Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What should IT teams do first when offboarding…
NHI Lifecycle Management

What should IT teams do first when offboarding has not yet been formalised?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: NHI Lifecycle Management

Start documenting every device, license, and access right from the employee’s first day, not the last. That creates the inventory needed to revoke access quickly, recover equipment, and reuse assets without losing control. It also gives security teams a baseline for detecting unusual data movement later in the lifecycle and makes offboarding a repeatable control instead of an emergency cleanup.

What should teams establish before offboarding becomes a project?

When offboarding is still informal, the first step is not the final disablement action, it is building the inventory that makes disablement reliable. Teams need a live record of devices, licenses, access rights, and ownership from day one, so leaver handling becomes a repeatable process instead of a scramble. That same baseline supports recovery, reuse, and later anomaly detection.

A practical early control is to treat joiner, mover, and leaver data as one lifecycle record rather than three separate tasks. When provisioning is tracked from the start, IT can see which assets were assigned, which accounts were created, and which entitlements should disappear together at exit. That reduces the chance of orphaned access and missed returns.

Well-run lifecycle tracking also makes offboarding less dependent on memory or manager recall. If the record shows who owns the device, who approved the access, and what was issued to the employee, teams can verify closure against evidence instead of assumptions. That matters because informal offboarding often fails at the handoff between HR, IT, and security.

Why does starting at day one matter for access and asset control?

Starting at day one gives security teams a baseline for the full employment lifecycle, not just the exit event. It creates the context needed to revoke access quickly, reclaim equipment, and spot unusual activity later, such as data movement that does not fit the employee’s normal pattern. Without that baseline, exit work becomes partial and reactive.

The same inventory supports least-privilege cleanup. If teams know what was granted, they can remove only what the person actually used, avoid accidental over-revocation, and identify stale access that outlived the original need. That is especially important where access is tied to shared systems, SaaS tools, or licensed applications that do not fail closed when employment ends.

It also improves asset recovery. Devices, tokens, subscriptions, and other assigned items are easier to recover when they are recorded at issuance, not reconstructed after resignation. In practice, that shortens the time between notice and secure recovery, which is where many organisations otherwise lose control of equipment and accounts.

How does this turn offboarding into a repeatable control?

The key shift is from one-off cleanup to a standard lifecycle workflow. Once the baseline exists, offboarding can follow a consistent sequence: confirm inventory, revoke access, reclaim assets, close licenses, and validate completion. That sequence is easier to automate, easier to audit, and far less likely to depend on a single person’s knowledge.

This is also where process discipline pays off operationally. A documented lifecycle record helps teams distinguish between a true leaver, a role change, and a temporary leave of absence. Those cases often look similar at first glance, but they require different access and asset actions. Good records reduce unnecessary disruption while still limiting exposure.

For organisations with shared services or machine access in the mix, lifecycle records should also include who owns the account or credential and when it should be reviewed. That prevents delayed cleanup and makes it easier to see whether access was intentionally retained or simply forgotten during a transition.

Risk and Threat Considerations

Informal offboarding creates exposure because access, devices, and licenses can outlive employment longer than anyone expects. The main risk is not just lost assets, it is continued access into systems, data, and workflows after the person should no longer be trusted with them.

Failure mechanism: Without a day-one inventory, teams cannot reliably identify everything that must be revoked or recovered at exit. That leaves orphaned accounts, unrecovered devices, stale entitlements, and gaps in later investigation when unusual data movement or account use needs to be explained.

Impact: The organisation can lose control of data, create unnecessary license cost, miss suspicious post-exit activity, and extend the blast radius of any account or device compromise tied to a departing employee.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingOffboarding gaps are the exact control failure described.
NHI-05 — Overprivileged NHILifecycle records help remove excess access that lingers after role change or exit.
NHI-07 — Long-Lived SecretsForgotten credentials and tokens often remain usable after offboarding.
Recommendation — Document and revoke every issued credential, device, and entitlement before departure. Review and trim entitlements to the minimum needed before access is closed. Rotate or retire secrets tied to leavers as part of exit validation.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementRevoking and tracking credentials is central to offboarding control.
AC-2 — Account ManagementAccount provisioning and deprovisioning are core to employee offboarding.
Recommendation — Track, revoke, and lifecycle-manage authenticators when employment ends. Maintain complete account records and disable access promptly at separation.
CIS Controls v8CIS-5 — Account ManagementCIS account inventory and lifecycle controls directly support offboarding hygiene.
Recommendation — Maintain an accurate account inventory and remove access as soon as it is no longer needed.
NIST CSF 2.0ID.AM-01 — Physical Devices and Systems InventoryThe answer depends on inventorying devices from the start of employment.
PR.AA-01 — Identities and Credentials Are Issued, Managed, Verified, Revoked, and AuditedThe answer is about managing and revoking access across the lifecycle.
ID.AM-02 — Software Platforms and Applications InventoryTracking licensed tools and app access is part of the required inventory.
Recommendation — Keep a current inventory of assigned devices so recovery and deprovisioning are reliable. Manage and revoke identities and credentials through a documented lifecycle process. Inventory assigned applications and licenses so they can be removed or reassigned at exit.

Practitioner Guidance

What to prioritise: Start with a single source of truth for issued devices, licensed tools, and access entitlements, then make intake a required step at onboarding. If the record cannot answer “what was granted, to whom, and who owns the cleanup,” the offboarding process is not ready.

What to verify: Check that each assignment has an owner, a revocation path, and a recovery path. The practical test is whether another team member can close the employee’s access without relying on tribal knowledge or chasing multiple approvers.

Practitioner takeaway: Offboarding becomes manageable only after the organisation can reconstruct the employee’s footprint quickly and accurately, so the real first move is to make lifecycle inventory part of onboarding, not an afterthought at departure.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org