Offboarding

Offboarding you can prove, not just tick

What replaces the spreadsheet with one row per app and a column of checkmarks.

One pass closes every account the person ever had, and records how each one closed: deprovisioned over SCIM, closed through the admin console, transferred to an owner, session revoked. The offboarding stays open while any line is still open.

That last property is the one that matters, and it is where the gap between what a company believes and what is true is widest.

Most teams believe offboarding is done. What is usually true is that your SSO apps are done, and the rest is a spreadsheet somebody worked through while doing their actual job.

Why the spreadsheet survives

Because it works, in the narrow sense. Every row does get ticked eventually.

What it cannot do is prove anything to you. A tick records that somebody said they did it. It does not record whether the account closed, whether a session was still open, or whether the app even supports closing accounts by the route they used.

It also has no opinion about order, and order matters more than it looks. Data transfer has to run before deletion, because deleting a Google account takes its Drive with it. Sessions have to be revoked before credentials rotate, because rotating a password does not end a session that is already open. Both are wrong the other way round, and both are what a person doing this at 5pm on a Friday gets wrong.

What replaces it

One pass across everything the plan ever granted, with the method recorded per line: deprovisioned over SCIM, closed through the admin console, transferred to an owner, session revoked.

Those are different guarantees. A single green tick for all of them hides the only thing you are trying to establish.

Shadow accounts are included, because discovery has already found the apps people signed up for without telling anyone, and those are exactly the accounts a checklist has never heard of.

Die Workflow-Ansicht in Iden mit neun Workflows, gruppiert als Onboarding, Wechsel und Offboarding, jeweils mit den betroffenen Applikationen und der Angabe, ob der Workflow automatisch läuft.

Neun Workflows in drei Gruppen. Entscheidend ist die Spalte mit den Applikationen: Das Basis-Onboarding betrifft 32, ein Standortwechsel nur 3.

Offboarding is one of the three workflow families, and the variants matter. Offboarding with backups and offboarding without are different processes for different populations, which is why interns and full-time staff should not run through the same one.

The rule that makes it worth something

The exit stays open while anything is open.

That sounds small. It is the difference between a process that produces a status and one that produces a guarantee, because a partial offboarding can never be recorded as a finished one.

What still needs a person

A shared admin account with no single owner. An app where the leaver was the only administrator. A licence worth reclaiming deliberately.

These route to the app owner with full context, and they are why the last line of an honest offboarding summary is never zero.

Frequently asked questions

Minutes for the automated set, in one pass. What needs a person takes as long as that person takes, and the offboarding stays open until they come back.

Owned resources transfer before anything is deleted, because a deleted Google account takes its Drive with it. The ordering is enforced rather than left to whoever is running it.

Every line records what closed, how it closed, and when. That is a different artefact from a ticked checklist, which proves somebody ticked a box rather than that an account is shut.