Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What breaks when a leaver keeps work access…
NHI Lifecycle Management

What breaks when a leaver keeps work access on personal devices?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: NHI Lifecycle Management

Unrevoked access on personal devices can leave company data exposed after employment ends. The risk is highest when credentials remain saved in browsers, password managers, or apps that still sign in automatically. If the account cannot be closed immediately, use strong unique passwords, enable multi factor authentication where possible, sign out everywhere, and remove the data from devices you keep.

What breaks when work access survives on a personal device?

When a leaver’s access still exists on a personal device, the break is usually in offboarding, not just in the account itself. The device can keep old sessions, cached credentials, synced files, and saved passwords alive after employment ends, which means company data may still be reachable from a machine the organisation no longer controls. That creates a clean path from departure to unauthorized access.

Why personal-device persistence makes offboarding fail

The main issue is that access often survives in more than one place. A browser may auto-fill credentials, a password manager may keep the secret, an app may preserve a refresh token, or a synced profile may continue to open documents and mail. If the user can still authenticate from that device, revoking the account later may be too late to prevent exposure.

This is why leaver handling has to treat the endpoint, the session, and the stored secret as a single problem. Disabling the account helps, but it does not fully solve exposure if the device already holds material that can restore access, especially on consumer-managed phones, laptops, and tablets where the organisation cannot directly enforce deletion.

What the remaining access can do in practice

The practical damage is straightforward: retained access can let a former worker read mail, download files, recover shared links, approve workflows, or reach SaaS applications that were never meant to stay open. If the personal device is unmanaged, the organisation may also lose visibility into whether files were copied, forwarded, or synchronised before the leaver was cut off.

For that reason, the control question is not only “Was the account disabled?” It is also “Can any trusted device, app, or saved secret still reconstitute access?” That distinction matters because a post-employment session can continue to behave like a valid user until tokens expire, passwords are changed, or the device is signed out and scrubbed.

Leaver reviews should therefore focus on the highest-risk materials first: active sessions, saved credentials, synced cloud storage, mail clients, remote-access apps, and any device enrolled for passwordless or single sign-on access. The lower the organisation’s control over the device, the more important it is to assume that residual access may outlive the employment relationship.

Risk and Threat Considerations

Residual access on a personal device creates a high-confidence exposure because the organisation may lose both authority and visibility at the same time. The former user may no longer be an employee, yet the device can still hold enough trust material to access data, forward information, or reconnect through cached sessions after offboarding.

Failure mechanism: saved credentials, tokens, and active sessions remain on a personally controlled endpoint after the account owner has left, allowing access to persist beyond the intended lifecycle and bypassing normal deprovisioning expectations.

Impact: company data can remain readable or exportable, offboarding can fail to terminate access cleanly, and any later compromise of the personal device can expose corporate mail, files, and application access as well.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCovers revoking and changing credentials that may still authenticate from a personal device.
IA-2 — Identification and Authentication (Organizational Users)Applies because the issue is whether a former user can still authenticate after employment ends.
Recommendation — Revoke and rotate authenticators so saved credentials and tokens cannot keep working after offboarding. Disable user authentication paths immediately when employment ends and verify they no longer work.
CIS Controls v8CIS-5 — Account ManagementDirectly addresses lifecycle removal of access when a leaver retains login capability on a device.
Recommendation — Remove dormant user access and confirm all accounts are deprovisioned at separation.
ISO/IEC 27001:2022A.5.18 — Access rightsRelevant because access rights must be removed when employment ends.
Recommendation — Revoke access rights promptly and validate that no residual entitlements remain.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingMatches the residual-access failure mode when credentials or sessions survive departure.
Recommendation — Terminate and verify all surviving access paths during offboarding.

Practitioner Guidance

What to verify: confirm that sign-out, token revocation, password reset, and device-level removal all happened, because any one of those steps alone may leave a usable path back in. If the account is still needed briefly, reduce the exposure window and track exactly which applications still trust that device.

What to prioritise: if the device is personal and unmanaged, treat saved secrets and persistent sessions as a higher priority than the device itself, because those are often the fastest route to continued access. Where possible, force a global sign-out before relying on manual collection or later cleanup.

Practitioner takeaway: offboarding is complete only when the identity, the session, and the endpoint all stop being trusted together, not when HR says the employee has left.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org