Because they change access needs and user intent at the same time. A person who is leaving, moving roles, or entering a disciplinary process may still have legitimate access while their relationship to the organisation has already shifted. That gap is where data movement, retention, and exfiltration risk rises.
Why This Matters for Security Teams
Resignations and role changes are high-risk moments because the normal assumptions behind access control start to fail. A user may still authenticate successfully while no longer needing the same systems, datasets, or administrative paths. That creates a narrow but important window where legitimate access can be used in ways the organisation did not intend, especially if termination workflows, approval chains, and monitoring are not tightly linked. The operational issue is not just account removal; it is timely rights reduction.
Security teams often underestimate how quickly risk shifts once intent changes. A departing employee may download files for convenience, a manager may retain access after moving into a different function, or a contractor may keep credentials that should have been expired. The control objective is to align access with current business need, then detect when behaviour no longer matches that need. The NIST Cybersecurity Framework 2.0 is useful here because it frames identity, monitoring, and response as continuous functions rather than one-time events. In practice, many security teams encounter insider loss only after data has already moved, rather than through intentional offboarding discipline.
How It Works in Practice
The practical answer is to treat resignation and role change as a coordinated identity event, not a HR-only update. Access should be re-evaluated as soon as the change is known, with the scope of entitlements reduced to the minimum needed for transition work. That often includes separating administrative access, removing shared mailbox rights, disabling privileged paths, and tightening access to source code, customer data, finance systems, and cloud consoles.
Good practice also depends on joining policy, workflow, and telemetry. The identity system should reflect the new status quickly, while logging and detection should watch for unusual downloads, mailbox forwarding, privilege escalation, and access to repositories outside the person’s new remit. NIST guidance in NIST SP 800-53 Rev 5 Security and Privacy Controls maps well to this problem because it supports access enforcement, auditability, and separation of duties. Many organisations also use event-driven revocation for high-risk departures, with tighter review for finance, engineering, and privileged operators.
- Trigger access review from the employment or role-change event, not from periodic recertification alone.
- Reduce standing privilege before the change takes effect where business operations allow it.
- Monitor for data staging, forwarding rules, and anomalous authentication after notice is given.
- Preserve evidence and maintain chain of custody if disciplinary or legal action is possible.
These controls tend to break down when HR, IAM, PAM, and security monitoring are run as separate workflows because revocation arrives too late or lacks sufficient context.
Common Variations and Edge Cases
Tighter offboarding often increases operational friction, requiring organisations to balance rapid risk reduction against business continuity. That tradeoff is real in cases where an employee is transferring internally, supporting handover duties, or retaining access to complete urgent work. Best practice is evolving here: there is no universal standard for exactly how much temporary access should remain, so organisations need role-specific rules and approval paths rather than a one-size-fits-all policy.
Edge cases are common. A resignation with a long notice period may justify limited access retention, but not broad system access. A role change may require new access before old access is removed, creating a short overlap period that should be tightly time-bound. In high-trust environments, the most important control is often not immediate lockout but precise scoping, strong logging, and fast exception review. If the person holds privileged access, the identity change should also trigger PAM review and, where appropriate, step-up approval for sensitive actions. For organisations handling regulated data, this is also where accountability expectations from the broader control environment matter, not just directory hygiene.
The human factor matters too. People who are leaving may still act responsibly, but organisations should not rely on goodwill as a control. The risk rises when normal process is bypassed for speed, when exceptions are not documented, or when access reviews are treated as a formality rather than a real security decision. That is the gap attackers, disgruntled insiders, and accidental data loss all tend to exploit.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA | Identity events should drive access reassessment and revocation. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is central to removing or adjusting access after status changes. |
Tie role changes to timely access updates and monitor for anomalous post-change activity.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org