The integrator left in March. Their IAM role still lists full read access across three storage buckets holding seismic and personnel records. No one revoked it because the exit checklist only required the final invoice to be marked paid.
Delivery teams created the role during a six-week migration sprint. The brief was simple: move the legacy files without breaking daily reporting. Broad permissions let the vendor finish on time and the milestone dashboard turned green.
Six months later the same role still authenticates from the old corporate network range. Audit logs show occasional use from an IP block the integrator once owned. Residency controls only checked bucket location, not who could reach them.
Your security lead flagged the exposure in the July review. The response was that re-provisioning the access would delay an unrelated compliance export. The export never happened, yet the role stayed live.
Procurement records show the integrator contract contained a 30-day access sunset clause. No one mapped that clause to the actual IAM objects because the handover document only listed user accounts, not machine identities.
The next vendor now inherits the same wide role because the current integration work needs similar file movement. Scope creep turns permanent access into the path of least resistance.
Fixing this requires the security team to own the revocation step before any milestone payment is released. Until that changes, every departed vendor leaves an invisible trust boundary behind.