IT CanvassTalk to an advisor
Real projects · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · all levels

Employee offboarding

A leaver project: revoke all access promptly and completely on termination.

Quick answer

This project automates offboarding: on a termination event, SailPoint disables accounts and revokes all access quickly, closing the orphaned-account risk.

Key takeaways
  • Trigger from a termination event
  • Disable then remove accounts
  • Revoke all roles and entitlements
  • Produce an audit trail

Offboarding (the leaver process) is the single most important security automation in identity governance, because lingering access after departure is both a top audit finding and a real breach vector. This project ensures that when someone leaves, their access is removed promptly and completely.

The goal

On a termination event, SailPoint should disable accounts immediately to stop access fast, then fully deprovision as cleanup completes, leaving no orphaned access and a complete audit trail.

How to build it

  • Detect termination via a lifecycle event from the authoritative source.
  • Disable accounts immediately to cut access without waiting for full cleanup.
  • Revoke all roles and directly-held entitlements across every connected system.
  • Handle owned items, reassign or archive mailboxes, files and any resources the person owned.
  • Record every revocation as audit evidence.

Design considerations

The key design tension is speed versus grace. Immediate disable protects the organisation the moment someone leaves; graceful deprovisioning then handles data ownership, mailbox delegation and manager reassignment. Decide the sequence and timing deliberately, and make sure the leaver process covers every connected system, an un-onboarded application is exactly where orphaned access survives.

Common pitfalls

  • Slow or partial revocation leaving orphaned accounts.
  • Missing systems not covered by the leaver process.
  • No handling of owned data (mailboxes, files) on departure.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What triggers offboarding?

Frequently asked questions

What does the term Employee offboarding refer to in SailPoint?
Offboarding (the leaver process) is the single most important security automation in identity governance, because lingering access after departure is both a top audit finding and a real breach vector. This project ensures that when someone leaves, their access is removed promptly and completely.
What else is worth knowing about Employee offboarding?
On a termination event, SailPoint should disable accounts immediately to stop access fast, then fully deprovision as cleanup completes, leaving no orphaned access and a complete audit trail.
What is the practical takeaway on Employee offboarding?
Decide the sequence and timing deliberately, and make sure the leaver process covers every connected system, an un-onboarded application is exactly where orphaned access survives.
What tends to go wrong with Employee offboarding?
Slow or partial revocation leaving orphaned accounts. Missing systems not covered by the leaver process. No handling of owned data (mailboxes, files) on departure.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support