Govern

Day one to last day

A leaver stops being reachable on the day they leave.

A joiner, a mover and a leaver, and what one run changes for each

What the industry reports

  • 45%of former employees admit signing back in to view, take or delete dataPonemon Institute, 2025
  • 32%of organizations take more than seven days to fully deprovision a leaverOneLogin, IT decision-maker survey
The moment

Their last day was Friday. On Monday the sessions are still live, the groups still list them, and the OAuth grants never expired.

For IT operations, on both ends of the org chart.

The directory change is the trigger

The run starts when employment ends in the directory, with no ticket in between.

One run strips everything

Sessions, groups, application assignments, directory roles and OAuth grants. Five kinds of access that usually need five people.

An unsupported step says so

Where a connector cannot do something, the step is skipped with its reason on the record.

What you get

Everything this covers.

  1. Joiner

    • Birthright access by role and department when the account is created
    • The directory change is the trigger
    A new starter’s first day, with the access their role grants arriving before they sign in
  2. Mover

    • Out of the groups and applications the old job needed
    • Into the ones the new job does, in the same run
    A move between teams, with the access the old role granted coming off as the new one is added
  3. Leaver

    • Sessions, groups, app assignments, roles and OAuth grants in a single run
    • A step a connector cannot do is skipped with its reason
    A leaver from trigger event through to execution, step by step
  4. Evidence

    • Workflows versioned, with a snapshot of the version that ran
    • A record per step: what ran, what changed, what failed
    • Notified in the product, by email, on Slack or by webhook
    Run history with the outcome and the reason recorded per step

See it on your own tenant.

Connect your directory and see findings the same day.