Are there any concerns with removing a CloudSOC SySAdmin?
Before permanently deleting a SysAdmin user, disable the account for a designated grace period. A disabled account can be instantly restored if critical services fail, whereas a deleted account is irrecoverable.
Critical CloudSOC Dependencies
| Service Impacted | Risk & Verification | Resolution Steps |
| CASB Securlets | If the Securlet was activated using the SysAdmin's personal credentials rather than a dedicated service account. | Verify: Contact Support to confirm the activating user. Fix: Reactivate the Securlet using a service account with SysAdmin rights. |
| CloudSOC API Keys | API keys generated by a SysAdmin will be invalidated upon account deletion. | Verify: Check the "Last Used" date on API keys created by this user. Fix: Recreate necessary keys under a service account. |
| SpanVA Ownership | Note: Ownership is no longer required as of SpanVA .170 (Shipping early May 2026). | Verify and fix: Update SpanVA ownership in CloudSOC | Settings | SpanVA details |