I don't see this as a vulnerability: how is Google supposed to know that a person has left the company? You let them know by deleting the account.
I don't know if Google is the best example here. Apple might be a better one:
1. User's work email is user@company.com
2. User creates Apple ID using their work email. Their Apple ID is user@example.com
3. User gets fired and their company email is deleted
4. User can still sign in to the SaaS apps using SIWA and their "company" Apple ID
It's worth noting that OAuth providers - like Apple - include information such as if they are authoratitive or not over a particular account.
The "About" button in the menu leads to a webpage that 404s. As another commenter has pointed out the correct URL is https://www.littleworkshop.fr/projects/keepout/