Access that outlives employment is one of the most common findings in security reviews. This checklist covers all three moments in the lifecycle. Print it, or adapt it to your ticketing system. The leaver section is the one that most often fails, so it is the most detailed.
Joiner: before day one
Mover: team or role change
Movers are where privilege piles up. The rule is simple: add what the new role needs, remove what the old role gave.
Leaver: before the last day
Leaver: on the last day
Leaver: the week after
Retention and records
Decide how long the account, mailbox and logs are kept, and who may access them. Check with your compliance counsel for obligations that apply to you, including under the DPDP Act 2023.
Exceptions
- Contractors: set an end date at the start and a sponsor who confirms the end.
- Sudden departures: use the same list, in order, starting with session revocation.
- Rehires: create fresh access; do not revive old group memberships.
About this runbook
With AuthMantra you can receive joiner, mover and leaver changes from your HR system over SCIM 2.0, provision and deprovision applications by outbound SCIM, see and revoke sessions, and export the audit log as evidence. The checklist above is the process around those tools.
authmantra.com/praxis/run/offboarding-checklist/ · info@authmantra.com