The lifecycle.
ON JOINING
Individual accounts with the minimum access needed A second authentication step required Devices configured and recorded A short briefing on the basics A record of what was granted
THAT LAST POINT
The list of what a person was given is what you work through when they leave.
Without it, removal is incomplete.
ON CHANGING ROLE
Adjust access to the new role.
Do not simply add. Access accumulates otherwise.
ON LEAVING
Remove every account, the same day Change shared credentials they knew Recover devices Remove access from third-party services Reset any shared second factor
WHAT PEOPLE FORGET
Social accounts Payment services Third-party tools Keys and API credentials Remote access
FOR A DIFFICULT DEPARTURE
Remove access before the conversation, where warranted.
WHAT TO VERIFY AFTERWARDS
That nothing remains.
WHAT TO REVIEW
The process itself, after each departure.