Access that was issued six months ago and forgotten is not an abstract risk — it is a routine cause of leaks. A team's makeup changes faster than the access list gets updated: an employee changed roles, a contractor finished a project, an intern left after two weeks, and the resource still shows as active. Here is what traces to use for a regular check, how often to run a review, and what to do when you find access that should have been closed long ago.
Why regularly check who is using resources
A list of issued access goes stale faster than it looks. Without a regular check, a company learns about forgotten access not in a calm setting but at the moment of an incident, when it is already too late to work out who used it and why. A review is not a reaction to suspicion — it is a way to learn about a problem before someone gets to exploit it.
What traces are available
Three sources cover most of an audit. The transaction history shows when and against which resource charges were made — an active charge means someone is genuinely using the resource, not that it merely sits on the department's books. The list of active rentals in the account is a snapshot of the current state: which numbers, mailboxes and proxy channels are paid for, and until when. The service's own login log shows the time of the last sign-in under a specific account, not just the fact that the resource was paid for. Access that is paid but has not been opened in a long time is its own reason to ask a question, even if it is formally still active.
Signs that access has leaked or stayed with a former contractor
Warning signs show up as mismatches. A sign-in from a geo that matches no one on the team. Activity at hours when the team is definitely not working. A resource that keeps charging a month after the project it was issued for has closed. A former contractor's account with login entries dated after their official departure — the most direct sign that access was not revoked in time.
How often to review
A full reconciliation of the access register against the list of active employees is worth doing at least once a quarter, and monthly for teams with high contractor turnover. A targeted check of a single resource is needed right after a departure or a contract ending, without waiting for the scheduled cycle: between someone's departure and the next quarterly audit, access can well be used by someone else.
What to do when you suspect a problem
If access with signs of a leak turns up, the sequence is simple and fast. First — change the password to the resource in question: a mailbox, a proxy rental account, a work account. Next — revoke all active sessions and API keys tied to that access, so an old session does not keep working after the password change. If a number was used as a second factor, the second factor moves to a new number assigned personally to the current person responsible, and the old number is pulled out of 2FA rotation. Each of the three steps takes minutes — what usually takes longer is not the fix but spotting the problem in the first place.
Why an audit is cheaper than recovery
A regular review is reading logs and lists that already exist, which costs nothing but time. Recovering from a leak means changing every linked access, working out exactly what was compromised, and communicating with everyone the incident touched. The difference is an order of magnitude: half an hour of monthly checking versus days of incident review and reputational costs that never make it into a report. The same register described in employee onboarding is the basis for both issuing access and later auditing it: if resources were logged from the start, a review is just checking dates, not investigating from scratch.
Frequently Asked Questions
How often should you check who is using work access?
A full review at least once a quarter; a targeted check of a specific resource right after an employee's departure or the end of a contractor's work, without waiting for the scheduled cycle.
What signs suggest access stayed with a former contractor?
The login log: activity after the official departure date, a sign-in from an unfamiliar geo, or charges on a resource that no longer has an active owner on the team.
What is the first thing to do if you suspect leaked access?
Change the resource's password, revoke active sessions and keys, and, if access was tied to a number as a second factor, move the second factor to a new number assigned to the current person responsible.
To be able to quickly move a second factor to a new number assigned personally to the responsible employee whenever you suspect a leak, use turbon.rent number rental.