IT Glossary
IT offboarding removes every access a departing employee holds. Learn what the checklist misses and why the SaaS estate is always the hard part.
August 7, 2026
IT offboarding is the process of removing every access, account, license, and device a departing employee holds, at the moment their contract ends. It is the leaver stage of the identity lifecycle, and the only stage with a hard deadline: unlike onboarding, doing it late is a security incident rather than an inconvenience.
Disabling the directory account takes seconds and creates a false sense of completion. Every application not connected to the identity provider keeps working: the local login still authenticates, the OAuth grant still refreshes, the API token still calls. In a mid-market estate of 100 or more tools, the applications outside single sign-on are usually the majority, and they are exactly what a checklist written from memory misses.
A developer leaves on a Friday. His AD account is disabled at 17:00 and the ticket is closed. On Monday his personal access token is still pulling from a private repository, his Figma seat is still billed, and monitoring alerts still route to his address. None of it appeared on the checklist because none of it lived in the directory. Building offboarding from a live application inventory rather than a static list is what closes that gap, and it is what Corma automates across the estate.
Access should end at the contract end time, not the next business day. For involuntary departures, revocation is coordinated with the moment the person is informed.
OAuth grants and API tokens. They survive a disabled directory account and almost never appear on a manually written checklist.
HR triggers it with the departure date, IT executes it, and security verifies it. Evidence of completion is what auditors ask for under ISO 27001 and NIS2.
Disabled first, so data and ownership can be transferred, then deleted according to the retention policy. Immediate deletion destroys evidence and orphans shared content.