Skip to content

Applications and access

Employee offboarding checklist for SaaS access

Download a free offboarding review template. Confirm accounts, assign access changes, preserve ownership and verify removal in each source application.

Get the user access review template

What to take away

A confirmed departure starts an access process, not a presumption that every account is safe to delete. This checklist helps IT and application owners connect verified accounts to decisions, source-side changes and evidence. It covers SaaS access; use your organization’s separate HR, device and retention procedures alongside it.

Use it in your next review

Download the offboarding access review template

Use a blank register or three fictional examples. Track one account per application, keeping a requested change separate from a source-verified result.

How to use this template
  1. Import as UTF-8 with comma separators; keep account identifiers as text.
  2. Confirm the departure, identity, authoritative account source and business owner before recording a decision.
  3. Assign each source change and record who checked the result, when, and where the evidence is retained. Leave unresolved items open.

Free, no email required. This manual review aid is not an Elba import format. Keep completed files in an approved location; your edits are not sent to Elba. Store evidence references rather than passwords, tokens or copied personal data.

Review a departing employee’s SaaS access in Elba

See verified accounts, review decisions, eligible revocation requests and the completed review export. Source checks remain part of your process.

See an access review in Elba

1. Confirm the departure and the identity

Use the authoritative HR or identity record to establish who is leaving, the effective date and the responsible owner. Resolve conflicting identities before changing access. An unmatched account, email domain or old activity observation does not establish a departure.

2. Inventory accounts beyond the identity provider

Collect dated account lists from relevant applications and validate them with their owners. Review direct sign-ins, guests, privileged roles, OAuth grants and shared or service accounts separately. Browser observations help locate applications to investigate; they do not prove a current account or its permissions. Keep unknown coverage explicit.

3. Preserve ownership and business continuity

Identify files, mailboxes, billing ownership and automations that depend on the account. Assign their future owners and follow the source provider’s supported transfer and retention procedure before deletion where required. Do not remove a shared or service account solely because the departing person used it. Store evidence references rather than copying business data into the checklist.

References: Google Workspace — Maintain data security after an employee leaves · Microsoft — Remove a former employee

4. Apply the appropriate native controls

Google documents separate steps for credentials, sessions and authorized apps, with data preservation before account deletion. Microsoft’s departure procedure covers preventing sign-in, preserving mailbox and OneDrive access, and subsequent license or account actions. Follow the current provider instructions for your configuration, including the authoritative directory for hybrid identity. Blocking new sign-ins is not evidence that every application session or token has stopped working.

References: Google Workspace — Maintain data security after an employee leaves · Microsoft — Remove a former employee

5. Verify the result and close explicit exceptions

For every change, record the decision, executor, due date, source-side result, verifier and evidence reference. A submitted request or manual completion declaration is not independently verified removal. Check the account, role or grant in the application and record exactly what the check covers. Give remaining dependencies and exceptions an owner and review date rather than silently closing them.

How Elba supports the review

Elba identity gaps and access reviews help investigate accounts associated with a confirmed departure. Use authoritative connected accounts or validated imports to record revoke or role-change decisions. A person can request revocation only where the integration and account permit it; perform other changes in the source. Okta context is read-only. Elba unenrollment does not deprovision connected applications. Elba does not independently verify removal: retain source checks alongside the completed review’s PDF summary and detailed CSV.

SaaS offboarding review checklist

0 of 8 checks complete

Your checks stay on this page and reset when you reload it.

Common questions

Is disabling SSO enough?

Check the relevant source applications, sessions, direct authentication and grants. Identity-provider action alone does not establish that every SaaS access path was removed.

Is this a complete employee exit procedure?

No. It is an access-review aid. Coordinate it with your organization’s HR, device, legal and data-retention procedures; do not treat this template as a compliance certification.

Does Elba automatically remove every account?

No. Actions depend on integration and account eligibility. Other changes require source-side work, and requests or manual declarations still require independent source evidence.

Sources & further reading

Primary documentation used to review this guide. Product settings and edition requirements can change; check the linked documentation before making changes.

Put it into practice

User access review checklistThird-party OAuth app reviewApplications and access in Elba
AI security6 min

Shadow AI: discover tools and control sensitive data

Build a Shadow AI inventory, distinguish observed use from verified access, and test controls for sensitive prompts and uploads.

Read the guide
Data protection9 min

Google Workspace DLP: setup, rules and limits

Check your Workspace edition, configure Drive DLP rules, test detections, and fix risky sharing. Includes rule examples and an access-review checklist.

Read the guide
Applications and access6 min

User access review checklist: from accounts to completed changes

Run an access review with verified accounts, clear decisions, tracked changes, and completion evidence. Includes a reusable review checklist.

Read the guide
Data protection6 min

SharePoint external sharing: review access with Copilot in mind

Review SharePoint and OneDrive sharing, distinguish permissions from discovery controls, and verify access changes with owners and practical checks.

Read the guide
Data protection7 min

Find and fix Anyone links in Google Drive and SharePoint

Build a dated inventory of anonymous file links, decide with owners, and verify changes in Drive, SharePoint, and OneDrive.

Read the guide
Security awareness7 min

After a phishing click: check the SaaS controls training cannot close

Keep phishing practice, then verify mailbox rules, OAuth consent, file links, and sensitive AI use after a suspected compromise.

Read the guide
Application security7 min

Audit third-party OAuth apps in Google Workspace and Microsoft 365

Inventory connected apps and consent, rank grants by scope, and verify keep, restrict, or revoke decisions in the source.

Read the guide

From review to remediation

Turn departure decisions into a tracked access review

Bring an application list to a demo: review authoritative accounts, distinguish supported requests from manual changes, and retain the completed PDF/CSV with source evidence.

Request a demo