Who Still Has Access?
Access grows every time your company adds an employee, contractor, application, or connected account. Estimate how many digital doors your business is managing, then see where stronger controls could make the biggest difference.
Access Often Outlives the Work That Created It
Disabling someone’s email is not the same as removing all of their access. Permissions may remain inside business applications, connected accounts, shared drives, project systems, administrative tools, or resources someone accessed through a work login.
Employees Change Roles
New permissions are added while access from a previous role may remain.
Contractors Finish Projects
External users can stay connected after the work or relationship ends.
Applications Keep Accumulating
Every new application creates another set of accounts, permissions, and exceptions to manage.
Sharing Extends Beyond Accounts
External file access, shared links, connected applications, and elevated roles may require separate review.
How Many Digital Doors Does Your Business Have?
Estimate the number of user-to-application access relationships your business is managing. Then see how the total changes when you add another employee or another application.
Adjust Your Organization's Numbers
Full-time and regular personnel requiring business systems access.
Email, messaging, project tools, file drives, and software.
Agencies, freelancers, and vendors with accounts or file access.
Logins governed through Google Workspace, Entra, or Okta.
Total access lifecycle moments per year requiring updates.
Universal 2-step verification requirement.
Estimated User-to-Application Access Relationships
An access relationship is an estimate of one person's access to one application. It is not the same as a confirmed vulnerability.
- Total identities = employees + recurring external users
- Access relationships = total identities × average applications used per person
- Centrally managed relationships = access relationships × centralized identity coverage
- Relationships outside central control = total access relationships minus centrally managed relationships
- Annual access actions = annual employee lifecycle events × average applications used per person
- Adding one application creates one new relationship for each current identity
- Adding one person creates one new relationship for each current application
This is a directional operating estimate, not a security audit. Relationships outside central control are not necessarily vulnerabilities. Actual exposure may also include shared accounts, service accounts, shared links, device sessions, administrator privileges, and OAuth connections.
Confirm that MFA coverage includes privileged accounts, contractors, recovery methods, exceptions, and applications outside the main identity system.
Begin with applications used by the most people or containing sensitive information, then document ownership for accounts that must remain separate.
Establish a quarterly review covering employees, contractors, applications, external sharing, and elevated roles.
Access Control Is a System, Not One Setting
MFA matters. Centralized identity matters. Neither replaces the need to understand whether a person should still have access.
Centralize Identity Where Practical
Use a common identity system and SSO to make accounts easier to create, manage, and remove.
Require Strong Authentication
Protect important accounts with MFA and appropriate administrative controls.
Review Applications, Sharing, and Elevated Roles
Connected applications, external file access, contractors, and administrator privileges still require deliberate review.
Connect Access to the Employee Lifecycle
Hiring, role changes, contractor engagements, and departures should trigger repeatable access steps.
A Stronger Technology Foundation From IT to AI
Grux helps growing teams manage employee support, accounts, devices, access, data, and everyday business systems. We strengthen the technology foundation, improve the productivity tools built on it, and create bespoke software and AI workflows where they can make work easier.
Protect the data and infrastructure behind every workflow. Grux designs automation around your existing security controls, sensitive data, operational requirements, and applicable compliance obligations.
Connect AI to the systems your business already uses. Grux builds and integrates the software needed to move information, trigger actions, update records, and keep work moving across your organization.
Find and automate the work with the greatest return. Grux maps your processes, ranks the strongest AI opportunities, builds custom workflows, and measures the value they create.
Frequently Asked Questions
What is an access relationship?
An access relationship is one person’s access to one application. If 50 employees each use 10 applications, the calculator estimates 500 user-to-application relationships.
Does every access relationship represent a vulnerability?
No. Most access exists for legitimate business reasons. The estimate represents the environment that must be understood and governed, not a count of security problems.
Does MFA solve the access problem?
No. MFA helps protect an account from unauthorized sign-in, but it does not determine whether someone should still have the account or permission.
Does disabling email remove every kind of access?
Not necessarily. Third-party applications, external file sharing, connected accounts, contractor access, and special administrative permissions may require separate action.
What does “outside centralized control” mean?
It means the relationship may not be managed directly through the company’s central identity system and may require a separate process, application owner, or manual review.
Does Grux only work with Google Workspace?
No. Grux works across the business technology environment. Google Workspace is one common identity and productivity environment, but access may also exist in CRMs, financial platforms, project systems, communication tools, custom software, and other applications.
Do we need to replace our current IT provider?
No. Grux can evaluate whether the best next step is to improve the existing process, supplement the current provider, or establish a more complete managed technology relationship.