Offboarding success rate is the share of leaver workflows that complete as intended, with access removed across the relevant applications and accounts. It is a governance outcome metric, not a task completion metric. High values indicate that revocation, deprovisioning, and downstream account closure are happening reliably in practice.
Expanded Definition
Offboarding success rate measures whether leaver workflows actually remove access everywhere it matters, not merely whether a ticket was closed. In NHI security, that includes service accounts, API keys, tokens, certificates, vault entries, and downstream application permissions that can survive after employment or ownership ends. The concept aligns with lifecycle governance in the NHI Lifecycle Management Guide and with broader control expectations in the NIST Cybersecurity Framework 2.0, where process completion is only meaningful if it reduces exposure in practice.
Definitions vary across vendors and internal identity programs, because some teams count only HR-triggered deprovisioning while others include application-by-application closure and revocation validation. NHI Management Group treats the metric as an outcome measure tied to confirmed removal of active access, including orphaned credentials and delegated paths that can remain in place after a person leaves. The most common misapplication is treating workflow closure as success, which occurs when IAM teams do not verify that every dependent system received and executed the revocation event.
Examples and Use Cases
Implementing offboarding success rate rigorously often introduces verification overhead, requiring organisations to balance faster employee exits against the cost of proving that access is truly gone.
- A developer leaves and the HR ticket closes, but a cloud access key remains active in a CI/CD secret store; the offboarding workflow is counted as failed until that key is revoked and confirmed.
- A contractor account is disabled in the directory, yet the same identity still has access through a shared SaaS workspace; the offboarding measure should include downstream application closure, not just directory deactivation.
- An engineering team uses Ultimate Guide to NHIs lifecycle practices to validate that tokens, vault records, and service account bindings are removed after role change or departure.
- A security team benchmarks leaver processing against NIST Cybersecurity Framework 2.0 by checking whether identity revocation reduces the organisation’s exposed attack surface.
- A post-merger cleanup effort identifies stale third-party integrations still authenticated with former employee credentials, so offboarding success becomes a remediation metric for inherited access sprawl.
Why It Matters in NHI Security
Offboarding failures are especially dangerous for NHIs because machine access is often less visible than human access and can persist long after the original owner departs. NHI Management Group research shows that only 20% of organisations have formal processes for offboarding and revoking API keys, which helps explain why lifecycle gaps remain a persistent source of exposure. The same problem appears in broader breach patterns covered in Top 10 NHI Issues, where unmanaged lifecycle events repeatedly surface as a control failure.
When offboarding success rate is low, the organisation can retain active paths into production systems, vaults, data stores, and partner integrations even after employment ends. That turns routine personnel changes into latent security incidents, particularly when secrets are duplicated or reused across systems. In governance terms, the metric helps identify whether revocation is merely requested or actually enforced across the environment. Organisations typically encounter the true cost only after an insider event, audit finding, or breach review, at which point offboarding success rate becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Covers lifecycle and revocation failures for non-human identities and their credentials. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions management depends on timely removal of stale credentials and accounts. |
| NIST Zero Trust (SP 800-207) | SC-7 | Zero Trust requires continuous removal of trust when identity context changes or ends. |
| NIST SP 800-63 | AAL2 | Identity assurance weakens if authenticators and credentials remain active after departure. |
| OWASP Agentic AI Top 10 | A1 | Agentic systems must lose tool access and privileges when the owning actor exits. |
Verify every leaver event removes NHI access, then confirm revocation across all dependent systems.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org