Home About Experience Projects Case studies Resources Articles Briefs Playbook Tools FAQ How we start Security Get in touch

Security operations

Automating Offboarding: Revoking Access on the Last Day, Every Time

The laptop comes back on the last day because somebody owns that. The accounts stay open because nobody does. Here is how to make revocation automatic, and the one distinction that keeps it safe.

Think about the last person who left your business. The laptop came back on the last day, because somebody owned that and there was a deadline.

Now try their email. The shared drive. One client tool.

WHAT COMES BACK, AND WHAT DOES NOT Last day laptop returned Day 1 email still receiving Day 7 shared drive still open Day 30 client portal still live Day 90 nobody checked An account nobody closed is a credential nobody has to steal. The physical handover has an owner and a deadline. The digital one usually has neither.
Figure 1: nobody decides to leave access open. Closing it was simply never assigned to anyone.

Why this is worth automating rather than remembering

Verizon's 2025 Data Breach Investigations Report, which aggregates real incident records rather than surveying opinions, covers 22,052 incidents and 12,195 confirmed breaches across 139 countries. Two findings matter here.

Stolen credentials were the single most common way into a breach, at 22 percent of cases. And 88 percent of breaches at small and medium businesses involved ransomware, against 39 percent at large enterprises, because attackers automate and automation does not check your headcount before it scans.

An account that was never closed is a credential nobody had to steal. It sits in a former employee's old password manager on a personal laptop, waiting to be part of somebody else's automated sweep.

The risk is almost never a vengeful ex-employee. It is a live credential nobody remembered existed.

How to build it

1. Build the access map from the card statement, not from memory

Twelve months of card and bank statements, every recurring charge identified: what it is, who uses it, what it costs. Almost every business doing this for the first time finds at least one subscription nobody can name. Memory will not produce this list and neither will asking around.

2. Separate the map from the credentials

The map is documentation and should be complete and shared. It contains no secrets. Credentials belong in a password manager with a named emergency contact, and the recovery path should be tested before the week you need it.

3. Attach revocation to the leaving process that already exists

There is already a checklist for the laptop and the final payslip. Access revocation goes on the same list, with the same owner and the same deadline. This is an operations item, not an IT project, which is precisely why it never gets done.

4. Automate the trigger, not the judgment

When someone is marked as leaving in whatever system holds that fact, fire a checklist with one task per system, each assigned to whoever administers it, all due on the last day. The revocation itself often still needs a human; the remembering does not.

5. Kill shared logins before anything else

An account four people use cannot be handed over, revoked or audited. It is the single thing that makes both coverage and offboarding messy. Where individual accounts are possible, use them, and treat this as the prerequisite it is.

6. Run a quarterly access review automatically

A scheduled job that lists every account and its owner, and asks each system administrator to confirm the list. Orphaned accounts surface here rather than during an incident.

TWO THINGS PEOPLE WRONGLY COMBINE The access map Every system, who has access, what it costs, who the vendor contact is. CONTAINS NO SECRETS Should be complete, shared, and built from the card statement rather than memory. The credentials Passwords, keys, two-factor seeds. NEVER IN A DOCUMENT A password manager with a named emergency contact, and the recovery path tested before the week you actually need it.
Figure 2: knowing what exists and being able to open it are different problems with different solutions.

Tools and what they cost

OptionWhat it costsHonest trade-off
Google Workspace or Microsoft 365 admin + Apps ScriptIncluded in your existing subscription.Handles the core identity and the systems tied to it, at no extra cost. Third-party tools outside single sign-on still need individual handling.
Password manager with team features (1Password, Bitwarden)Roughly $4 to $8 per user per month; Bitwarden has cheaper tiers.Solves the credential half properly, including emergency access. Only covers what people actually store in it.
Identity provider with SSO (Okta, JumpCloud, Entra)Per-user monthly, typically in the low single-digit to low double-digit dollars.Revocation at one point covers every connected app. Real cost, real setup, and worth it above roughly twenty people.
A checklist template plus a calendar reminderFree.Genuinely better than nothing and far better than most businesses manage. It depends on a person remembering, which is what you are trying to remove.

What it is actually worth

This is a risk-reduction automation, which means honest measurement is about exposure rather than about a productivity percentage.

What independent data supports: stolen credentials are the most common breach entry point at 22 percent, per Verizon's incident records. Reducing live orphaned credentials reduces exposure to the most common attack path. That is a mechanism, not a promised percentage.

The cost side, honestly: Hiscox, an insurer, reported a median cyberattack cost of around $8,300 for US small businesses in its 2023 Cyber Readiness Report, fielded by Forrester across more than 500 US small businesses. Hiscox sells cyber insurance, which I am telling you rather than leaving you to discover. Note also that a median is not a worst case; the distribution has a long tail and the tail is where a business gets hurt.

The number that is genuinely yours: count the accounts still live for people who have left. Do it once. That count is your current exposure, it costs nothing to produce, and it is the only figure in this article that describes your actual business.

And a statistic I am deliberately not using: the claim that 60 percent of small businesses close within six months of a cyberattack. The National Cyber Security Alliance publicly disavowed it in 2022, describing it as a third-party 2011 figure they did not generate and could not verify the source of.

How it breaks

The access map goes stale. New tools get bought and never added. Attach adding to the map to the purchase itself, or you will repeat this exercise in eighteen months.

Two-factor is tied to a personal phone. The most common single point of failure in a small business, and it surfaces at the worst possible moment. Move it to something the company controls before you need to test it.

The automation fires but nobody completes the tasks. A generated checklist that sits unactioned is worse than a manual one, because everybody now assumes it was handled. Escalate incomplete revocation tasks by name after twenty-four hours.

How to tell whether it worked

One primary measure: live accounts belonging to people who have left, counted quarterly, target zero. Secondary: time from last day to full revocation, which should be same-day, and the number of shared logins remaining, which should be falling.

Sources and honesty note. Breach figures are from the Verizon 2025 Data Breach Investigations Report, covering 22,052 incidents and 12,195 confirmed breaches across 139 countries, aggregated from real incident data rather than survey responses. The median small-business attack cost is from the Hiscox Cyber Readiness Report 2023, fielded by Forrester Consulting across more than 500 US small businesses; Hiscox sells cyber insurance. Deliberately excluded: the widely repeated claim that 60 percent of small businesses close within six months of a cyberattack, which the National Cyber Security Alliance disavowed in May 2022 as an unverifiable third-party 2011 figure. Pricing is list price at time of writing.

Paul Prado Pacardo is a Senior Executive Assistant and Operations professional with over ten years supporting C-level leaders, and the solo founder of a multi-product software studio. Available for remote Chief of Staff, Operations, Senior Executive Assistant and Project Manager roles.