Scenario
User works for organisation A who is a customer of ours and is registered for our 'Private' ideas portal. They have been able to register as a user as they have an email address on the allowed domain list that we administer. User leaves organisation A and joins organisation B in a similar role in a similar industry. Organisation B uses a competitor product of ours.
Using a private portal we have no way of knowing that the user has left organisation A, and now has access to all of our ideas which they could communicate to our competitor or submit similar ideas.
Possible Solution
We need some way of forcing users to re-verify their email address every so often (maybe monthly). As long as organisation A has removed access to their inbox, they will not be able to verify and can in-turn be removed from the ideas portal.
I think this would be useful to all customers who want to use a private ideas portal, but does not have access to their customer's SSO to give that extra security layer.
Due to the low number of votes on this idea, we are unlikely to work on it in the near future.