MANAGED IT & SECURITY

Who Still Has Access?

Access grows every time your company adds an employee, contractor, application, or connected account. Estimate how many digital doors your business is managing, then see where stronger controls could make the biggest difference.

Calculate Your Access Sprawl
The Multiplier Effect
Identities × Applications
Illustrative Example
Total Identities
55
50 team + 5 contractors
Apps / Person
12
Average business tools
Estimated Digital Doors
660 Relationships
Each requiring onboarding, access changes, and clean removal.

Access Often Outlives the Work That Created It

Disabling someone’s email is not the same as removing all of their access. Permissions may remain inside business applications, connected accounts, shared drives, project systems, administrative tools, or resources someone accessed through a work login.

Employees Change Roles

New permissions are added while access from a previous role may remain.

Contractors Finish Projects

External users can stay connected after the work or relationship ends.

Applications Keep Accumulating

Every new application creates another set of accounts, permissions, and exceptions to manage.

Sharing Extends Beyond Accounts

External file access, shared links, connected applications, and elevated roles may require separate review.

INTERACTIVE CALCULATOR

How Many Digital Doors Does Your Business Have?

Estimate the number of user-to-application access relationships your business is managing. Then see how the total changes when you add another employee or another application.

Estimated Relationships
660 total
Action Plan
+1Each new employee adds 12 relationships
+1Each new application adds 55 relationships
Access Parameters

Adjust Your Organization's Numbers

Live Calculation
employees
5 employees250 employees

Full-time and regular personnel requiring business systems access.

apps
3 apps40 apps

Email, messaging, project tools, file drives, and software.

people
0 people100 people

Agencies, freelancers, and vendors with accounts or file access.

%
0% (None)100% (All)

Logins governed through Google Workspace, Entra, or Okta.

events
0 events100 events

Total access lifecycle moments per year requiring updates.

Policy status

Universal 2-step verification requirement.

Scheduled audits of active accounts
Assumes normal business operations. Slide or type exact values.Updates live instantly
Calculated Estimate

Estimated User-to-Application Access Relationships

660

An access relationship is an estimate of one person's access to one application. It is not the same as a confirmed vulnerability.

Centrally Managed
396
Via SSO or common identity
Estimated Outside Central Identity
264
May require separate ownership or review
Annual Access Actions
216
Hires, moves & leavers
Total Identities
55
Employees + contractors
Tailored Action PlanMFA: Yes | Quarterly
1
Review MFA Exceptions and Privileged Accounts

Confirm that MFA coverage includes privileged accounts, contractors, recovery methods, exceptions, and applications outside the main identity system.

2
Expand Centralized Identity and SSO

Begin with applications used by the most people or containing sensitive information, then document ownership for accounts that must remain separate.

3
Establish Recurring Access Reviews

Establish a quarterly review covering employees, contractors, applications, external sharing, and elevated roles.

Access Control Is a System, Not One Setting

MFA matters. Centralized identity matters. Neither replaces the need to understand whether a person should still have access.

Centralize Identity Where Practical

Use a common identity system and SSO to make accounts easier to create, manage, and remove.

Require Strong Authentication

Protect important accounts with MFA and appropriate administrative controls.

Review Applications, Sharing, and Elevated Roles

Connected applications, external file access, contractors, and administrator privileges still require deliberate review.

Connect Access to the Employee Lifecycle

Hiring, role changes, contractor engagements, and departures should trigger repeatable access steps.

Frequently Asked Questions

What is an access relationship?

An access relationship is one person’s access to one application. If 50 employees each use 10 applications, the calculator estimates 500 user-to-application relationships.

Does every access relationship represent a vulnerability?

No. Most access exists for legitimate business reasons. The estimate represents the environment that must be understood and governed, not a count of security problems.

Does MFA solve the access problem?

No. MFA helps protect an account from unauthorized sign-in, but it does not determine whether someone should still have the account or permission.

Does disabling email remove every kind of access?

Not necessarily. Third-party applications, external file sharing, connected accounts, contractor access, and special administrative permissions may require separate action.

What does “outside centralized control” mean?

It means the relationship may not be managed directly through the company’s central identity system and may require a separate process, application owner, or manual review.

Does Grux only work with Google Workspace?

No. Grux works across the business technology environment. Google Workspace is one common identity and productivity environment, but access may also exist in CRMs, financial platforms, project systems, communication tools, custom software, and other applications.

Do we need to replace our current IT provider?

No. Grux can evaluate whether the best next step is to improve the existing process, supplement the current provider, or establish a more complete managed technology relationship.