Join our Newsletter — 33% off our NHI Course
Home Glossary NHI Lifecycle Management Departure Window
NHI Lifecycle Management

Departure Window

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: NHI Lifecycle Management

The departure window is the period around resignation or termination when insider risk is highest because remaining access and possible motive overlap. Security teams reduce that risk by completing offboarding immediately, revoking every account and entitlement on the last working day, and raising detection sensitivity during notice periods.

Expanded Definition

The departure window is the short period around resignation, dismissal, or contract end when access still exists but trust assumptions are already changing. In NHI security, the term matters because service accounts, API keys, automation tokens, and shared admin credentials can remain active even after a human operator’s role has changed. That creates a mismatch between organisational intent and live privilege.

Definitions vary across vendors, but in practice the departure window should be treated as a lifecycle control problem, not just an HR event. It overlaps with offboarding, entitlement review, secrets revocation, and alerting for unusual access during notice periods. NIST guidance on access control and monitoring, including the NIST Cybersecurity Framework 2.0, supports this operational view by emphasizing timely governance and detection. For NHI programs, the window is especially dangerous when a departing engineer knows where credentials are stored, which automations they maintain, and which fallback paths remain undocumented.

The most common misapplication is treating departure as complete once HR closes the record, which occurs when account ownership, key rotation, and delegated access are not actually removed.

Examples and Use Cases

Implementing departure-window controls rigorously often introduces operational friction, requiring organisations to balance continuity of service against the speed of access removal.

  • A platform engineer gives two weeks’ notice, and the team accelerates rotation of deployment tokens before the final day to prevent post-exit misuse.
  • A contractor’s access to CI/CD secrets is revoked on the same day the engagement ends, while pipeline owners verify no orphaned keys remain embedded in jobs or config.
  • An SRE with production break-glass access moves into a non-privileged role, prompting immediate reassignment of ownership and review of all delegated automations.
  • An identity team monitors API key usage more aggressively during a notice period because the former operator still knows which integration paths are least visible.
  • The Ultimate Guide to NHIs is useful for mapping these actions to lifecycle governance, while SPIFFE guidance can help teams standardize workload identity handling during transitions, even though no single standard governs every departure scenario yet.

These examples are most effective when paired with identity inventory, owner confirmation, and a final entitlement sweep before the person leaves.

Why It Matters in NHI Security

Departure windows are high-risk because the organisation may still trust the person operationally while their incentives have already changed. That risk is amplified for NHIs, where credentials often outlive the individual who created them. NHIMG reports that only 20% of organisations have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them, which helps explain why access persists after employment ends. The Ultimate Guide to NHIs also notes that 91.6% of secrets remain valid five days after notification, showing how slowly remediation can lag behind the event that should trigger it.

This is why the departure window is not just a personnel concern; it is a control failure that can expose production systems, data pipelines, and customer environments. A mature program treats it as a Zero Trust and governance checkpoint, with immediate revocation, rotation, and logging review. It also aligns with the operational intent behind the NIST Cybersecurity Framework 2.0 by reducing access persistence and improving detection.

Organisations typically encounter the real cost only after an ex-employee account, stale token, or forgotten automation is used unexpectedly, at which point departure-window controls become operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Covers lifecycle and ownership failures that leave NHI access active after departure.
NIST CSF 2.0PR.ACAccess control and least-privilege governance apply directly to post-exit access removal.
NIST Zero Trust (SP 800-207)Zero Trust requires continuous revalidation, making departure timing a critical trust boundary.
NIST SP 800-63AAL2Authenticator assurance levels inform how strongly access should be bound and revoked.
OWASP Agentic AI Top 10AG-04Agentic systems inherit departure risk when human operators leave with active tool access.

Revoke, rotate, and reassign every NHI credential and entitlement before the departure date closes.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org