Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable when social media access is…
Governance, Ownership & Risk

Who is accountable when social media access is not revoked after a contractor or employee leaves?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Governance, Ownership & Risk

The owning business function and its access administrators share accountability, because they control the approval and removal process. Security teams can set policy and oversight, but the operational duty to revoke access sits with the teams managing those accounts. Failure to offboard promptly leaves the organisation exposed to unauthorized posting and account abuse.

Accountability for Social Media Access Offboarding

When social media access remains active after a contractor or employee leaves, accountability usually follows the ownership of the account and the process that governs it. The business function that uses the account and the administrators who can remove access are the primary accountable parties, while security and governance functions are responsible for setting policy, enforcing standards, and checking that offboarding actually happens. For identity-managed accounts, this is closely tied to joiner-mover-leaver discipline and the control expectations reflected in NIST SP 800-53 Rev 5 Security and Privacy Controls.

What practitioners often miss is that “accountable” does not mean “the security team owns every removal action.” In most organisations, the operational removal step sits with the team that administers the account, because that team controls the access path and can confirm revocation. In practice, many security teams encounter the gap only after a former user has already retained posting or messaging capability, rather than through intentional offboarding governance.

How Social Media Offboarding Should Work in Practice

Social media accounts are often shared, delegated, or tied to marketing, communications, recruiting, or customer support workflows. That makes revocation different from a simple password reset. The key question is not only who can log in, but who can publish, approve content, manage linked apps, and recover the account if credentials were previously shared. If those functions are not explicitly assigned, offboarding becomes inconsistent and accountability becomes blurred.

In practice, the owning business function should define who approves access, who performs removal, and who confirms completion. Access administrators then execute the revocation, remove device sessions where possible, and replace shared credentials or tokens. Security teams should not be the sole operational owner, but they should require evidence that removal happened and that any delegated access, connected apps, or recovery methods were also reviewed. That matters because residual access can persist even after a visible password change if secondary credentials, app tokens, or recovery email paths remain active.

  • Identify the account owner and the administrator who can actually revoke access.
  • Remove the user from platform roles, not just from internal HR records.
  • Review linked applications, recovery options, and shared credentials.
  • Confirm that page ownership, ad accounts, and posting rights were transferred or removed.
  • Record the revocation so the business function can demonstrate completion.

Where this breaks down is in organisations that treat social media access as a casual operational detail rather than a controlled business service, because no one is left with clear authority to remove access promptly.

When Accountability Gets Blurred by Shared Roles and Delegated Access

Tighter access control often increases coordination overhead, requiring organisations to balance fast campaign operations against clear revocation discipline.

Social media management frequently includes temporary contractors, agency staff, and multiple approvers. That creates a genuine accountability tradeoff: more people can contribute to content operations, but more people can also retain indirect access if the offboarding process is informal. The point of contention is usually whether the account belongs to the brand, the campaign team, or the central communications function. Guidance varies by operating model, but the consensus is that ownership should sit with the business function that relies on the account, while administrative custody sits with the team that can enforce removal.

Edge cases matter. If an account is managed through a social media management platform, revoking one person’s access may not be enough if they still retain access to the publishing tool. If the former worker used their own authenticator, email alias, or recovery channel, access may remain possible even after internal approval says the account was closed. The accountability model therefore has to cover the account itself, the management console, and the supporting identity and recovery paths. That is also why identity lifecycle controls remain relevant even when the subject is a public-facing social account. Where ownership and administration are split across functions, the organisation should define which team is responsible for confirmation, not just initiation, of revocation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementCovers timely removal of user access after role change or departure.
Recommendation — Enforce rapid access revocation when users leave or no longer need account access.
NIST CSF 2.0PR.AA-04 — Identity Management, Authentication, and Access ProvisioningApplies to provisioning and deprovisioning identity access for accounts and services.
GV.RM-03 — Risk Management Roles, Responsibilities, and AuthoritiesAddresses clear ownership and accountability for access and control decisions.
Recommendation — Require timely deprovisioning and review access pathways when personnel exit. Define accountable owners for account access decisions and revocation duties.
NIST SP 800-63IAL — Identity Assurance LevelRelevant where identity proofing and identity lifecycle underpin account governance.
Recommendation — Use identity lifecycle controls to ensure departed users no longer retain valid access.
OWASP Non-Human Identity Top 10NHI-01 — Inventory and OwnershipSocial media accounts and tokens require clear ownership and lifecycle accountability.
Recommendation — Maintain ownership and inventory so offboarding can revoke each account path cleanly.

Practitioner Guidance

What to prioritise: Assign one business owner for the social account and one administrator for revocation. If either role is missing, offboarding becomes a process gap rather than a personnel gap.

What to verify: Confirm that removal covers publishing rights, shared credentials, connected apps, recovery settings, and any platform-level role assignment. A successful HR departure does not prove access has been revoked.

Decision rule: If the account is used for external posting or customer contact, treat delayed revocation as a higher-risk condition and escalate until a named owner confirms completion.

Practitioner takeaway: Accountability is strongest when the business function owns the service, administrators execute revocation, and security validates that the removal actually closed every access path.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org