n8n lifecycle & offboarding security checks
Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.
On n8n, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the n8n connector needs.
Checks (4)
severity: low n8n Workflow Agent Stale fix difficulty: easy #
Review and deactivate or update stale workflows
- Open n8n > Workflows
- Review the workflow and determine if still needed
- Deactivate or delete as appropriate
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium n8n Workflow Agent Active Never Executed fix difficulty: easy #
Investigate active AI workflow that has never run
- Open n8n > Workflows > select the workflow
- Check if the trigger is properly configured
- Execute manually to verify or deactivate
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: medium n8n Workflow Agent Inactive Webhook fix difficulty: easy #
Remove or reactivate the inactive webhook workflow
- Open n8n > Workflows > select the workflow
- Either reactivate or delete the workflow
- The webhook endpoint is exposed while the workflow exists
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6
severity: high n8n Workflow Agent Orphaned Owner fix difficulty: easy #
Reassign the n8n workflow agent to an active owner
- Identify the workflow owner in n8n
- Transfer ownership to an active team member
Satisfies: NIS2 Directive NIS2-21.i.2 DORA (SaaS Security) DORA-9.6