By NHI Mgmt Group Editorial TeamBased on Zluri: “Employee Offboarding: 5 Security Guidelines for a Remote Workplace” (June 26, 2025)

TL;DR: Remote offboarding can leave former employees with lingering SaaS, CRM, email, and SSO access, creating avoidable exposure when deprovisioning is delayed or incomplete, according to Zluri and OneLogin. The governance gap is not the exit process itself but the failure to terminate access quickly enough across every identity system.


At a glance

What this is: This is an offboarding-focused security guide arguing that remote leavers remain a risk when SaaS, SSO, shared accounts, and phone systems are not deprovisioned together.

Why it matters: It matters because identity teams need a lifecycle process that removes access everywhere at once, not a disconnected checklist that leaves ex-employees with usable accounts and recoverable data.

By the numbers:

  • 32% of companies reported taking more than a week to deprovision employees from SaaS apps who have left.

Context

Remote employee offboarding is the controlled removal of access, accounts, data handover, and device ownership when someone leaves. In this article, the core governance problem is not the exit meeting or paperwork, but the gap between departure and complete deprovisioning across SaaS, SSO, shared accounts, voicemail, and remote access.

For IAM and IGA teams, the issue is lifecycle consistency. If access removal is handled as separate tasks across HR, IT, and app owners, former employees can retain usable permissions long enough to create avoidable exposure, billing waste, and confidentiality risk.

The article’s central message is that offboarding must operate as a synchronized identity process, not a sequence of loosely connected admin actions. That is a familiar failure mode in distributed SaaS environments, where app sprawl and inconsistent ownership make leaver handling slow and incomplete.


Key questions

Q: What happens when user deprovisioning is not connected to employee offboarding?

A: When offboarding is disconnected from deprovisioning, former employees can retain access to databases, applications, or shared tools long after they should lose it. That creates a direct path for data exposure, unauthorized modification, and avoidable breach impact. It also leaves security teams with no reliable way to enforce immediate access removal at the moment separation occurs.

Q: Why do delayed offboarding processes create security risk?

A: Delayed offboarding creates security risk because access can remain active after the business relationship ends. Former users may still reach email, files, CRM, or admin tools, which expands the window for data theft or disruption. The issue is not the departure itself, but the period during which stale access still works.

Q: What signs show that leaver access removal is failing?

A: Common signs include former employees still appearing in SaaS audit logs, licenses remaining assigned after exit, shared passwords not being changed, and IT being unaware of all apps the person used. If the organisation cannot prove which systems were closed, ownership changed, and data recovered, offboarding is incomplete.

Q: How should IAM and SaaS teams share responsibility for app offboarding?

A: IAM should own the lifecycle logic for access removal, while SaaS operations should supply the usage and contract context that proves whether access is still needed. When those functions stay separate, offboarding becomes inconsistent and accounts survive because no single team sees the full picture.


Technical breakdown

Why offboarding fails when deprovisioning is not parallel

Offboarding only works when identity removal happens across systems at the same pace as the employee exit. In SaaS-heavy environments, the identity subject can remain active in the IdP, SSO layer, application tenant, and shared communications tools even after HR considers the person gone. That creates a timing gap, not just an administrative gap. The mechanism is simple: access is distributed, but revocation is often sequenced manually, so one missing step leaves the former user able to log in, view data, or continue acting under existing permissions.

Practical implication: Treat offboarding as a synchronized workflow across HR, IAM, and application owners, not as independent tickets.

Why shared accounts and ownership updates are a control boundary

The article highlights a second mechanism that often gets missed: ownership transfer. Shared accounts, delegated passwords, and mailbox or voicemail assets can outlive the employee if the organization does not explicitly reassign them. That is not the same as removing a named user from SSO. Shared access creates residual identity authority because multiple people may know the secret or continue to rely on the account after the original owner leaves. If ownership does not change, the account can remain a live business path even when the person has exited.

Practical implication: Reassign shared assets, reset shared secrets, and record a new accountable owner before the leaver process closes.

How app sprawl turns offboarding into a discovery problem

The article also points to shadow IT as an offboarding blocker. If the organization does not know which SaaS applications an employee used, it cannot revoke access cleanly or back up data reliably. That turns offboarding into a discovery exercise before it becomes a revocation exercise. The technical issue is coverage: deprovisioning controls only work on known accounts and known apps, while employee usage often extends beyond the officially managed stack. Without user-level application discovery, the offboarding workflow is blind to a portion of the identity surface.

Practical implication: Maintain user-level SaaS inventory so leaver revocation can cover both sanctioned and discovered applications.


Threat narrative

Attacker objective: The objective is to preserve access to company systems and data after departure, whether for personal use, competitor advantage, or accidental continued exposure.

  1. Entry occurs when an employee leaves but retains active access in SaaS, SSO, or shared communication tools because deprovisioning has not completed.
  2. Credential or account misuse follows when the former employee can still sign in, view CRM records, or use shared accounts that were never reset.
  3. Impact occurs when retained access exposes confidential business data, customer information, or competitive sales visibility after separation.
  • Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Offboarding is a lifecycle control, not an HR formality: The article shows that access removal is only secure when identity, application, and data handover are terminated together. When those steps are split across teams and time, the organisation creates a residual access window that outlives the employment relationship. For IAM and IGA teams, the lesson is that leaver governance is a control system, not a checklist.

Residual SaaS access is the real offboarding gap: Remote work expands the number of systems a leaver may still reach after exit, especially CRM, collaboration, and SSO-linked apps. That makes unmanaged application inventory the hidden failure mode behind many offboarding incidents. Residual SaaS access: this is the period where a former employee still has usable access because no single system owns the complete revocation path. The practitioner implication is tighter lifecycle orchestration across identity and application owners.

Shared credentials extend the blast radius of leaver failure: When teams rely on shared passwords or informal ownership handoffs, offboarding no longer removes one identity, it leaves behind a business account with unclear accountability. That weakens governance because the account may still function even after the named user departs. The implication is that shared access must be treated as a high-risk control boundary, not an efficiency shortcut.

Discovery is now part of offboarding assurance: Organisations cannot claim complete deprovisioning if they only revoke what their directory already knows about. SaaS sprawl means the leaver process must identify shadow applications and recover data before access is removed. The governance implication is simple: offboarding maturity is measured by whether the organisation can see the full application estate, not by how quickly it can click revoke in SSO.

Offboarding delays convert routine exits into governance exposure: The article’s figures show that deprovisioning often lags the actual departure event, which is enough time for unnecessary access to persist. That is a lifecycle weakness, not an isolated admin error. Practitioners should treat delayed revocation as a measurable control failure in NHI governance and human IAM alike.

From our research library:

What this signals

Residual access after exit: Offboarding now has to be measured by how quickly access disappears across SaaS, SSO, and collaboration systems, not by whether HR marked the employee as departed. When those layers are decoupled, the control failure is a timing window that can be exploited or simply forgotten.

Lifecycle governance is the real issue: Identity teams should treat leaver handling as part of the same governance model that covers joiners, movers, and privilege changes. That means proving who owned the account, when it was revoked, and whether any shared credentials or delegated systems survived the exit.

Visibility closes the gap: If user-level discovery is missing, offboarding becomes partial by definition because the team can only revoke known applications. The practical signal of maturity is whether the organisation can see the full SaaS footprint for each user before deprovisioning begins.


For practitioners

  • Synchronise leaver workflows Make HR exit, IT deprovisioning, app owner confirmation, and data transfer run as one coordinated process so access removal is not delayed by handoffs.
  • Inventory every SaaS application used by each employee Use user-level app discovery so offboarding can include unsanctioned or shadow applications, not just the systems already in the directory.
  • Reset shared credentials before account closure Change passwords and reassign ownership for shared accounts, mailboxes, and voicemail systems before the former employee’s access path is considered closed.
  • Revoke SSO and remote access together Remove IdP, SSO, VPN, and remote desktop access in the same deprovisioning flow so one remaining path does not preserve access after exit.
  • Back up business data before revocation completes Preserve application data and transfer ownership where needed so revocation does not create a separate data-loss problem during the exit process.

Key takeaways

  • Remote offboarding becomes a security problem when identity removal, application ownership, and data handover do not happen together.
  • The article cites 32% of companies taking more than a week to deprovision leavers from SaaS apps, which is long enough to preserve unnecessary access.
  • A complete offboarding control should prove discovery, revocation, and ownership transfer across every system the employee could still reach.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe article is fundamentally about leaver access that survives employee departure.
NHI-05 — Overprivileged NHIFormer employees retaining access exemplifies privilege that outlives its business need.
NHI-09 — NHI ReuseShared accounts and reused access paths create offboarding risk when ownership changes are unclear.
Recommendation — Map leaver workflows to NHI-01 and verify that every account, token, and shared asset is revoked at exit. Review retained access paths against NHI-05 and remove any entitlement not required after departure. Eliminate reused identities and shared credentials before the leaver process closes.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccount lifecycle management is the core control family implicated by delayed revocation.
IA-5 — Authenticator ManagementCredential reset and revocation are central to the shared-account and offboarding issues here.
Recommendation — Apply AC-2 to ensure accounts are disabled, reassigned, or removed when users leave. Use IA-5 to rotate or revoke authenticators tied to leavers and shared access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about removing inappropriate entitlements from departing users across systems.
Recommendation — Enforce PR.AA-05 so entitlements are removed as part of a documented offboarding workflow.
CIS Controls v8CIS-5 — Account ManagementCIS-5 directly addresses managing lifecycle changes for accounts and access rights.
Recommendation — Use CIS-5 to track, disable, and reassign accounts during employee exit.

Key terms

  • Off-boarding: Off-boarding is the process of removing a departing user’s access, credentials, and related entitlements from the environment. In mature IAM programmes, it also includes reviewing sessions, shared secrets, delegated roles, and linked non-human identities so that exit events do not leave behind hidden access paths.
  • Deprovisioning: Deprovisioning is the removal of access when a user changes roles or leaves an organisation. For security teams, it is the point where stale accounts, tokens, and permissions should disappear. Weak deprovisioning leaves residual access that can outlive the business need that created it.
  • Shared Account: An account used by more than one person or process, often for convenience in operational environments. In identity governance, shared accounts weaken attribution, complicate auditing and make it difficult to prove who performed an action during production or maintenance activity.
  • Shadow IT: Shadow IT is the use of applications or services outside formal enterprise approval or visibility. In SaaS environments, it often includes department-purchased tools and unsanctioned integrations that create hidden identity, data, and access paths the security team cannot readily govern.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org