Accountability usually spans IAM, email administration, and HR lifecycle owners because the risk sits at the boundary between identity status and mailbox configuration. If the programme treats offboarding as only credential revocation, no one owns the message-routing layer that keeps the risk alive.
Why This Matters for Security Teams
A forwarding rule left behind after offboarding is not just an email hygiene issue. It is a retention of access path that can expose sensitive messages, password resets, and business workflows after the employee has left. Current guidance treats this as a lifecycle control problem, because the account can be disabled while the mailbox remains capable of routing data elsewhere. That distinction is why accountability often splits across IAM, email administration, and HR lifecycle owners.
The operational risk is familiar in NHI governance too: closing one identity control does not necessarily terminate the downstream mechanism that keeps access alive. NHI Mgmt Group notes in the Ultimate Guide to NHIs that only 20% of organisations have formal processes for offboarding and revoking API keys, a signal that lifecycle gaps are usually process gaps before they are technical failures. The same pattern appears in mailbox offboarding, where teams assume disablement equals removal of risk. In practice, many security teams encounter mailbox forwarding abuse only after data has already been redirected, rather than through intentional offboarding review.
How It Works in Practice
Accountability should be assigned to the control owners who can actually remove the risk. IAM owns identity disablement and joiner-mover-leaver workflow enforcement. Email administration owns mailbox configuration, forwarding rules, delegation settings, and transport rules. HR or employee lifecycle owners own the trigger that starts and completes the offboarding event. That division is consistent with the control logic in NIST SP 800-53 Rev 5 Security and Privacy Controls, which expects organisations to define responsibilities, enforce access termination, and monitor configuration drift.
Operationally, the cleanest approach is to make forwarding-rule checks a mandatory offboarding step, not an optional cleanup task. A strong process usually includes:
- Immediate mailbox review before account closure or suspension.
- Removal of user-created forwarding rules, auto-replies, and delegation grants.
- Verification that shared mailbox access and application-linked mail routing are not left behind.
- Logging and approval for any exception that preserves routing for legal or business continuity reasons.
- Post-offboarding monitoring for rule recreation, especially where delegates or automation remain active.
The policy should also define who signs off on completion. If HR closes the record, IAM disables the account, and email admins remove the forwarding rule, accountability is shared but not ambiguous. Each team owns a different control point, and the evidence should show that all three happened in sequence. That is the practical lesson behind NHI lifecycle guidance in the Ultimate Guide to NHIs: offboarding fails when organisations treat identity revocation as a single action instead of a set of dependent removals. These controls tend to break down when mailbox administration is decentralised across business units because no single owner can confirm that forwarding exceptions were removed.
Common Variations and Edge Cases
Tighter forwarding controls often increase operational overhead, requiring organisations to balance clean offboarding against legitimate continuity needs. Some environments need temporary forwarding for legal review, executive transition, or regulated record retention, but best practice is evolving on how long those exceptions should remain in place. The important point is that exceptions must be explicit, time-bounded, and owned by a named approver rather than left to the departing employee or their manager.
There is also a split between mailbox forwarding and alternate exfiltration paths. A disabled user account may still have access through delegated inbox permissions, mobile clients, shared mailbox membership, or mail flow rules. That is why accountability cannot sit with IAM alone. In larger organisations, the email platform team often owns the last mile of enforcement, while HR and security own the evidence that the control was actually completed. If monitoring is weak, forward rules can be recreated after offboarding by a delegate or automation account, which is why periodic review matters even after the employee has left. As a governance benchmark, NHI Mgmt Group reports that 91.6% of secrets remain valid five days after notification in the Ultimate Guide to NHIs, underscoring how often revocation lags behind intent.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Offboarding must remove lingering email access paths, not just disable the user. |
| NIST SP 800-63 | Identity lifecycle governance depends on timely deactivation of authenticating accounts. | |
| OWASP Non-Human Identity Top 10 | NHI-06 | Forwarding rules resemble lingering access paths that survive intended revocation. |
Treat mailbox forwarding as a lingering identity path and revoke it as part of lifecycle closure.
Related resources from NHI Mgmt Group
- Who is accountable when a homegrown IAM process fails an audit or leaves access active too long?
- Who is accountable for exposed NHI secrets after an employee leaves?
- Who is accountable when orphaned apps keep running after an employee leaves?
- Who is accountable for access removal after an employee leaves?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org