Blog
Notes on access governance.
Notes on employee offboarding, access governance and compliance from the team building AccessRevoke.
Latest
Orphaned Access: The Silent Breach Vector Nobody Audits
Orphaned access (old accounts, stale OAuth grants, forgotten tokens) rarely shows up in a pen test scope, but it is one of the most common ways real breaches start.
5 min read
Read the post5 min read
NIS2 and Access Governance: What It Actually Requires
NIS2 does not name "access revocation" explicitly, but its access control and incident-response requirements make orphaned access a compliance gap. Here is what to actually check.
NIS2Compliance
6 min read
The Employee Offboarding Checklist Security Teams Actually Need
Most offboarding checklists stop at disabling the SSO account. Here is what actually needs to happen across identity, workspace, chat and dev tools when someone leaves.
OffboardingIAM