TL;DR: Delayed de-provisioning, orphan secrets, and shared access are the core failure patterns in IT onboarding and offboarding, according to Entro Security, with its checklist guidance showing why employee lifecycle steps now double as identity security control points. Lifecycle governance, not just user provisioning, is where secrets exposure and residual access are won or lost.
Editorial analysis by NHI Mgmt Group, based on content published by Entro Security: “Secure IT onboarding and offboarding checklists”.
Key questions
Q: What breaks when offboarding only disables the primary account?
A: The lifecycle control remains incomplete.
Q: Why do delayed offboarding processes create security risk?
A: Delayed offboarding creates security risk because access can remain active after the business relationship ends.
Q: How can security teams prevent orphan secrets after employee departures?
A: Security teams should maintain a complete inventory of secrets ownership, map every dependency before offboarding, and rotate any token or key that the departing employee created or used.
Practitioner guidance
- Define secrets ownership at creation Require every API key, token, or shared credential created during onboarding to have a named owner, system dependency, and offboarding trigger before it is used in production.
- Revoke credentials beyond the user account Treat offboarding as a full credential-lifecycle event by disabling user access, rotating downstream secrets, and confirming that all tokens tied to the departing employee are no longer active.
- Inventory shared access paths before departure Map where each credential is used across cloud accounts, collaboration tools, and developer workflows so the team can rotate or delete the right secret without breaking live services.
Bottom line: IT onboarding and offboarding now function as identity control points because they determine whether secrets and access paths are created, owned, and removed correctly.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Onboarding is where NHI ownership starts, not where access merely begins. The article shows that provisioning, training, and credential creation are inseparable from lifecycle governance. Once API keys, tokens, and shared access paths are introduced without ownership metadata, the organisation has already created future offboarding risk. The practical conclusion is that secrets lifecycle design must start at issuance, not at departure.
A few things that frame the scale:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, according to the Ultimate Guide to NHIs.
- Around 59% of companies report experiencing a data breach related to poorly managed offboarding processes.
A question worth separating out:
Q: What is the difference between user deprovisioning and secret revocation?
A: User deprovisioning removes the person’s ability to authenticate as a user, while secret revocation invalidates the machine credentials that may still exist in applications, scripts, or cloud services. Both are needed because a disabled account does not automatically kill the access paths created during work.
👉 Read our full editorial: IT onboarding and offboarding are now NHI control points