Orphaned Account Checker
For whoever is asked who owns every login

Paste your account export. See every account nobody owns.

Orphaned Account Checker reads your account export line by line for orphaned, dormant and unrotated accounts against ISO/IEC 27001, SOC 2, PCI DSS and CIS Controls, one inventory of every credential, each line read on owner, last rotation, last access review and last use. Paste your account export: people, service accounts, API keys and AI agent credentials. Every account whose owner has left or was never named comes back, with the dormant ones, the keys nobody rotated, service accounts anyone can log in to, shared logins and agent credentials nobody reviews, each with the clause an auditor will cite.

Check your own exportEight accounts free, no account needed. A published dictionary of 14 account types, 12 system classes and 220 export column names loads with the page; every check runs in your browser.

Paste an export, never a connection. Your directory's user export, your cloud platform's credential report or a spreadsheet: one line per account. Nothing connects to your systems and nothing leaves your browser until you save. Recognised secret patterns are removed; review the list before you save.

Never paste passwords, keys or tokens; the list needs names and dates only.

Masked names work. Replace account names and people with your own codes (E1042, SVC-07); every finding still works, and the staff list can use the same codes.

Every flag shows the rule that raised it and the column it read.

It never scores an account or a company, and never says an account is compliant, secure or safe to delete. A finding is a question for the account owner or the reviewer.

Specimen, 5 of 40 accountsan invented logistics company
HookAccountOwnerFindings
1adm-E1008
administrator or privileged person account
E1008
left
145
2svc-orders-api
service account
E1005
left
256
4svc-backup
service account
IT Operations (team mailbox)
team
357
–agent-claims-triage
ai agent credential
none named
no owner
31011
12breakglass-01
break-glass or emergency account
E1002
active
none raised

40 accounts, 11 nobody owns, 5 dormant, 4 privileged with a gap.

14 of 14 finding types raised, 40 of 40 accounts typed, 2 assumed from the name.

Two colleagues at a desk going through a list, one at a laptop, one writing on a clipboard
Walk into the access review with one named person against every login, and a question already written for each login that has none. It works from the export you already pull: no connector to approve, nothing to install, and the list never leaves your browser to get there.
01

Paste the export as it comes out

One account per row: account | type | system | owner at least, or the columns your export already carries (last logon, password last set, enabled, member of, MFA, last reviewed, ticket). Column names are matched against 220 names that directory, identity provider, cloud credential report and service account exports use.

02

Add the staff list, if you have it

One person per row: person | active or left | left on, masked or not. With it, owners who have left and a leaver's own enabled account become findings; without it, no owner is checked and the page says so.

03

Take the questions to the owners

Fourteen findings in a fixed order, from a leaver's enabled account to a secret pasted where a label belongs, each naming the accounts, the column that raised it, the clause from the regimes you tick, and the question for the account owner or the reviewer.

Header row with any of Account, Type, System, Owner, Enabled, Last used, Last changed, Created, Privileged or Member of, Interactive login, MFA, Stored in, Last reviewed, Approval, Notes. Tabs, pipes, commas or double spaces. A first line such as regimes: ISO/IEC 27001, SOC 2 | dormant after: 90 days | as at: 2026-09-28 sets the regimes, the periods and the date.
Nothing is sent anywhere until you choose to save.
Regimes that apply, and the periods you set

Why an export, and not a connector

A connector reads your directory live, and before anyone can use it a security review has to approve the access it asks for. The question the auditor, the board or the security manager asks first is simpler: across every login we have, people, service accounts, keys and agents, who owns each one, and which ones nobody does. The answer sits in the exports your team already pulls for the access review. That is what this reads, in your browser, from the export as it stands.

The dictionary is ours and published in full: the fourteen account types and who should own each, the twelve system classes, the fourteen findings with the rule each one applies, the clauses each regime attaches, what an orphaned account is, the rotation periods the standards set and the columns an access review template needs. It reads labels only, and a finding is a question for the account owner or the reviewer, never a ruling.