insomnia.club back to site
[ playbook · hr and recruiting ]

Offboarding that actually turns off every account

When HR records a termination date, the workflow schedules deprovisioning across your identity provider and the apps it does not cover, transfers ownership of files and accounts, opens the equipment return, and produces an audit record showing what was removed and when.

who owns it

IT or security operations, triggered by HR

what starts it

A termination or resignation is entered in the HRIS

01the problem and who owns it

Offboarding usually starts with an email from HR to IT and ends whenever someone remembers the last app. Single sign-on covers some tools, but shared logins, admin accounts, API keys, and apps outside SSO linger for months.

HR owns the date, IT owns the accounts, security owns the risk, and finance owns licenses still being paid for. An auditor asking for proof that a former employee lost access gets a spreadsheet nobody fully trusts.

02what the AI does, step by step

  1. Receive the termination eventThe HRIS sends the employee, last day, separation type, and manager. Involuntary separations are marked for immediate action at a time HR specifies, not end of day.
  2. Inventory the person's accessThe workflow lists accounts from the identity provider, SaaS management data, and direct app APIs, plus shared vault items, cloud console roles, and code repository memberships tied to that person.
  3. Revoke on scheduleAt the set time, the identity account is suspended, sessions are revoked, and SCIM-connected apps deprovision. Apps without SCIM get API calls or a ticket to their admin with a due time.
  4. Transfer ownershipDrive files, shared mailboxes, calendar events, CRM records, and scheduled jobs owned by the person are reassigned to the manager or a named successor.
  5. Recover equipment and licensesA return kit request goes out for laptops, devices are flagged in MDM for lock or wipe after return, and freed licenses are reported to finance.
  6. Verify and recordA final pass checks each system again and summarizes anything still active. A model reads the results and writes a plain-language exception list for IT.

03systems it connects to

04human checkpoints

05what to measure

06risks and guardrails

07build vs buy

If nearly every tool sits behind SSO with SCIM, your identity provider's lifecycle features, or a platform like Rippling, already do most of this. SaaS management tools can fill in discovery.

A custom workflow earns its place when you have many apps outside SSO, homegrown systems, shared credentials, or compliance requirements that demand a per-person audit record your current tools cannot produce.

Browse every hr and recruiting playbook or the full library.

want this running in your business?

We can inventory where access really lives in your company and build a deprovisioning workflow that closes it on schedule and leaves an audit record behind.

See how we deliver it: ai workflow automation.

book a call drop your number

info@insomnia.club