Paste your account export. See every account nobody owns.
Orphaned Account Checker reads your account export line by line for orphaned, dormant and unrotated accounts against ISO/IEC 27001, SOC 2, PCI DSS and CIS Controls, one inventory of every credential, each line read on owner, last rotation, last access review and last use. Paste your account export: people, service accounts, API keys and AI agent credentials. Every account whose owner has left or was never named comes back, with the dormant ones, the keys nobody rotated, service accounts anyone can log in to, shared logins and agent credentials nobody reviews, each with the clause an auditor will cite.
Paste an export, never a connection. Your directory's user export, your cloud platform's credential report or a spreadsheet: one line per account. Nothing connects to your systems and nothing leaves your browser until you save. Recognised secret patterns are removed; review the list before you save.
Never paste passwords, keys or tokens; the list needs names and dates only.
Masked names work. Replace account names and people with your own codes (E1042, SVC-07); every finding still works, and the staff list can use the same codes.
Every flag shows the rule that raised it and the column it read.
It never scores an account or a company, and never says an account is compliant, secure or safe to delete. A finding is a question for the account owner or the reviewer.
| Hook | Account | Owner | Findings |
|---|---|---|---|
| 1 | adm-E1008 administrator or privileged person account | E1008 left | 145 |
| 2 | svc-orders-api service account | E1005 left | 256 |
| 4 | svc-backup service account | IT Operations (team mailbox) team | 357 |
| – | agent-claims-triage ai agent credential | none named no owner | 31011 |
| 12 | breakglass-01 break-glass or emergency account | E1002 active | none raised |
40 accounts, 11 nobody owns, 5 dormant, 4 privileged with a gap.
14 of 14 finding types raised, 40 of 40 accounts typed, 2 assumed from the name.

Paste the export as it comes out
One account per row: account | type | system | owner at least, or the columns your export already carries (last logon, password last set, enabled, member of, MFA, last reviewed, ticket). Column names are matched against 220 names that directory, identity provider, cloud credential report and service account exports use.
Add the staff list, if you have it
One person per row: person | active or left | left on, masked or not. With it, owners who have left and a leaver's own enabled account become findings; without it, no owner is checked and the page says so.
Take the questions to the owners
Fourteen findings in a fixed order, from a leaver's enabled account to a secret pasted where a label belongs, each naming the accounts, the column that raised it, the clause from the regimes you tick, and the question for the account owner or the reviewer.
Why an export, and not a connector
A connector reads your directory live, and before anyone can use it a security review has to approve the access it asks for. The question the auditor, the board or the security manager asks first is simpler: across every login we have, people, service accounts, keys and agents, who owns each one, and which ones nobody does. The answer sits in the exports your team already pulls for the access review. That is what this reads, in your browser, from the export as it stands.