Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› How should IAM teams handle data left behind…
NHI Lifecycle Management

How should IAM teams handle data left behind by departing employees?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: NHI Lifecycle Management

They should make data transfer or backup a required offboarding step, separate from account closure. Departing employees often leave shared files, project artifacts, and application-owned records that must be preserved or reassigned. If the organisation cannot move custody cleanly, offboarding is incomplete even when login access has been removed.

What IAM teams should preserve before they close the account

The practical issue is not the login itself, it is the custody of work product and business records that were created under that employee’s access. IAM teams should treat transfer, retention, and reassignment as part of offboarding, because file ownership, shared folders, tickets, notes, reports, and application records can outlive the account that created them. Identity Security Programme Guide helps frame this as an operating model problem, not a single admin task.

That means the offboarding process needs a clear custody decision for each data type: keep, reassign, archive, or delete. The goal is to avoid a situation where access is removed but the organisation loses the ability to run the process, defend a decision, or satisfy retention needs. For shared workspaces and cross-functional projects, the new owner should be known before the user is disabled.

Data transfer also has to cover systems where the employee is not the sole owner in a human sense, such as notes in SaaS tools, task histories, shared inboxes, and records attached to automation or service workflows. Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is useful here because the same lifecycle logic applies to credentials, ownership, and decommissioning decisions around non-human access paths.

Teams should also distinguish preservation from access removal. An account can be closed quickly while records are transferred into a controlled repository, but that only works if the organisation has a defined handoff path and someone accountable for each content class. Without that separation, teams often discover missing files after the leaver profile is gone, when recovery is slower and less reliable.

Where offboarding data handling usually fails

The most common failure is assuming that disabling authentication finishes offboarding. It does not. The real exposure is orphaned content, undocumented ownership, and assets that remain in shared drives or business applications with no clear custodian. Insider Threat and Identity Guide is relevant because leaver handling sits on the boundary between normal workforce exit and residual insider-risk exposure.

Another failure mode is over-reliance on manager memory. If the manager cannot enumerate the employee’s data locations, the organisation will miss material records. This is especially common when employees used personal work habits, informal collaboration spaces, or manually maintained spreadsheets outside centralised repositories.

Delay creates its own risk. The longer ownership remains ambiguous, the more likely it is that records are edited, deleted, or duplicated in ways that weaken auditability. That is why preservation and reassignment should happen as close to departure as operationally possible, with the account closure step sequenced after the transfer step has been confirmed.

How to make the offboarding handoff auditable and repeatable

A reliable process starts with a leaver checklist that forces explicit ownership decisions. The checklist should identify where the employee stored work, who approves transfer, where the records will land, and whether anything must be retained for legal, regulatory, or operational reasons. If the organisation cannot prove those decisions later, the process is too informal to trust.

Automation can help, but only where it supports classification and routing, not where it guesses at business meaning. Top 10 NHI Issues is a useful reminder that lifecycle discipline matters most when ownership, permissions, and reuse patterns are easy to overlook.

For high-value records, the handoff should be evidenced, not assumed. Teams should be able to show what was moved, to whom, when it was archived, and what control preserved the original state. That is the difference between a clean offboarding record and a former employee still effectively holding institutional memory in unmanaged places.

Risk and Threat Considerations

When offboarding focuses only on account closure, organisations can lose control of business-critical data even while believing the exit is complete. The main exposure is not just retention failure, it is accidental disclosure, unauthorised reuse, or loss of continuity when files, notes, and application records are left without a clear custodian.

Failure mechanism: The employee’s access is removed, but their content remains in shared drives, collaboration tools, or application records with no assigned owner, no transfer trail, and no retention decision. That creates orphaned data that may be deleted, copied, or exposed through stale permissions.

Impact: Teams can lose auditability, miss legal or operational records, and leave sensitive material accessible longer than intended. In a serious case, the organisation may not know whether the departed employee’s data was preserved, reassigned, or inadvertently exposed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementLeaver offboarding needs account and data custody control across personnel changes.
Recommendation — Define offboarding steps that transfer or retain data before removing access.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccount disablement must be sequenced with removal and transfer of residual access-related obligations.
MP-6 — Media SanitizationDeparting-user data may need controlled preservation or disposal depending on retention needs.
Recommendation — Tie account termination to a verified data handoff and ownership reassignment. Preserve, archive, or dispose of leaver data under a defined retention rule.
ISO/IEC 27001:2022A.5.11 — Return of assetsLeaver data custody is part of returning organisational assets and records at exit.
A.5.33 — Protection of recordsDeparting employees can leave records that must remain protected and attributable after exit.
Recommendation — Require verified return or transfer of work product and records before closure. Assign record ownership and retention controls before deprovisioning the user.

Practitioner Guidance

What to prioritise: Build the leaver process around data custody first, access removal second. If the employee has files, shared workspaces, or application-owned records, close the account only after a named owner has accepted responsibility for each item.

What to verify: Confirm that the organisation can prove where each material record went, who now owns it, and what retention or disposal rule applies. If that evidence cannot be produced, the offboarding step is not operationally complete.

Common mistake: Treating manager approval as sufficient proof of transfer. In practice, the missing control is usually not intent, but a documented handoff and a checked destination for the data.

Practitioner takeaway: A clean offboarding is measured by preserved custody, not just removed access, because data that has no owner is still a live operational risk even after the account is gone.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org