Offboarding governance should be shared, but identity governance should provide the control point that aligns HR and IT. HR typically initiates the departure event, while IT and security must ensure access is revoked, reviewed, and logged across all connected systems. Clear ownership reduces gaps, because no single team can safely assume the other has removed every remaining entitlement.
How ownership should work when HR starts the exit and IT executes access removal
Offboarding governance should be shared, but the ownership model should be explicit: HR owns the employment event, while identity governance owns the control point that turns that event into consistent access removal. IT, security, and system owners then execute and verify the downstream revocation steps across directories, SaaS, endpoints, and shared platforms.
The practical reason this matters is that exit processing is a cross-system control problem, not a single-team task. If HR closes the employment record but nobody owns the identity workflow, entitlements can survive in application consoles, privileged toolchains, vaults, and legacy integrations long after the person leaves.
Identity governance is the right control point because it can reconcile the people-process signal from HR with the access-state signal from IT. That gives the organisation one place to define triggers, service-level expectations, exception handling, and evidence requirements for deprovisioning, rather than relying on informal handoffs between teams.
- HR should trigger the departure event as soon as it is known, with the effective date and any leave status captured accurately.
- Identity governance should translate that event into a revocation workflow, then track completion and exceptions.
- IT and security should remove access, confirm privileged paths are closed, and retain proof of completion.
For lifecycle detail, the NHI Lifecycle Management Guide is the clearest internal reference for provisioning, rotation, and offboarding controls. The broader Ultimate Guide to NHIs also frames offboarding as a governance and visibility problem, not just an account closure task.
Where handoffs fail in real offboarding programs
The most common failure is assuming that one system event removes all access. In practice, HR may be accurate about the employment status, but that does not automatically deprovision downstream applications, API keys, shared admin paths, or cloud consoles. Likewise, IT may remove the primary directory account while leaving connected entitlements active elsewhere.
Ownership gaps also appear when no one is responsible for recertifying what remains after the initial disablement. That is where orphaned access, dormant tokens, shared credentials, and excess privilege survive, especially in environments with multiple business units, third-party admins, and many separately managed tools.
A useful operating model is to treat offboarding governance as a closed-loop process: trigger, revoke, verify, and record. If any of those steps is missing, the organisation has not really governed offboarding, it has only started it.
Events like unrevoked signing credentials and lingering former-employee tokens show why the control point needs to sit above individual systems. The Coupang Signing Key Breach is a useful reminder that delayed revocation can create large exposure, and the 2025 State of NHIs and Secrets in Cybersecurity reports how often former-employee tokens remain active after offboarding.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Offboarding ownership needs a defined governance model across HR, IT, and security. |
| PR.AA-01 — Identities and Access Services Managed | Exit processing must remove access consistently across connected systems and services. | |
| Recommendation — Define who owns the offboarding control chain and document handoff responsibilities. Manage identity lifecycle events so departure triggers remove all active access paths. | ||
| CIS Controls v8 | 5 — Account Management | Offboarding is an account and entitlement removal problem across the enterprise. |
| 6 — Access Control Management | Shared ownership must ensure least privilege is revoked and verified at exit. | |
| Recommendation — Review and disable departing-user access promptly across all systems and applications. Enforce access removal workflows that confirm no residual privileges remain after offboarding. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Employee exit often leaves behind tokens, keys, or credentials that still authenticate. |
| NHI-03 — Least Privilege and Access Governance | Offboarding governance must close excessive and lingering access after departure. | |
| NHI-06 — Lifecycle and Ownership | The question is fundamentally about who owns lifecycle control for exit processing. | |
| Recommendation — Rotate or revoke identity-enabling secrets immediately when a user leaves. Verify and remove excess entitlements during the offboarding workflow. Assign clear lifecycle ownership so departures trigger complete deprovisioning and review. | ||
Practitioner Guidance
What to prioritise: Assign one control owner for the workflow, even if multiple teams execute parts of it. In most organisations, identity governance is the best home for that owner because it can enforce the join between HR status, IT removal, and security verification.
What to verify: Do not trust an offboarding ticket until you can show that access was removed across primary directories, privileged paths, and the main connected applications. The evidence should include timestamps, exceptions, and a clear sign-off path for any system that could not be automatically revoked.
Common mistake: Treating “employee terminated” as equivalent to “access removed.” That shortcut is especially dangerous where accounts, tokens, or shared administrative paths are managed outside the HR system and need explicit technical closure.
Practitioner takeaway: Offboarding governance works only when one function owns the end-to-end control, with HR as the trigger and identity governance as the accountable mechanism that proves revocation actually happened.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org