IT Onboarding and Offboarding: Closing the Security Gap
The IT Security Gap Most Businesses Overlook
Ask most business owners how quickly a departing employee's access gets revoked and you'll get a vague answer: "pretty quickly," "HR handles that." The gap between an employee's last day and full revocation of access is one of the most common, and most preventable, sources of data exposure in mid-market businesses — quiet, constant, and rarely making headlines.
Why Offboarding Is a Bigger Risk Than It Looks
Without a structured process, offboarding depends on someone remembering to tell IT — access can remain active for days, weeks, or months. A single employee typically has logins across email, file storage, CRM, finance systems, VPN, shared drives, and SaaS tools IT may not even know about, so disabling one account doesn't touch the rest. Departures on bad terms (disputes, redundancies, terminations) carry elevated risk precisely when a clean process matters most. And BYOD or informally-synced personal devices can retain company data indefinitely if offboarding doesn't address them.
What a Proper Offboarding Process Covers
A trigger that doesn't rely on memory — HR notifies IT the moment a departure date is confirmed, as a mandatory workflow step.
A full access inventory covering every system, not just the obvious ones, including department-purchased SaaS and shared passwords.
Immediate suspension on the departure date, with full deletion on a set schedule after, preserving data for handover while blocking access.
Licence reclamation — closing the loop with [cloud cost management](/blog/cloud-cost-management-microsoft-365-azure/), since an unused licence is both a security risk and wasted spend.
Physical access revocation — building passes, alarm codes, keys, in the same process.
Device return and remote wipe of company data on managed and BYOD devices.
Handover of shared mailboxes and files before the account is disabled.
Documentation and sign-off by IT and HR, creating an audit trail.
Onboarding Deserves the Same Discipline
Provision access on a least-privilege basis rather than copying "whatever the last person had," enforce MFA and strong credentials from day one, and document what was granted so there's a clear record to revoke against later.
Why This Connects to Compliance
Access control underpins the Essential Eight principle of restricting administrative privileges — a strong patching regime and MFA mean little if access isn't removed the moment someone leaves. It also matters for the Notifiable Data Breaches scheme: unauthorised access by a former employee is reportable if it meets the threshold for serious harm, and a documented offboarding process is your best evidence that reasonable steps were taken.
How Ucomm Group Can Help
Onboarding and offboarding sit at the intersection of HR process and IT security, and fall through the cracks when nobody owns the whole picture. As part of our managed IT services, we build a documented workflow tied into your HR process, covering the full access inventory, same-day suspension, licence reclamation, and audit documentation for every departure.
Talk to us about tightening your onboarding and offboarding process - we will review your current process and show you where the gaps are.
Frequently Asked Questions
How quickly should access be revoked after an employee leaves?
On their last working day, no later, via a structured process that removes access to every system rather than relying on someone remembering to submit a ticket.
Does this only apply to accounts we manage directly, like Microsoft 365?
No — it needs to cover every system an employee touched, including SaaS tools bought outside IT's visibility, shared passwords, VPN, physical access, and personal devices under BYOD.
Is offboarding really a security issue, or just an administrative one?
Both. Former employee access is a common, preventable cause of unauthorised access and can trigger obligations under the Notifiable Data Breaches scheme.