· Nurul Aini
Pending invites that never expire are still open doors
An invite sitting in someone’s inbox after the project ended is an access path. Onboarding applications that cannot age invites leave that path open by default.
Invites are created in a rush at the start of onboarding. They are rarely cleaned up. A contractor, a partner, or a personal Gmail address remains able to join the tenant long after the checklist was marked complete.
We age the pending-invite table. Anything older than the policy window — and if there is no policy window, we use thirty days as a working assumption and say so — is listed. Accepted invites to non-customer domains are listed separately.
The control is unglamorous: expiry, domain allow-lists where the contract names them, and a weekly exception report for operations. None of that requires a new product. It requires the onboarding application to treat an invite as an access grant, which it is.
When we raise this on a file, we raise it as an admissions finding. It is not a “hygiene” comment. Hygiene comments get ignored. Open invites do not.