Skip to content

Glossary

Offboarding

Removing every access a departing person held, which is harder than it sounds because nothing reports the accounts that were missed.

In plain terms

Collecting the keys back on the last day. The difficulty is not the collecting, it is knowing how many keys were cut, because they were issued over several years by different people for different reasons and nobody kept a single list.

01

Why it matters

Because it is the one moment when the whole of somebody's access is supposed to be dealt with at once, and it is handled by whoever remembers what to do. Systems with a cost attached get remembered because finance notices; free tools do not, and the free tools are where a great deal of company material now lives. What is missed produces no error and no alert, so the failure is invisible from the inside.

02

How it works

The central systems are usually fine and are not the risk. Payroll, email and anything with a per-seat charge are removed reliably, because the charge itself is a reminder and somebody is watching the invoice. Those are the accounts people picture when they think about this, which is part of why the rest goes unnoticed.

What escapes is anything adopted outside a process. A tool somebody signed up for with a work address, a personal plan used for work, a connector authorised once during a project: none of them appears on a checklist because nothing put them there, and the person who could have named them has left.

Removing the sign-in route is not the same as removing the account, and this is the commonest half-completed version. A central identity system can be switched off while the account continues to exist, along with any direct password set before the central route was introduced and any material stored inside it.

Tokens and connections outlive people particularly well. An automation authorised under somebody's account keeps running after they leave, because it holds its own credential and nothing about their departure touches it. The workflow continues to work, which is exactly why nobody investigates it.

Material taken before departure is outside this entirely. Exports, downloads and forwarded documents happened while access was legitimate, and no removal reaches them, which is why the timing of the removal matters more than its thoroughness in a contested departure.

What the last day actually reaches

What the last day actually reachesThe reason the right-hand column survives is worth stating plainly, because it is not carelessness. Every item on the left has something external reminding somebody it exists: an invoice, a mailbox that bounces, a line on a form. Every item on the right was created by somebody solving an immediate problem, without a process, and its continued existence costs nothing and produces no signal. A checklist cannot fix this by being longer, because the entries that matter are precisely the ones nobody knew to write down, and each departure adds a few more that the next checklist also will not have. That is also why the AI category is over-represented on the right: assistants, search tools and automation platforms are frequently adopted by a team directly, and they reach further into company material than most of what was set up formally. The realistic posture is not a better checklist but accepting that the event will miss things and having something periodic that sweeps for them, which is a different control with a different cadence and is the one most organisations skip.Reliably removedPayroll and email.Anything with a per-seatcharge.Whatever is on the checklist.Usually still thereA free tool signed up fordirectly.A connector authorised during aproject.An automation holding its owncredential.The left column is what peoplepicture and it is handled well.The right column is what anorganisation accumulates, andnothing in it reports its ownexistence, so the gap isinvisible until somebody goeslooking.
The reason the right-hand column survives is worth stating plainly, because it is not carelessness. Every item on the left has something external reminding somebody it exists: an invoice, a mailbox that bounces, a line on a form. Every item on the right was created by somebody solving an immediate problem, without a process, and its continued existence costs nothing and produces no signal. A checklist cannot fix this by being longer, because the entries that matter are precisely the ones nobody knew to write down, and each departure adds a few more that the next checklist also will not have. That is also why the AI category is over-represented on the right: assistants, search tools and automation platforms are frequently adopted by a team directly, and they reach further into company material than most of what was set up formally. The realistic posture is not a better checklist but accepting that the event will miss things and having something periodic that sweeps for them, which is a different control with a different cadence and is the one most organisations skip.
03

Seen in the wild

  • Finding an assistant account signed up for with a work address that never appeared on any leaver checklist.

    ChatGPT
  • An automation still running under a departed employee's authorisation because it holds its own credential.

    Make
  • A search deployment where the sign-in route was removed and the account itself was left in place.

    Glean
04

Common misconceptions

People assume

Disabling the central account covers it.

In fact

It covers everything that account was the route into. Tools signed up for directly, connections holding their own credentials and any password set before the central route existed are all untouched, and none of them reports itself.

People assume

A checklist solves it.

In fact

A checklist covers what somebody knew about when they wrote it. The accounts that matter are the ones adopted without a process, which is precisely why they are not on it, and each departure adds more of them than it removes.

05

Questions

What is usually missed?
Anything free and anything adopted directly by the person. Paid systems are removed because the charge is a reminder and finance is watching, so what survives is the tool somebody signed up for during a project, a personal plan used for work, and any connector authorised once and forgotten.
How does this differ from a periodic access review?
This is an event and the review is a sweep. The event handles what is known at the moment somebody leaves; the review is what eventually catches what the event missed. Relying on the review alone means accepting a gap of however long the cycle is.
Do automations stop when their owner leaves?
Usually not, because they hold their own stored credentials rather than borrowing the person's session. The workflow keeps running normally, which is why nobody looks at it, and it continues to reach whatever it was authorised to reach on the day it was set up.
06

Key takeaways

  • Paid systems are removed reliably because the invoice is the reminder.
  • Free and self-adopted tools are what survive a departure.
  • Removing the sign-in route leaves the account and its contents in place.
  • Automations keep running: they hold their own credentials.
08

Tools that use this

  • ChatGPT

    Accounts signed up for with a work address, absent from any checklist.

  • Make

    Automations that keep running under a departed person's authorisation.

  • Glean

    Sign-in route removed while the account itself remains.

Last checked August 2026

All glossary terms