The organisation may be unable to stop the person from using live systems, sharing information, or even broadcasting internal events before access is removed. That delay turns offboarding into an operational and reputational incident. A controlled handover should pair device return, access revocation, and reuse checks so the business can move cleanly into the next employee lifecycle stage.
When access still exists on the last day, what actually fails?
The failure is usually not technical first, it is operational. The organisation is still relying on a person who can act with live access after the employment relationship has effectively ended, so the risk is not just misuse of systems but also delayed handover, incomplete inventory recovery, and uncertainty about who still holds authority to act.
That is why late deprovisioning is treated as an offboarding control problem, not just an HR timing issue. Once access remains active, the organisation has to assume the person can continue to read data, change records, send messages, and reach shared services until revocation is complete.
Why the last-day gap becomes an incident condition
The last day is where offboarding and access governance collide. If the organisation cannot remove access promptly, the departing employee can continue to use credentials, sessions, devices, or remote access paths that were legitimate a few hours earlier but are no longer appropriate.
This matters because the gap widens the blast radius of any disagreement, mistake, or resentment at departure. Even without malicious intent, a lingering account can create confidentiality exposure, unauthorised transactions, or continuity problems if the person still appears able to operate inside active systems.
What good offboarding has to synchronise
Effective offboarding brings together three actions that should happen as one controlled sequence: access revocation, device return, and reuse checks. Access revocation removes the ability to act; device return recovers company assets and any remaining trust anchors; reuse checks make sure the same credentials or identifiers are not still active elsewhere.
For shared or privileged access paths, the key question is whether any live system still trusts the departing user after their final working hour. If the answer is yes, the offboarding process is incomplete, even if the employee has already handed in a badge or left the building.
Risk and Threat Considerations
Late removal of access creates a short window in which a former employee may still read sensitive information, alter records, or misuse shared tools after the organisation believes the relationship has ended. The same gap can also be exploited opportunistically if sessions, tokens, or remote access remain valid.
Failure mechanism: A delay between exit and deprovisioning leaves active permissions, sessions, or device trust in place, so the departing user can continue to act through legitimate access paths.
Impact: Confidentiality loss, unauthorised changes, audit ambiguity, and reputational harm can follow, especially if the person can still reach internal communications or operational systems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Departing-employee access is an account lifecycle issue that CIS account controls directly address. |
| Recommendation — Remove or disable accounts immediately at separation and verify no residual access paths remain. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | This question centers on timely revocation and lifecycle control of user access after employment ends. |
| IA-5 — Authenticator Management | Lingering credentials, tokens, or keys can preserve access after departure and must be managed. | |
| Recommendation — Disable or remove accounts at separation and confirm all delegated access is revoked. Revoke, rotate, or invalidate authenticators tied to the departing user. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access-rights removal on exit is a direct Annex A control concern for this scenario. |
| Recommendation — Revoke access rights promptly when employment or role changes end. | ||
| NIST CSF 2.0 | PR.AA-05 — Protective Technology, Identity and Access Management | The scenario depends on ensuring access is removed when no longer authorized. |
| Recommendation — Enforce timely deprovisioning and validate that access revocation takes effect across systems. | ||
Practitioner Guidance
What to prioritise: Treat the final working day as a control deadline, not a courtesy target. The highest priority is removing live access that can still reach production data, shared communications, and administrative functions before the person leaves supervision.
What to verify: Confirm that the deprovisioning event is not just an account disablement in one directory. Verify active sessions, remote access, application logins, mobile device trust, and any shared or delegated credentials that could preserve access after exit.
Practitioner takeaway: Offboarding is complete only when the former employee can no longer authenticate, reuse trust, or act through residual access in any business-critical system.
Related resources from NHI Mgmt Group
- What happens when a former employee still has admin access in a SaaS application?
- What happens when a departing employee or compromised user keeps active access to cloud applications?
- What happens when a departing employee or contractor has already been trusted with access and credentials?
- What happens when a departing employee retains API token or proxy-style access?