Offboarding is cheap to do properly and expensive to get wrong, which is why auditors sample it in almost every engagement. The failure is rarely the identity provider — it is everything that sits outside it.
Before the last day
- HR triggers the process, not word of mouth. If IT hears about departures informally, the control depends on someone remembering.
- Confirm the departure type — voluntary or involuntary — because the timeline and sequence differ.
- Identify data and processes only this person holds, and hand them over while they are still willing to help.
- Transfer ownership of documents, calendars, service accounts, code repositories and vendor relationships.
- Identify shared credentials they know, ready for rotation.
Access revocation
- Identity provider account disabled to your stated timeline — same day is the common standard, and your own policy is what you are measured against.
- Disable before delete. Deletion destroys audit trails and orphans owned resources. Disable, transfer ownership, then delete on a retention schedule.
- Revoke active sessions and refresh tokens — disabling an account does not always terminate what is already signed in.
- Systems outside SSO, which is where leaver findings concentrate: legacy internal applications, tools bought on a departmental card, vendor portals, and anything with a local account.
- VPN and remote access, including certificates.
- API keys and personal access tokens they created — these outlive the account and are a routine finding.
- Cloud console access and any IAM users tied to them.
- Privileged and administrative accounts, checked explicitly rather than assumed to be covered.
- Physical access — badges, door codes, parking, and any site with a separate system.
- MFA devices deregistered.
- Mailing lists, shared inboxes and delegated mailbox access.
Rotate every shared credential the person knew. This is the strongest practical argument against having shared accounts at all — each one turns a routine departure into a rotation exercise.
Evidence offboarding without chasing it
GRC Copilot pulls entitlements from connected systems, flags accounts that should have been revoked, and files the evidence auditors sample.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Assets
- Laptop, phone, tokens, external drives, and anything held at home — a per-person asset list makes this verifiable rather than a guess.
- Confirm device encryption status before wipe, and follow your data retention rules on the contents.
- Documents and physical records.
- Company cards and subscriptions in their name.
Involuntary departures
Handle differently and decide the protocol in advance, not on the day. Revoke access before or during the conversation, not after. Agree beforehand who coordinates HR, security and the line manager, and how to handle the elevated risk of data exfiltration in the period leading up to it if the departure was anticipated. This is the highest-risk scenario in the whole process and the one most often improvised.
Confirm and evidence
- An exit briefing reminding the individual of obligations that survive termination — confidentiality above all. It deters, and it evidences notice.
- A completed checklist with dates and the name of who performed each step.
- Reconcile the HR leaver list against active accounts periodically. This single test finds what a policy review never will, and it is exactly what an auditor runs.
Non-employees
Contractors, consultants and temporary staff frequently sit outside the HR system, so no leaver event ever fires for them. Set an expiry date at account creation tied to the contract end, and give every service account a named human owner whose own departure triggers a review.
Frequently asked questions
How fast must access be revoked?
Same day is the common expectation, immediately for involuntary departures. Whatever your policy states becomes your audit standard, so state something achievable.
Why disable rather than delete?
Deletion can destroy audit trails and orphan owned files and calendars. Disable, transfer, then delete per retention policy.
What is most commonly missed?
Systems outside SSO, API keys the person created, and shared credentials they knew.
How do we prove it happened?
A dated, completed checklist per leaver plus a periodic reconciliation of HR leavers against active accounts.
Key takeaways
- HR must trigger the process, or it depends on memory.
- Disable before delete, and kill active sessions and tokens.
- The gaps are outside SSO — local accounts, API keys, shared credentials.
- Reconcile leavers against active accounts before your auditor does.