The fired engineer had an SSH key which no one knew about; hence no one revoked it. They had a leading IdP/SSO solution, but that solution wasn't connected to their db.
This got me thinking; at early stage, who is actually keeping track of all the keys, tokens, and credentials floating around? There's no IT, no security team, just founders and engineers barely taking care of their own tasks.
To every early stage founders, how are you tackling this today?