What to take away
A confirmed departure starts an access process, not a presumption that every account is safe to delete. This checklist helps IT and application owners connect verified accounts to decisions, source-side changes and evidence. It covers SaaS access; use your organization’s separate HR, device and retention procedures alongside it.
Use it in your next review
Download the offboarding access review template
Use a blank register or three fictional examples. Track one account per application, keeping a requested change separate from a source-verified result.
How to use this template
- Import as UTF-8 with comma separators; keep account identifiers as text.
- Confirm the departure, identity, authoritative account source and business owner before recording a decision.
- Assign each source change and record who checked the result, when, and where the evidence is retained. Leave unresolved items open.
Free, no email required. This manual review aid is not an Elba import format. Keep completed files in an approved location; your edits are not sent to Elba. Store evidence references rather than passwords, tokens or copied personal data.
Review a departing employee’s SaaS access in Elba
See verified accounts, review decisions, eligible revocation requests and the completed review export. Source checks remain part of your process.
See an access review in Elba1. Confirm the departure and the identity
Use the authoritative HR or identity record to establish who is leaving, the effective date and the responsible owner. Resolve conflicting identities before changing access. An unmatched account, email domain or old activity observation does not establish a departure.
2. Inventory accounts beyond the identity provider
Collect dated account lists from relevant applications and validate them with their owners. Review direct sign-ins, guests, privileged roles, OAuth grants and shared or service accounts separately. Browser observations help locate applications to investigate; they do not prove a current account or its permissions. Keep unknown coverage explicit.
3. Preserve ownership and business continuity
Identify files, mailboxes, billing ownership and automations that depend on the account. Assign their future owners and follow the source provider’s supported transfer and retention procedure before deletion where required. Do not remove a shared or service account solely because the departing person used it. Store evidence references rather than copying business data into the checklist.
References: Google Workspace — Maintain data security after an employee leaves · Microsoft — Remove a former employee
4. Apply the appropriate native controls
Google documents separate steps for credentials, sessions and authorized apps, with data preservation before account deletion. Microsoft’s departure procedure covers preventing sign-in, preserving mailbox and OneDrive access, and subsequent license or account actions. Follow the current provider instructions for your configuration, including the authoritative directory for hybrid identity. Blocking new sign-ins is not evidence that every application session or token has stopped working.
References: Google Workspace — Maintain data security after an employee leaves · Microsoft — Remove a former employee
5. Verify the result and close explicit exceptions
For every change, record the decision, executor, due date, source-side result, verifier and evidence reference. A submitted request or manual completion declaration is not independently verified removal. Check the account, role or grant in the application and record exactly what the check covers. Give remaining dependencies and exceptions an owner and review date rather than silently closing them.
How Elba supports the review
Elba identity gaps and access reviews help investigate accounts associated with a confirmed departure. Use authoritative connected accounts or validated imports to record revoke or role-change decisions. A person can request revocation only where the integration and account permit it; perform other changes in the source. Okta context is read-only. Elba unenrollment does not deprovision connected applications. Elba does not independently verify removal: retain source checks alongside the completed review’s PDF summary and detailed CSV.
SaaS offboarding review checklist
Your checks stay on this page and reset when you reload it.
Common questions
Is disabling SSO enough?
Check the relevant source applications, sessions, direct authentication and grants. Identity-provider action alone does not establish that every SaaS access path was removed.
Is this a complete employee exit procedure?
No. It is an access-review aid. Coordinate it with your organization’s HR, device, legal and data-retention procedures; do not treat this template as a compliance certification.
Does Elba automatically remove every account?
No. Actions depend on integration and account eligibility. Other changes require source-side work, and requests or manual declarations still require independent source evidence.
Sources & further reading
Primary documentation used to review this guide. Product settings and edition requirements can change; check the linked documentation before making changes.