Loading...
Compliance

Access revoked the moment a departure is filed

An offboarding improvement plan that tracks whether departing workers lose system access by their last working day, so teams can replace email handoffs with measurable, timely deprovisioning.

Trusted by frontline teams 15 years of frontline software

Built for: Technology And Saas · Financial Services · Healthcare Organizations · Professional Services · Manufacturing

Overview

Access revoked the moment a departure is filed is an operational improvement plan for measuring and improving offboarding deprovisioning. It centers on one outcome: the percentage of departures where access is revoked by the worker’s last working day. The template sets a 30-day measurement window and a suggested target change, giving HR, IT, identity-access, security, and compliance teams a shared way to evaluate whether the process is working.

Use it when departures are communicated by email, tasks are split across teams, or leaders cannot reliably tell which accounts remained active after a worker left. It is especially useful when the organization needs to connect the departure event to assigned actions, completion timestamps, and exception review. The pattern can cover employees, contractors, interns, and other workforce identities if their scope is defined before measurement.

This plan is not a complete identity-governance program, access review, incident-response process, or inventory of every application. It should not be used as the sole control for emergency termination decisions, privileged-access monitoring, or legal hold requirements. Configure the workflow with your HR and security teams, then validate the result against identity-provider, directory, endpoint, VPN, SaaS, and privileged-account records. The measured receipt exists only after your tenant runs the plan; the template does not claim a customer outcome.

Standards & compliance context

  • This plan supports general access-control and workforce termination controls found in security frameworks such as SOC 2 and ISO 27001, but it does not by itself demonstrate compliance.
  • Organizations subject to privacy, healthcare, financial, or contractual security requirements should map the workflow and evidence fields to their applicable control library.
  • Use documented approval and exception handling for delayed revocation, emergency departures, legal holds, and accounts that cannot be disabled immediately.
  • Retain timestamps and review records according to the organization’s audit, privacy, and records-retention policies.

General regulatory context for orientation only — verify current requirements with counsel or the relevant agency before relying on this template for compliance.

How to use this template

  1. 1. Define the departure population, last-working-day rule, systems in scope, accountable owners, and evidence required for a successful revocation.
  2. 2. Connect or configure the departure intake so each filed departure creates assigned deprovisioning tasks rather than relying on an untracked email.
  3. 3. Record the departure timestamp, last working day, revocation timestamp, worker type, and exception reason for every included case.
  4. 4. Review identity-provider, directory, endpoint, VPN, SaaS, privileged-account, and physical-access records to confirm that checklist completion matches actual revocation.
  5. 5. Calculate the access-revoked-by-last-day rate for the 30-day window, compare it with the baseline, and investigate every missed deadline.
  6. 6. Correct the workflow, ownership, integrations, or escalation path, then repeat the measurement to confirm that the improvement holds.

Best practices

  • Capture the exact last working date and time, including time zone, because a date-only field can hide late revocation.
  • Separate scheduled departures from involuntary departures and define the required revocation timing for each class.
  • Use a system-generated departure event as the trigger and keep email as a notification rather than the control record.
  • Require timestamped evidence from the identity provider or application owner instead of accepting an unchecked completion box.
  • Include contractors, temporary workers, shared accounts, service accounts, and privileged identities only when their ownership and treatment are explicitly defined.
  • Review missed deadlines individually and classify the cause as late notice, unclear ownership, integration failure, incomplete inventory, or exception.
  • Recheck the metric after rollout so an early improvement is not mistaken for a sustained change.
  • Restrict departure details and access records to people who need them, especially for involuntary or sensitive exits.

What this template typically catches

Issues teams running this template most often surface in practice:

Departures are filed by email but no owner is clearly accountable for completing revocation.
The identity provider is disabled while an application, VPN, privileged account, or shared credential remains active.
A checklist is marked complete without timestamped evidence from the relevant access system.
The recorded last working date is wrong, ambiguous, or missing a time zone, making the rate appear better than it is.
Seasonal hiring, acquisitions, or contractor cycles change the departure mix and make an unadjusted comparison misleading.
An initial improvement is not re-checked after go-live, so the rate drifts back as volume or staffing changes.
Exceptions are handled informally and excluded from the metric, hiding the cases with the greatest access risk.

Common use cases

HR and identity teams at a SaaS company
HR files a structured departure event that assigns identity, endpoint, VPN, and application tasks to named owners. The team reviews the 30-day access-revoked-by-last-day rate and traces misses to integration or ownership gaps.
Security-led urgent termination workflow
Security and HR define a separate urgent-departure path with immediate access revocation and documented escalation. The plan preserves the same evidence and review discipline while distinguishing urgent cases from scheduled exits.
Healthcare contractor offboarding
A healthcare organization includes employees, agency workers, and contractors in the scope after defining which clinical, administrative, remote-access, and physical systems each group uses. Compliance reviewers inspect exceptions and evidence without placing unnecessary departure details in broad notifications.
Financial services audit preparation
An access-governance owner uses the plan to replace informal termination emails with assigned tasks and timestamped records. Before an audit, the team samples departures against identity and application logs rather than relying solely on workflow status.

Frequently asked questions

What does this offboarding plan measure?

It measures the rate of departures where access is revoked by the worker’s last working day. The template uses a 30-day measurement window and focuses on the change from informal email handoffs to a tracked departure process. It does not replace an organization’s access inventory or identity-provider logs.

Who should run this plan?

HR or People Operations should file the departure, while the IT or identity-access team owns deprovisioning and evidence collection. Security or compliance leaders should review the result and investigate exceptions. Assign one accountable owner so a departure cannot stall between departments.

How often should the metric be reviewed?

Use the 30-day window in this template for the initial baseline and first review. After rollout, review the rate at least monthly and inspect every missed deadline individually. Shorter reviews may be appropriate for high-turnover teams or systems with elevated access risk.

Does this satisfy offboarding compliance requirements?

It supports general access-control, workforce termination, and audit-readiness practices by creating a measurable deadline for deprovisioning. The applicable requirements depend on your industry, contracts, systems, and jurisdictions, including standards such as SOC 2, ISO 27001, and sector-specific privacy or security rules. Have your compliance or legal team map the workflow to your formal control requirements.

What is the most common pitfall when using this template?

A team may mark a task complete without checking the actual identity provider, SaaS application, VPN, privileged account, or shared credential. Another pitfall is measuring only whether IT received notice rather than whether access was revoked by the last working day. Require evidence and record exceptions instead of treating a completed checklist as proof.

Can I customize the plan for contractors and different departure types?

Yes. Add worker type, departure reason, risk level, last working time, required systems, and whether the departure is voluntary or involuntary. Involuntary departures may require immediate revocation, while scheduled departures can use a timed workflow, but both should remain visible in the same review process.

Can this connect to HR, identity, and ticketing systems?

Customize the workflow around your HRIS, identity provider, directory, endpoint-management platform, and service desk. The important handoff is a structured departure event that creates assigned tasks and records timestamps. Validate that integrations carry the correct last working time and do not expose confidential departure details to unnecessary recipients.

How does this compare with emailing IT about a departure?

Email depends on a person noticing the message, interpreting the deadline, and remembering every account to disable. This plan turns the departure into an assigned, reviewable process with a defined metric and measurement window. Email can remain a notification channel, but it should not be the only control or the system of record.

How should we roll this out without disrupting departures?

Start with one department or departure type, establish the current rate, and run the workflow alongside the existing process for a short validation period. Reconcile completed tasks against identity and application records before expanding. Then set the target change, train HR and IT owners, and review missed deadlines in the first 30-day cycle.

Go deeper on the topic

Related concepts
  • AI governance is the framework a company uses to decide what AI tools are allowed to do, who's accountable for their outputs, what data they're allowed to...
  • Compliance is the practice of ensuring employee behavior meets regulatory, contractual, and internal-policy requirements — and of producing the evidence to...
  • Compliance training automation is the software-driven process for assigning, tracking, and evidencing required training (HIPAA, harassment prevention,...
  • HR case management is a structured system for handling employee questions, requests, and issues — with routing, SLAs, an audit trail, and a knowledge base...

Ready to use this template?

Get started with MangoApps and use Access revoked the moment a departure is filed with your team — pricing built for small business.

Get Started