onboarding / offboarding
expressionIT supportsecurity
The account-and-access lifecycle at hiring and departure: created and granted on day one, revoked completely on the last - the second half is the audit finding.
Orphaned accounts of departed employees are a perennial breach vector.
Onboarding and offboarding are the joiner and leaver processes, and the asymmetry between them is one of the most reliable findings in any access review. Onboarding is highly visible, because a new person who cannot work complains immediately and loudly, and offboarding is invisible, because an account that still functions after someone leaves generates no complaint from anyone.
That asymmetry produces the predictable outcome. Access accumulates at the individual level too, since a person moving between roles gains the new permissions and rarely loses the old ones, which is privilege creep and ends with long-serving employees holding access no single role would ever justify. Nobody decided that; it is the sum of many reasonable individual decisions.
The fixes are structural rather than procedural. Automated deprovisioning driven by the authoritative HR record removes the dependency on somebody remembering, role-based access makes a change of role a replacement rather than an addition, and periodic recertification forces someone to affirm that access is still needed. The test of whether any of it works is simple and rarely run: pick someone who left three months ago and try to find what they can still reach.