Glossary
Offboarding
Removing every access a departing person held, which is harder than it sounds because nothing reports the accounts that were missed.
In plain terms
Collecting the keys back on the last day. The difficulty is not the collecting, it is knowing how many keys were cut, because they were issued over several years by different people for different reasons and nobody kept a single list.
Why it matters
Because it is the one moment when the whole of somebody's access is supposed to be dealt with at once, and it is handled by whoever remembers what to do. Systems with a cost attached get remembered because finance notices; free tools do not, and the free tools are where a great deal of company material now lives. What is missed produces no error and no alert, so the failure is invisible from the inside.
How it works
The central systems are usually fine and are not the risk. Payroll, email and anything with a per-seat charge are removed reliably, because the charge itself is a reminder and somebody is watching the invoice. Those are the accounts people picture when they think about this, which is part of why the rest goes unnoticed.
What escapes is anything adopted outside a process. A tool somebody signed up for with a work address, a personal plan used for work, a connector authorised once during a project: none of them appears on a checklist because nothing put them there, and the person who could have named them has left.
Removing the sign-in route is not the same as removing the account, and this is the commonest half-completed version. A central identity system can be switched off while the account continues to exist, along with any direct password set before the central route was introduced and any material stored inside it.
Tokens and connections outlive people particularly well. An automation authorised under somebody's account keeps running after they leave, because it holds its own credential and nothing about their departure touches it. The workflow continues to work, which is exactly why nobody investigates it.
Material taken before departure is outside this entirely. Exports, downloads and forwarded documents happened while access was legitimate, and no removal reaches them, which is why the timing of the removal matters more than its thoroughness in a contested departure.
What the last day actually reaches
Seen in the wild
Finding an assistant account signed up for with a work address that never appeared on any leaver checklist.
ChatGPTAn automation still running under a departed employee's authorisation because it holds its own credential.
MakeA search deployment where the sign-in route was removed and the account itself was left in place.
Glean
Common misconceptions
People assume
Disabling the central account covers it.
In fact
It covers everything that account was the route into. Tools signed up for directly, connections holding their own credentials and any password set before the central route existed are all untouched, and none of them reports itself.
People assume
A checklist solves it.
In fact
A checklist covers what somebody knew about when they wrote it. The accounts that matter are the ones adopted without a process, which is precisely why they are not on it, and each departure adds more of them than it removes.
Questions
- What is usually missed?
- Anything free and anything adopted directly by the person. Paid systems are removed because the charge is a reminder and finance is watching, so what survives is the tool somebody signed up for during a project, a personal plan used for work, and any connector authorised once and forgotten.
- How does this differ from a periodic access review?
- This is an event and the review is a sweep. The event handles what is known at the moment somebody leaves; the review is what eventually catches what the event missed. Relying on the review alone means accepting a gap of however long the cycle is.
- Do automations stop when their owner leaves?
- Usually not, because they hold their own stored credentials rather than borrowing the person's session. The workflow keeps running normally, which is why nobody looks at it, and it continues to reach whatever it was authorised to reach on the day it was set up.
Key takeaways
- Paid systems are removed reliably because the invoice is the reminder.
- Free and self-adopted tools are what survive a departure.
- Removing the sign-in route leaves the account and its contents in place.
- Automations keep running: they hold their own credentials.
Last checked August 2026