IT Glossary
Deprovisioning removes user access when people leave or change roles. Learn the risks of poor deprovisioning, best practices, and how Corma automates it.
July 3, 2026
Deprovisioning is the process of removing a user's access to applications, systems, and data when they leave the organization or no longer need it. Timely deprovisioning prevents orphaned accounts, shrinks the attack surface, and is essential for compliance. When it is manual or incomplete, former employees and unused accounts keep access, which creates serious security and audit risks.
Manual and automated deprovisioning differ sharply. Manual deprovisioning takes hours to weeks, easily misses apps, leaves a patchy audit trail, and risks orphaned accounts. Automated deprovisioning works in near real time, covers every connected app, produces a complete and exportable audit trail, and leaves few risks when coverage is complete.
An employee leaves on a Friday. Their email is disabled, but a forgotten admin account in a niche analytics tool stays live for months, an orphaned account that fails the next audit and is a real breach risk. Automated deprovisioning revokes access across all apps the moment the leaver event fires, including the long-tail tools manual processes forget. It also recovers paid licenses, which ties offboarding directly to cost savings.
An active account that no longer has a legitimate owner, usually left behind after incomplete deprovisioning. It is a common audit failure and security risk.
Standards like ISO 27001 and SOC 2 expect access to be removed promptly when it is no longer needed, with evidence that it happened.
Revoking access also frees paid licenses for reassignment, which turns clean offboarding into direct software cost savings.