Systems and records
The only admin of a SaaS tool has left the company: what now?
By SourceX Editorial · Updated
Short answer
When the only admin of a SaaS tool leaves, regain admin access through what the company already controls: the identity provider, the work email account and any second owner or billing role. If those fail, ask the vendor to transfer ownership, backed by domain and billing proof. Then adopt a two-admin rule so one departure cannot lock you out again.
Key takeaways
- Start recovery with what the company controls: single sign-on, the work mailbox and billing contacts.
- Vendors typically reassign ownership after some mix of domain proof, payment proof and a letter from an officer.
- Get written HR or legal approval before using a former employee's company account, and log every step.
- Keep the subscription paid while access is recovered, or suspension may cut off exports.
- Every tool that holds company records needs at least two current employees as admins.
Why is a missing admin an urgent problem?#
A missing admin is urgent because the admin is usually the only person who can export data, manage users, change billing and act on vendor notices. Without one, the company keeps paying for the tool but cannot fully control it.
The risk grows when the departed admin signed up with a personal email, put billing on a personal card, or left the vendor sending renewal and security notices to a mailbox nobody reads. A failed payment or a missed notice can lead to suspension, and suspension can switch off exports at exactly the wrong moment.
Ordinary users rarely notice the gap. Tickets still get answered and deals still get logged, so the problem surfaces only when someone needs a new user added, a report exported or a contract renewed.
First, check what the company already controls#
The fastest recovery uses access the company already holds. Work through these checks before contacting the vendor, because each one can spare a long exchange with vendor support.
- Identity provider: if the tool uses single sign-on through Microsoft Entra ID, Google Workspace or Okta, an identity admin may be able to grant the app's admin role or restore the departed user's company account under policy.
- Work email: if the admin signed up with a company address, IT can often restore that mailbox and use the tool's normal password reset, with written approval.
- Other roles: look for a billing owner, a secondary owner, or an admin on a related product under the same vendor account.
- Billing records: find invoices, the contract or order form, the paying entity and the payment method.
- Vendor contacts: find the account manager or customer success contact named in past emails.
Get written approval before touching a former employee's account#
Written approval from HR or legal comes before anyone opens a former employee's mailbox or account. Internal policy, employment terms and privacy rules may limit who can do it and for what purpose, so the sign-off should name the tool, the reason and the person doing the recovery.
Keep a short log of what was done and when: mailbox restored, password reset, admin role reassigned, mailbox closed again. Avoid reading unrelated mail. The log protects the company if the access is questioned later and doubles as evidence for the vendor if a formal recovery is still needed.
How does vendor ownership recovery work?#
Vendor ownership recovery is a support process in which the vendor checks that you represent the customer and then reassigns the owner or admin role. Most established SaaS vendors publish a procedure, though the steps and the proof they accept differ.
Send the request from a company address, include the account identifiers, and ask for written confirmation once ownership changes. Response times vary, so start at once rather than waiting until the renewal or an export deadline is close.
| Proof | Examples | What it shows the vendor |
|---|---|---|
| Domain control | Adding a DNS record the vendor specifies, or receiving mail at the company domain | You control the company's email domain |
| Payment | Recent invoice, order form, payment details the vendor can match | You are the paying customer |
| Authority | Letter on company letterhead signed by an officer, naming the new admin | The requester can act for the company |
| Identity | A verification call or ID check, if the vendor requires one | The new admin is who they claim to be |
| Account details | Workspace or tenant name, account ID, original sign-up email | Which account is yours |
What if the account was set up on a personal email?#
A tool registered to a former employee's personal email is the hardest case, because the company cannot reset the password or receive the vendor's messages. Recovery then depends on payment records, the contract and the vendor's willingness to treat the company as the customer.
Ask the former employee first, politely and in writing, to add a company admin or transfer ownership. Many departures are friendly, and this is often the quickest path. If that fails, use the vendor's ownership process backed by invoices the company paid. Employment agreements and IP assignment terms may also help show the account belongs to the company, which counsel can confirm.
Illustrative: an HVAC contractor recovers its field service account#
Illustrative: a fictional HVAC contractor's office manager leaves after many years. Weeks later the team finds she was the only admin of the field service platform that holds every estimate, job, invoice and maintenance agreement. Technicians can still close jobs, but nobody can add a user, change the price book or export job history.
The platform does not use single sign-on, and her company mailbox was deleted rather than suspended when she left, so a password reset is not possible. The COO opens the vendor's ownership transfer process instead: the company adds the DNS record the vendor specifies, sends recent invoices paid from the company account and a letter signed by the president naming two new admins, and keeps the subscription paid while the request is reviewed.
Once ownership moves, the new admins export job history with notes and photos, move the billing contact to a shared finance inbox and record the tool in a system register. The same review finds several other tools with a single admin, and each is fixed before anyone else leaves.
How does a two-admin rule prevent the next lockout?#
A two-admin rule means every tool holding company records has at least two current employees with full admin rights, ideally from different teams. It usually costs little, at most an extra seat on some plans, and removes the single point of failure behind this kind of lockout.
The system register is the piece many companies lack. It turns offboarding from guesswork into a checklist, and it is the same list you need for renewals, audits and any review of which records the company holds.
- Two admins who are current employees on every important tool.
- Owner and admin roles tied to company email and, where offered, single sign-on.
- Billing on a company card or invoice, with a shared finance inbox as the billing contact.
- A system register listing each tool, its admins, billing owner, renewal date and export method.
- Admin access reviewed in every offboarding, before the departing person's last day.
- Multi-factor recovery methods held by the company, not only on a personal phone.
- Departing users' accounts suspended rather than deleted until their admin roles and files are moved, since deleted accounts may be recoverable only for a short time.
Where SourceX fits once access is back#
Recovering admin access is often when a company realizes it does not know what its tools hold. A SourceX fit check works from the same system register: system names, years of history and record families, with no files shared at that stage.
If a tool's records later move toward a license, the Approval step of the SourceX five-step transaction depends on knowing who can authorize release for the company, and the SourceX Evidence Packet records that release authorization. Clear admin ownership and clear signing authority are related problems, and fixing one tends to help with the other.
Frequently asked questions
Can we just sign in with the former employee's password?
Only with written approval, a documented reason and through company-controlled accounts. Using credentials someone left behind, or guessing them, can breach internal policy and the vendor's terms. A controlled reset of a company mailbox or a formal vendor recovery leaves a much clearer record.
What if the vendor refuses to transfer ownership?
Ask for the refusal and the requirements in writing, then supply what is missing, such as an officer's letter or payment proof. Escalate through your account manager. If the tool holds important records, counsel can review the contract and your rights to the data while you keep the subscription active.
Should we cancel the tool instead of recovering it?
Not before its records are exported. Canceling without admin access usually means losing the ability to export, and the contract may give no later window. Recover access, export and verify the records, and only then decide whether to keep or cancel the tool.
Does single sign-on solve the problem by itself?
It helps but does not settle it. Single sign-on controls who can sign in, while admin roles and billing ownership are often set inside each tool. A departed admin's account may be disabled correctly while the tool has no other admin left, so check roles inside each app too.
Who should be the second admin on a tool?
Someone who uses or oversees the tool regularly and is unlikely to leave at the same time as the first admin, ideally from a different team. For finance and HR systems, pick someone with a legitimate need to see the data, and record both names in the system register.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.