IT Glossary

IT Offboarding

IT offboarding removes every access a departing employee holds. Learn what the checklist misses and why the SaaS estate is always the hard part.

August 7, 2026

What is IT offboarding?

IT offboarding is the process of removing every access, account, license, and device a departing employee holds, at the moment their contract ends. It is the leaver stage of the identity lifecycle, and the only stage with a hard deadline: unlike onboarding, doing it late is a security incident rather than an inconvenience.

What complete IT offboarding covers

  • Disabling the directory account, which cuts federated access immediately.
  • Removing accounts in every application with its own login, federated or not.
  • Revoking OAuth grants, API keys, personal access tokens, and service account ownerships.
  • Transferring file ownership, shared drives, calendars, and mailbox delegation before deletion.
  • Reclaiming the licenses freed, and recovering the device and any hardware security key.

Why the SaaS estate is the hard part

Disabling the directory account takes seconds and creates a false sense of completion. Every application not connected to the identity provider keeps working: the local login still authenticates, the OAuth grant still refreshes, the API token still calls. In a mid-market estate of 100 or more tools, the applications outside single sign-on are usually the majority, and they are exactly what a checklist written from memory misses.

Examples and use cases

A developer leaves on a Friday. His AD account is disabled at 17:00 and the ticket is closed. On Monday his personal access token is still pulling from a private repository, his Figma seat is still billed, and monitoring alerts still route to his address. None of it appeared on the checklist because none of it lived in the directory. Building offboarding from a live application inventory rather than a static list is what closes that gap, and it is what Corma automates across the estate.

Related concepts

FAQ

How fast should IT offboarding happen?

Access should end at the contract end time, not the next business day. For involuntary departures, revocation is coordinated with the moment the person is informed.

What is the most commonly missed item in offboarding?

OAuth grants and API tokens. They survive a disabled directory account and almost never appear on a manually written checklist.

Who owns IT offboarding?

HR triggers it with the departure date, IT executes it, and security verifies it. Evidence of completion is what auditors ask for under ISO 27001 and NIS2.

Should accounts be deleted or disabled?

Disabled first, so data and ownership can be transferred, then deleted according to the retention policy. Immediate deletion destroys evidence and orphans shared content.

Request a demo