Offboarding is a security control, and it is usually the weakest one
Onboarding gets a checklist, an owner and a deadline. Departure gets an email. The access that survives a departure is the access nobody is watching.
Every organisation we assess has a documented onboarding process. Very few have an offboarding process that anyone can produce, and almost none can demonstrate that it was followed for the last ten people who left.
That asymmetry has an obvious cause. Onboarding fails loudly — a new starter without a login complains on day one. Offboarding fails silently, and the failure only becomes visible if somebody uses the access that was left behind.
What actually survives a departure
The account is usually disabled. The rest of it is where the exposure sits.
Sessions and tokens. Disabling an account does not always terminate active sessions. Refresh tokens can remain valid for hours or longer, so a mobile device that is already signed in may keep working after the account is gone. Session revocation is a separate action, and it is frequently not taken.
Application passwords and API keys. Anything issued to the person rather than to a role: integration credentials, personal access tokens, keys created for a project. These do not live in the directory and are not affected by disabling the account.
Shared and service accounts. The credentials the person knew. If a shared login was used, the departure changes nothing about who can use it, and nobody rotates it because nobody owns it.
Personal devices. On a BYOD device, the work container should be removed with the enrolment. It is worth verifying rather than assuming, and it is worth knowing what was in the device address book, which is the copy nobody thinks about.
Data already elsewhere. Files synced to a personal cloud, emails forwarded to a personal address, and documents downloaded before the notice period. Most of this is not malicious — it is a person tidying up their own work — and it is exposure either way.
Third-party services. Every SaaS product the person had a login to, most of which are not connected to your identity provider. The list is longer than IT thinks, because half of it was signed up for with a corporate card and no involvement from anyone.
Physical. Access cards, keys, hardware tokens, and the laptop that a manager said they would collect.
Why it fails
Nobody is told. The single most common cause. HR knows someone is leaving three weeks before IT does, or IT finds out from the all-staff email.
Nobody owns it end to end. HR owns the process, IT owns the accounts, the manager owns the equipment, and the handover between them has no deadline attached.
Involuntary departures move faster than the process. The termination that most needs immediate access removal is the one where the process has the least time to run, and where the decision to remove access is being made by people who are dealing with something else.
Contractors and volunteers are outside the process entirely. They frequently do not appear in the HR system that triggers offboarding, so nothing triggers.
What a working process looks like
One trigger, from HR, with a date. The system of record for people has to be the system that starts the process, and it has to fire on the last day, not on a notice being served.
A checklist with an owner per item and a completion record. Not a wiki page — a ticket with items that are closed individually, so that the record exists afterwards.
Session revocation as an explicit step. Disable the account, then revoke active sessions and refresh tokens. Two actions.
A same-day path for involuntary departures. Agreed in advance, with the authority to invoke it held by more than one person, and rehearsed at least once. This is the one where hesitation is most expensive.
Rotation for anything shared. Every shared credential the person knew, changed. If that is impractical, the real finding is the shared credential, not the departure.
Quarterly reconciliation. Compare active accounts against the current staff list. Every environment has orphans; the question is whether anyone is looking. This is also the check that catches the departures the process missed entirely.
Contractors and volunteers in scope, with an expiry. Access granted with an end date attached, so the default is expiry rather than persistence. This one change eliminates most of the long tail.
The measure that matters
Pick the last ten people who left and answer, from records: when was each account disabled, when were sessions revoked, when was the device returned or wiped, and which third-party services were removed.
If you cannot answer that from records, the process does not exist regardless of what the document says. It is a fast exercise and the result is usually a surprise.
More on our managed service and identity and workplace security.