MYTHOSAI

Account security / PRACTICAL GUIDE

Offboard a user with an access inventory

Remove access systematically while preserving required business records.

Before you start

Authorisation to manage the organisation's accounts and an agreed departure process.

Start with ownership and timing

Offboarding is an access change, a data-handover task and an operational event. Deleting an account immediately may remove records that another authorised person needs. Leaving it active indefinitely creates a different problem. Agree on the effective time, who can authorise changes and who owns the departing user's work.

The inventory can be a private document; no paid governance platform is required for this exercise. It must cover external services as well as the main computer login.

Work through the access layers

  1. List the user's identity accounts, email, remote access, business applications, shared folders, password-vault membership and physical access. Include personally issued API keys or integrations only when they are part of the organisation's authorised scope.
  2. Identify business data that needs transfer or retention. Use the service's supported administration or export features, with an approved owner and retention decision. Do not secretly copy unrelated personal information.
  3. At the agreed time, disable relevant sign-in, revoke sessions where supported, remove group memberships and remote access, and recover organisation-owned devices and keys. Record each action and its result.
  4. Review shared secrets the person legitimately knew. Rotate those that remain necessary, update dependent services and confirm the replacements work. Prefer named individual access for future use instead of routinely shared administrator passwords.

Verify the removal

Use authorised administration views to confirm membership and account status. Check for independent accounts at external suppliers; disabling a central identity does not necessarily disable a separate local login. Where a controlled test is permitted, confirm access is refused without trying to impersonate the departing person on unrelated services.

Preserve service continuity

An automated task might run under the user's account. Reassign it to an approved service identity or redesign the workflow before deleting its only owner. Also verify who can manage a domain, retrieve backups and renew essential services after the departure.

Close with an evidence record

Keep a dated checklist, the authorised operator and unresolved items. Distinguish completed removal from a request awaiting a supplier. A clean checklist is only useful if its entries describe observable results. Repeat the inventory when roles change, because privilege reduction also matters when a person remains employed.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.