Offboarding gaps leave orphaned accounts and lingering access. Here's the security checklist, the JML framework, and the software that automates it.
Every IT leader has a version of this story. Months after a departure, someone discovers the former employee's Salesforce account is still active. Or their Google Drive is still syncing. Or a shared credential they knew is still in production. Nobody did anything malicious - the offboarding checklist just never caught up with the reality of a few hundred SaaS applications.
The numbers back up the anecdotes. In a Nudge Security survey of 375 US IT professionals, half of respondents admitted they personally still had access to a former employer's cloud or SaaS applications - a quarter of them at multiple past employers. The same survey found IT teams spend roughly five hours per departing employee identifying and deprovisioning cloud access, and 69% have to consult three or more different sources just to figure out what the person could touch.
That is what makes offboarding the most security-critical workflow IT owns, and why employee offboarding software has moved from "nice to have" to a line item in security programs. This article covers the risk, the joiner-mover-leaver framework that puts offboarding in context, the checklist itself, and how to automate it.
Offboarding is a security problem, not a paperwork problem
HR treats offboarding as an administrative process: final paycheck, benefits, exit interview. For IT and security teams, it is an access revocation event - and every hour of delay is exposure.
The core risks:
- Orphaned accounts. Accounts that outlive their owner are unmonitored by design. Nobody notices anomalous logins on an account nobody is supposed to be using, which makes orphaned accounts attractive targets for credential stuffing and quiet persistence.
- Lingering access for the departed. Most former employees never touch their old accounts. Some do. Whether the motive is curiosity, convenience ("I just needed that one file"), or something worse, the organization carries the liability either way. Breaches are expensive: IBM's 2025 Cost of a Data Breach Report puts the global average at $4.44 million, and $10.22 million in the US - an all-time high.
- Slow detection. IBM's same report found breaches take an average of 241 days to identify and contain. An account that should not exist at all is exactly the kind of foothold that goes unnoticed for months.
- Non-human identities. Departing engineers leave behind API keys, service accounts, OAuth grants, and automations tied to their identity. OWASP's Non-Human Identities Top 10 for 2025 ranks improper offboarding as the number one NHI risk. When you disable the human account but the tokens keep working, you have deprovisioned the person and not the access.
- License and cost waste. Unrevoked seats are also money. Zylo's 2025 SaaS Management Index found organizations waste an average of $21 million annually on unused SaaS licenses. Departed employees' seats are a meaningful slice of that.
The uncomfortable finding in the Nudge Security data: 79% of IT teams felt confident in their offboarding process, yet 70% had experienced a security incident, business disruption, or wasted spend caused by ineffective offboarding. Confidence and coverage are not the same thing.
The joiner-mover-leaver framework
Offboarding is one third of the identity lifecycle, usually called joiner-mover-leaver (JML):
- Joiner: a new hire needs accounts, licenses, hardware, and access appropriate to their role on day one.
- Mover: an internal transfer needs new access granted and old access revoked. Movers are the silent failure mode - access accumulates over years of role changes because revocation is nobody's job.
- Leaver: everything the person can touch needs to be revoked, transferred, or recovered on a deadline.
The reason JML matters for offboarding specifically: you cannot revoke access you cannot enumerate. Organizations with disciplined joiner and mover processes - role-based access, a system of record for entitlements - can offboard in minutes because the blast radius is known. Organizations where access was granted ad hoc over five years discover the blast radius during the exit, one forgotten app at a time. That is where the "three or more sources" statistic comes from.
If you are building the joiner side too, we cover the full lifecycle in our guide to automating employee onboarding and offboarding.
The offboarding security checklist
Here is the checklist IT cannot skip, organized by system rather than by task, because that is how the work actually gets missed.
Identity and authentication
- Disable the identity provider account (Okta, Entra ID, Google Workspace) at the agreed hour - not "sometime that day."
- Revoke all active sessions and refresh tokens. Disabling the account does not always kill sessions already in flight.
- Remove the user from all groups, roles, and distribution lists.
- Revoke MFA devices and any registered passkeys.
- Reset or vault any shared credentials the person knew. If a password was shared, it is compromised the moment they leave.
SaaS applications
- Deprovision accounts in every connected app - including the ones not behind SSO. Shadow IT signed up with a work email is still corporate data.
- Revoke OAuth grants and third-party app authorizations tied to the user.
- Transfer ownership of documents, dashboards, scheduled reports, and shared drives before deletion, not after.
- Reclaim or downgrade the license so the seat stops billing.
Non-human identities
- Rotate API keys and tokens the person created or had access to.
- Reassign service accounts, cron jobs, CI/CD secrets, and automations owned by the departing identity.
- Check integration platforms (Zapier, Workato, custom webhooks) for flows running under their auth.
Devices and assets
- Recover the laptop, or trigger remote lock and wipe through MDM if recovery fails.
- Collect peripherals, security keys, badges, and any mobile devices.
- Update the asset record: status, custody, condition, and next assignment. If your asset inventory lives in spreadsheets, this step fails silently - see our review of the best IT asset management software for 2026.
Communications and knowledge
- Set mailbox delegation or forwarding per policy, with an expiry date.
- Transfer ownership of calendars, recurring meetings, and on-call rotations.
- Preserve anything under legal hold before touching the account.
The checklist is long, which is precisely the argument for software: a 30-item manual checklist executed under time pressure, across HR, IT, security, and the hiring manager, will miss items. The Nudge data says so.
Automating deprovisioning across SaaS
Modern employee offboarding software approaches the problem in three layers:
- Trigger. The workflow starts from the system of record - an HRIS termination event (Workday, BambooHR, HiBob) or a manager's request. No tickets typed by hand, no dependence on HR remembering to email IT.
- Orchestration. The platform fans out across identity provider, SaaS apps, MDM, and asset systems via API: disable, revoke, transfer, reclaim. Conditional logic handles the differences - a sales rep's offboarding touches different systems than an engineer's.
- Evidence. Every action is logged with a timestamp and an actor, producing the audit trail that SOC 2 and ISO 27001 auditors ask for when they sample terminated users against active accounts.
This is where agentic platforms change the economics. A traditional workflow tool executes the happy path; an AI agent can also handle the exceptions that used to become tickets - the manager asking to extend mailbox access, the request to transfer a Looker dashboard nobody anticipated, the device that never arrived back. Harmony runs these workflows natively in Slack and Microsoft Teams, resolving around 90% of the surrounding requests automatically, so offboarding becomes a monitored process rather than a scramble. It is one of the clearest applications of enterprise service management: HR triggers it, IT executes it, security audits it, and no department's part falls through the cracks.
Device recovery: the physical half of offboarding
Deprovisioning is instant; hardware is not. Remote and hybrid work made device recovery the slowest, most manual part of offboarding - shipping labels, reminders, and a laptop worth $2,000 sitting in a former employee's closet with corporate data on it.
A workable device recovery process looks like this: MDM lock on the termination date (data risk ends immediately, independent of shipping), an automated return kit or courier pickup triggered by the same offboarding workflow, escalation steps with defined timelines if the device does not come back, and an asset system that reconciles expected returns against actual receipts so unreturned devices surface as exceptions instead of surprises during the annual audit.
Employee offboarding software compared
Offboarding capability shows up in several tool categories. The right choice depends on whether you want offboarding as a feature or as part of a broader service management motion.
| Tool | Category | Offboarding strengths | Considerations |
|---|---|---|---|
| Harmony | Agentic ESM (IT, HR, and beyond) | HRIS-triggered workflows; AI agent deprovisions across SaaS, coordinates device recovery, and resolves exception requests in Slack/Teams; full audit trail | Best fit for teams consolidating service management, not just offboarding |
| ServiceNow | Enterprise ITSM/ITAM suite | Deep workflow engine and CMDB; strong for complex, regulated enterprises | Significant implementation and admin overhead; AI added onto legacy workflows |
| Okta Workflows | Identity automation | Excellent IdP-level deprovisioning and session revocation | Covers identity, not devices, tickets, or non-SSO shadow apps |
| Nudge Security | SaaS security / discovery | Discovers shadow SaaS and OAuth grants; offboarding playbooks | Discovery-first; pairs with, rather than replaces, a service platform |
| Rippling | HR/IT platform | Tight HRIS-to-device-and-app lifecycle for SMB and mid-market | Strongest when Rippling is also your HRIS |
| Freshservice | Mid-market ITSM | Approachable workflows and asset tracking | Offboarding depth depends on orchestration you build yourself |
FAQ
What is employee offboarding software?
It is software that automates the revocation side of the identity lifecycle: triggered by an HRIS termination event, it disables accounts, revokes sessions and OAuth grants, transfers data ownership, reclaims licenses, coordinates device recovery, and logs every step for audit. It replaces manual checklists spread across IT, HR, and security.
How fast should access be revoked when someone leaves?
Identity provider access and active sessions should be revoked at the moment of termination - same hour, not same week. Downstream SaaS deprovisioning and data transfer can follow a defined schedule (often 24-72 hours), but authentication must be cut immediately, especially for involuntary departures.
Why do orphaned accounts persist even at companies with SSO?
Because SSO never covers everything. Employees sign up for tools directly with work email, OAuth grants outlive the sessions that created them, and non-human identities - API keys, service accounts - are tied to people but not visible in the IdP. Surveyed IT teams needed three or more systems of record just to enumerate one person's access.
Is offboarding an IT process or an HR process?
Both, which is why it fails. HR owns the trigger and the employment logistics; IT and security own access, data, and devices. The fix is a shared, automated workflow with one system of record - the ESM model - rather than parallel checklists that assume the other team caught everything.
What should an offboarding audit trail include?
For each departure: the termination trigger and timestamp, every account disabled and when, sessions and tokens revoked, data ownership transfers, license reclamation, device recovery status, and any approved exceptions with their expiry. SOC 2 and ISO 27001 auditors sample terminated employees against active accounts; the trail should answer them without archaeology.
Close the gap before the next departure
Offboarding is the rare workflow where security, cost, and compliance all point at the same fix: automate the checklist, trigger it from the HRIS, and make the exceptions something an AI agent handles instead of a ticket queue. Harmony does exactly that - natively in Slack and Microsoft Teams, across IT and HR, with the audit trail built in.
See what your offboarding process looks like when ~90% of it runs itself. Book a Harmony demo at harmony.io.
