Fired yesterday.
Still logged in today.
Every departure opens a risk window. Get your 5-axis Risk Profile (access control, shadow IT, data continuity, compliance, and post-departure monitoring) in under 3 minutes.
Three steps to your risk profile
Quick Scan
Answer 3 questions about your access control. Get an instant risk score in 60 seconds.
Deep Assessment
Optionally answer 7 more questions to see radar analysis, benchmarks, cost estimates, and compliance gaps.
Evidence Roadmap
Get a personalized remediation report with MTTFAR targets, control gaps, and connector priorities.
Why this tool exists
“A senior engineer at €80k/year isn't a password-reset queue. Automation is.”
Turn the quiz into tenant evidence.
Connect with Microsoft admin consent to inspect disabled users, sign-in activity, OAuth grants, app roles, directory roles, Conditional Access, Intune devices, OneDrive presence and security alerts. No remediation permissions are requested.
What you are granting, and whySee exactly what Offboarding Evidence delivers
One scan turns a departure into auditable evidence. Offboarding Evidence keeps it live in a tenant workspace, hands you the runbook to fix it, and tracks the trend. Every shot below is a real, shipped surface.
From one scan
The exposure, documented
Connect Microsoft read-only. In minutes you get the evidence pack: access residue on disabled users, the non-human identities offboarding forgets, and any active leaver still in flight.
Evidence completeness
86%
Former users retain OAuth grants
Graph oauth2PermissionGrants
Disabled users still hold paid licenses
Graph subscribedSkus
Forwarding on disabled mailboxes
Exchange inbox rules
The identities offboarding forgets: secrets, tokens and workload apps that outlive the person who made them.
Revocation due now
A privileged leaver was flagged by the HRIS trigger. Offboarding Evidence opens the clock against your target window and tracks what is still open.
24h
Target
11
Access paths
IT Sec
Owner
What Offboarding Evidence adds
Evidence control, not a one-off scan
Offboarding Evidence re-scans on your cadence, keeps every result, and turns findings into an executable runbook. The workspace becomes your offboarding system of record.
Contoso Ltd · 240 users
Connector
Healthy
Last scan
1 Jul 2026
Evidence
86%
MTTFAR
19h
3 disabled users still hold OAuth grants.
# Reclaim licenses from disabled users
$targets = Get-MgUser -Filter 'accountEnabled eq false'
if ($Apply) {
Set-MgUserLicense -RemoveLicenses $skus ...
} else { "WHATIF: would remove 5 licenses" }
Every fix ships as an idempotent PowerShell runbook (.ps1 + .md). Destructive actions are gated on $Apply, with a rollback line per step. You run it in your own tenant.
Offboarding Evidence keeps every scan, so you can prove the direction of travel to an auditor or the board - not just today's number.
Do not take our word for it.
Download the exact sample evidence pack a customer gets - no login, no admin consent.
Leaver access evidence, sold as a product.
The free scan exposes the risk window. Offboarding Evidence turns that signal into a tenant workspace: recurring evidence, connector health, MTTFAR tracking, exportable packs and a billing trail your team can manage without a heavy identity governance rollout.
Connector Health
Track Microsoft evidence access, scan freshness and re-auth needs from one client workspace.
Evidence History
Keep each scan, risk band, severity count and evidence completeness score tied to a tenant timeline.
MTTFAR Trend
Measure mean time to full access revocation against standard, sensitive and hostile departure targets.
Export Pack
Produce board-ready PDF, findings CSV, remediation CSV and summary evidence for audit reviews.
How long does it take to completely revoke an employee's access to ALL systems?
Email, Slack, GitHub, Jira, Notion, CRM, VPN, AWS, Figma - absolutely everything.
Offboarding Evidence reads across your whole stack.
Microsoft 365, Entra and Intune are the offboarding core - where most leaver access actually lives - and they scan live today. Google Workspace, ticketing, SIEM, collaboration and HRIS are in active build. One evidence model, never an integration we do not have.
Microsoft 365 · Entra
Intune · Jamf · NinjaOne
Directory · Drive
Jira Service Management
Splunk · Sentinel · Elastic
Slack · Atlassian · Notion
Personio · HiBob · BambooHR
GitHub · GitLab
HaloPSA · ServiceNow
Salesforce · HubSpot
What each connector reads and produces12 connectors
| System | Status | Reads | Produces |
|---|---|---|---|
| Microsoft 365 / Entra ID | Live |
|
|
| Jira Service Management | Building |
|
|
| HaloPSA / ServiceNow / Freshservice / ConnectWise / Autotask | Roadmap |
|
|
| Personio / HiBob / BambooHR | Building |
|
|
| Workday | Building |
|
|
| Google Workspace | Building |
|
|
| Okta / OneLogin / JumpCloud | Live |
|
|
| GitHub / GitLab | Roadmap |
|
|
| Slack / Atlassian / Notion | Building |
|
|
| Salesforce / HubSpot | Roadmap |
|
|
| Intune / Jamf / Kandji / NinjaOne / Atera | Live |
|
|
| Sentinel / Splunk / Elastic | Building |
|
|
Offboarding is a security problem, not an HR checklist.
Shadow IT compounds for years
Employees sign up for dozens of SaaS apps with a corporate email. Notion, Loom, Miro, Figma, Zapier. Nobody audits them.
Access ≠ Account
Deleting a Microsoft 365 account does not revoke OAuth tokens, API keys, or GitHub forks. Access can outlive the employee by years.
Regulators expect evidence
GDPR, NIS2, and ISO 27001 require a documented offboarding trail. No procedure = audit findings and potential fines.
Ship an offboarding runbook in 2 weeks.
From a DIY runbook kit to a full security assessment, we build the procedure, automate the tooling, and deliver compliance evidence.