Common signs include former employees still appearing in SaaS audit logs, licenses remaining assigned after exit, shared passwords not being changed, and IT being unaware of all apps the person used. If the organisation cannot prove which systems were closed, ownership changed, and data recovered, offboarding is incomplete.
How to recognise a leaver process that is not actually removing access
The clearest symptom is residual presence. If a former employee still appears in SaaS audit trails, still holds active entitlements, or can continue using shared credentials after departure, the offboarding flow has not finished. A complete leaver process should remove access, transfer ownership, recover company data, and leave a provable audit trail that each step occurred.
Another sign is inconsistency between HR, IT, and application owners. When the organisation cannot name every application the leaver used, or no one can confirm who closed the account, the business is relying on memory instead of control.
Weak removal often shows up in lifecycle gaps rather than one obvious failure, so the real test is whether access disappears everywhere the person could authenticate or act.
What the strongest evidence of failed leaver access removal looks like
The strongest evidence is any state that should be impossible after exit but still exists. That includes active logins, lingering licenses, unrecovered files, still-assigned roles, retained admin paths, and shared passwords that were never changed. A partial offboarding record is not enough if the person could still reach data, systems, or collaborators through another route.
- Former-user activity still appears in application logs after the exit date.
- Entitlements remain assigned in one platform even though the HR event is closed.
- Service, shared, or delegated credentials were not rotated after departure.
- Ownership of accounts, files, or integrations was never reassigned.
- No one can prove which systems were reviewed, disabled, or recovered.
In practice, the failure is often hidden by good intentions: teams disable the primary account but miss secondary access paths, linked identities, or manually created access outside the formal process.
Why incomplete offboarding usually points to identity governance, not just HR delay
Leaver access removal is a governance problem because it depends on inventory, ownership, and revocation discipline. If the organisation lacks a reliable map of all applications and shared access, the leaver process cannot remove what it cannot see. That is why incomplete offboarding frequently tracks back to poor identity lifecycle management, not a single missed ticket.
For practitioners, the most useful question is whether revocation is being driven from a trusted authoritative source or from ad hoc follow-up. The latter tends to leave gaps in SaaS, file sharing, collaboration, and delegated access, especially where the person used more than one login path. NHIMG’s Joiner-Mover-Leaver (JML) Guide covers why the leaver step must revoke old-role access as well as the obvious account closure.
When access removal is failing, the organisation usually has a process shape but not a control result. The difference matters: a ticket being closed is not the same as proving the identity, credentials, and downstream permissions are gone.
Risk and Threat Considerations
Residual leaver access creates a standing opportunity for misuse, whether by the former employee, an insider with shared credentials, or an attacker who later obtains an abandoned credential. The main risk is not only unauthorized access, but also loss of visibility into who still has reach into SaaS data, business workflows, and shared assets.
Failure mechanism: Offboarding removes the visible account but leaves behind one or more usable access paths, such as shared passwords, unrotated tokens, unrevoked roles, or unmanaged SaaS entitlements.
Impact: Data can be read, changed, or exfiltrated after departure, ownership and accountability can be obscured, and the organisation may not know the full blast radius until an audit or incident exposes it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Leaver removal is an account lifecycle and access revocation problem. |
| Recommendation — Revoke dormant and departing-user access promptly and verify account ownership changes. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Failed leaver removal often leaves usable credentials, tokens, or shared secrets behind. |
| AC-2 — Account Management | Offboarding requires disabling, removing, and reviewing accounts across systems. | |
| Recommendation — Rotate or revoke authenticators and shared credentials when users leave. Disable departing-user accounts and confirm access is removed from every system. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Leaver access removal depends on managing identities through their lifecycle. |
| A.5.18 — Access rights | The question concerns whether access rights were actually withdrawn after exit. | |
| Recommendation — Ensure identities are created, changed, and removed under a controlled lifecycle. Review and revoke access rights when an employee or contractor leaves. | ||
Practitioner Guidance
What to verify: Treat leaver removal as complete only when you can prove closure across the full access path, not just the primary directory account. That proof should include SaaS audit evidence, entitlement removal, credential rotation where shared access existed, and ownership transfer for any account or integration the person used.
Decision rule: If you cannot show which systems the leaver could access on the day they left, assume the process is failing and prioritise discovery before arguing about whether any single account was disabled correctly. Missing inventory is itself a control failure.
Practitioner takeaway: A good leaver process is measured by what no longer works, and by what can be proven to have been removed. If the organisation cannot demonstrate that, the access removal control is not yet reliable.
Related resources from NHI Mgmt Group
- What signs show that Power BI access governance is failing?
- What is the difference between rotating a secret and revoking access?
- What are the signs that access review and deprovisioning processes are failing?
- What are the signs that Exchange Online PowerShell access is failing because of identity or session control issues?