Get notified of the departure (HRIS ticket, manager email, or a Slack ping), often no reliable pipeline for this.
Confirm the exact last day and time; voluntary vs. involuntary changes the urgency a lot.
Disable the account in the identity provider/SSO (Okta, Entra ID, Google Workspace).
Work through a running list, usually a spreadsheet, of SaaS tools not tied to SSO and revoke each one by hand.
Reassign the employee's shared drive files, open tickets, or Slack channel ownership before removing them.
Coordinate device return or remote wipe for the company laptop and phone.
Update the ticket confirming everything's revoked and log what was
Employee Offboarding: Access Revocation
Every account this person touched, SSO, email, endpoint, shared drives, and every third-party SaaS tool, is fully revoked by end of day on their last day, with a clean audit trail.
HR marks an employee's last day in the HRIS (termination or resignation), or a manager submits an offboarding ticket.
If it's an involuntary or hostile termination, access needs to be cut immediately, same hour, sometimes before HR even notifies the employee, not end of day. If the person held admin/privileged access to production systems, a second person has to verify that revocation before the ticket closes.
HRIS (Workday, BambooR), SSO/identity provider (Okta, Entra ID), Google Workspace or M365 admin, individual SaaS admin consoles (Salesforce, Slack, GitHub, Zoom), MDM for device wipe, ticketing system.
Any involuntary termination flagged as high-risk by legal, security, or HR; any account with standing privileged access to production or financial systems; and any device that can't be physically recovered.
About 30-45 minutes per offboarding when nothing gets missed, 2+ hours when a SaaS tool gets overlooked and someone finds a live account weeks later. At 1,200 employees with normal attrition, this happens multiple times a week, run by a small IT team with no dedicated headcount for it.
Steps 1, 3-4, and 6-7 are highly automatable if the trigger comes straight from the HRIS record instead of a manual ping: deprovision every SSO-connected app in one action and log it automatically. The judgment calls on hostile terminations and privileged-access double-checks should stay human.
2