Access revoked the moment a departure is filed
An offboarding improvement plan that tracks whether departing workers lose system access by their last working day, so teams can replace email handoffs with measurable, timely deprovisioning.
Trusted by frontline teams 15 years of frontline software
Built for: Technology And Saas · Financial Services · Healthcare Organizations · Professional Services · Manufacturing
Overview
Access revoked the moment a departure is filed is an operational improvement plan for measuring and improving offboarding deprovisioning. It centers on one outcome: the percentage of departures where access is revoked by the worker’s last working day. The template sets a 30-day measurement window and a suggested target change, giving HR, IT, identity-access, security, and compliance teams a shared way to evaluate whether the process is working.
Use it when departures are communicated by email, tasks are split across teams, or leaders cannot reliably tell which accounts remained active after a worker left. It is especially useful when the organization needs to connect the departure event to assigned actions, completion timestamps, and exception review. The pattern can cover employees, contractors, interns, and other workforce identities if their scope is defined before measurement.
This plan is not a complete identity-governance program, access review, incident-response process, or inventory of every application. It should not be used as the sole control for emergency termination decisions, privileged-access monitoring, or legal hold requirements. Configure the workflow with your HR and security teams, then validate the result against identity-provider, directory, endpoint, VPN, SaaS, and privileged-account records. The measured receipt exists only after your tenant runs the plan; the template does not claim a customer outcome.
Standards & compliance context
- This plan supports general access-control and workforce termination controls found in security frameworks such as SOC 2 and ISO 27001, but it does not by itself demonstrate compliance.
- Organizations subject to privacy, healthcare, financial, or contractual security requirements should map the workflow and evidence fields to their applicable control library.
- Use documented approval and exception handling for delayed revocation, emergency departures, legal holds, and accounts that cannot be disabled immediately.
- Retain timestamps and review records according to the organization’s audit, privacy, and records-retention policies.
General regulatory context for orientation only — verify current requirements with counsel or the relevant agency before relying on this template for compliance.
How to use this template
- 1. Define the departure population, last-working-day rule, systems in scope, accountable owners, and evidence required for a successful revocation.
- 2. Connect or configure the departure intake so each filed departure creates assigned deprovisioning tasks rather than relying on an untracked email.
- 3. Record the departure timestamp, last working day, revocation timestamp, worker type, and exception reason for every included case.
- 4. Review identity-provider, directory, endpoint, VPN, SaaS, privileged-account, and physical-access records to confirm that checklist completion matches actual revocation.
- 5. Calculate the access-revoked-by-last-day rate for the 30-day window, compare it with the baseline, and investigate every missed deadline.
- 6. Correct the workflow, ownership, integrations, or escalation path, then repeat the measurement to confirm that the improvement holds.
Best practices
- Capture the exact last working date and time, including time zone, because a date-only field can hide late revocation.
- Separate scheduled departures from involuntary departures and define the required revocation timing for each class.
- Use a system-generated departure event as the trigger and keep email as a notification rather than the control record.
- Require timestamped evidence from the identity provider or application owner instead of accepting an unchecked completion box.
- Include contractors, temporary workers, shared accounts, service accounts, and privileged identities only when their ownership and treatment are explicitly defined.
- Review missed deadlines individually and classify the cause as late notice, unclear ownership, integration failure, incomplete inventory, or exception.
- Recheck the metric after rollout so an early improvement is not mistaken for a sustained change.
- Restrict departure details and access records to people who need them, especially for involuntary or sensitive exits.
What this template typically catches
Issues teams running this template most often surface in practice:
Common use cases
Frequently asked questions
What does this offboarding plan measure?
It measures the rate of departures where access is revoked by the worker’s last working day. The template uses a 30-day measurement window and focuses on the change from informal email handoffs to a tracked departure process. It does not replace an organization’s access inventory or identity-provider logs.
Who should run this plan?
HR or People Operations should file the departure, while the IT or identity-access team owns deprovisioning and evidence collection. Security or compliance leaders should review the result and investigate exceptions. Assign one accountable owner so a departure cannot stall between departments.
How often should the metric be reviewed?
Use the 30-day window in this template for the initial baseline and first review. After rollout, review the rate at least monthly and inspect every missed deadline individually. Shorter reviews may be appropriate for high-turnover teams or systems with elevated access risk.
Does this satisfy offboarding compliance requirements?
It supports general access-control, workforce termination, and audit-readiness practices by creating a measurable deadline for deprovisioning. The applicable requirements depend on your industry, contracts, systems, and jurisdictions, including standards such as SOC 2, ISO 27001, and sector-specific privacy or security rules. Have your compliance or legal team map the workflow to your formal control requirements.
What is the most common pitfall when using this template?
A team may mark a task complete without checking the actual identity provider, SaaS application, VPN, privileged account, or shared credential. Another pitfall is measuring only whether IT received notice rather than whether access was revoked by the last working day. Require evidence and record exceptions instead of treating a completed checklist as proof.
Can I customize the plan for contractors and different departure types?
Yes. Add worker type, departure reason, risk level, last working time, required systems, and whether the departure is voluntary or involuntary. Involuntary departures may require immediate revocation, while scheduled departures can use a timed workflow, but both should remain visible in the same review process.
Can this connect to HR, identity, and ticketing systems?
Customize the workflow around your HRIS, identity provider, directory, endpoint-management platform, and service desk. The important handoff is a structured departure event that creates assigned tasks and records timestamps. Validate that integrations carry the correct last working time and do not expose confidential departure details to unnecessary recipients.
How does this compare with emailing IT about a departure?
Email depends on a person noticing the message, interpreting the deadline, and remembering every account to disable. This plan turns the departure into an assigned, reviewable process with a defined metric and measurement window. Email can remain a notification channel, but it should not be the only control or the system of record.
How should we roll this out without disrupting departures?
Start with one department or departure type, establish the current rate, and run the workflow alongside the existing process for a short validation period. Reconcile completed tasks against identity and application records before expanding. Then set the target change, train HR and IT owners, and review missed deadlines in the first 30-day cycle.
Related templates
Go deeper on the topic
-
AI governance is the framework a company uses to decide what AI tools are allowed to do, who's accountable for their outputs, what data they're allowed to...
-
Compliance is the practice of ensuring employee behavior meets regulatory, contractual, and internal-policy requirements — and of producing the evidence to...
-
Compliance training automation is the software-driven process for assigning, tracking, and evidencing required training (HIPAA, harassment prevention,...
-
HR case management is a structured system for handling employee questions, requests, and issues — with routing, SLAs, an audit trail, and a knowledge base...
Ready to use this template?
Get started with MangoApps and use Access revoked the moment a departure is filed with your team — pricing built for small business.