Offboarding that actually turns off every account
When HR records a termination date, the workflow schedules deprovisioning across your identity provider and the apps it does not cover, transfers ownership of files and accounts, opens the equipment return, and produces an audit record showing what was removed and when.
IT or security operations, triggered by HR
A termination or resignation is entered in the HRIS
01the problem and who owns it
Offboarding usually starts with an email from HR to IT and ends whenever someone remembers the last app. Single sign-on covers some tools, but shared logins, admin accounts, API keys, and apps outside SSO linger for months.
HR owns the date, IT owns the accounts, security owns the risk, and finance owns licenses still being paid for. An auditor asking for proof that a former employee lost access gets a spreadsheet nobody fully trusts.
02what the AI does, step by step
- Receive the termination eventThe HRIS sends the employee, last day, separation type, and manager. Involuntary separations are marked for immediate action at a time HR specifies, not end of day.
- Inventory the person's accessThe workflow lists accounts from the identity provider, SaaS management data, and direct app APIs, plus shared vault items, cloud console roles, and code repository memberships tied to that person.
- Revoke on scheduleAt the set time, the identity account is suspended, sessions are revoked, and SCIM-connected apps deprovision. Apps without SCIM get API calls or a ticket to their admin with a due time.
- Transfer ownershipDrive files, shared mailboxes, calendar events, CRM records, and scheduled jobs owned by the person are reassigned to the manager or a named successor.
- Recover equipment and licensesA return kit request goes out for laptops, devices are flagged in MDM for lock or wipe after return, and freed licenses are reported to finance.
- Verify and recordA final pass checks each system again and summarizes anything still active. A model reads the results and writes a plain-language exception list for IT.
03systems it connects to
- Identity provider. Okta, Microsoft Entra ID, or Google Workspace as the main switch.
- HRIS. Workday, BambooHR, Rippling, or similar as the source of separation events.
- Device management. Jamf, Microsoft Intune, or Kandji for lock, wipe, and inventory.
- Password vault and cloud consoles. 1Password or Bitwarden shared vaults, plus AWS, Google Cloud, or Azure roles.
04human checkpoints
- Timing for involuntary exits. HR confirms the exact cutoff moment before the workflow arms, so access is not cut before a conversation happens.
- Data and mailbox decisions. The manager approves who receives files and whether email forwards or bounces.
- Device wipe. IT confirms before any remote wipe, especially for personal devices enrolled in MDM.
05what to measure
- Time to full revocation. From last day to the final system closed, tracked per app.
- Orphaned accounts found. Active accounts tied to former employees in periodic access reviews.
- Manual tickets per offboarding. Apps still needing a human, a list to shrink by adding SCIM or API coverage.
- Recovered licenses and equipment. Returned devices and reclaimed seats per month.
06risks and guardrails
- Leaving access open. The biggest risk is an app the inventory missed. Run periodic access reviews against the HRIS roster regardless of the workflow.
- Cutting access too early. Premature revocation can disrupt a notice period or a legal hold. Keep litigation holds and retention rules in the decision path.
- Overprivileged automation. The workflow itself holds admin rights across many systems. Give it scoped service accounts, store credentials in a vault, and log every action it takes.
07build vs buy
If nearly every tool sits behind SSO with SCIM, your identity provider's lifecycle features, or a platform like Rippling, already do most of this. SaaS management tools can fill in discovery.
A custom workflow earns its place when you have many apps outside SSO, homegrown systems, shared credentials, or compliance requirements that demand a per-person audit record your current tools cannot produce.
08related playbooks
Browse every hr and recruiting playbook or the full library.
want this running in your business?
We can inventory where access really lives in your company and build a deprovisioning workflow that closes it on schedule and leaves an audit record behind.
See how we deliver it: ai workflow automation.
book a call drop your number