. We agree a schedule with you based on how often people and suppliers change.

Keep reading

More on Problems We Solve

Start here

Unsure who can get into what?

Tell us which tools, cloud accounts and systems your business uses. We will help you get a clear picture of access and a simple way to keep it current, and if your setup needs only light tidying, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →