Skip to content
Free Assessment · 10 Questions · ~3 minutes

Fired yesterday.
Still logged in today.

Every departure opens a risk window. Get your 5-axis Risk Profile (access control, shadow IT, data continuity, compliance, and post-departure monitoring) in under 3 minutes.

12
evidence controls across identity, SaaS, devices, data and SIEM
24
finding types that carry a dry-run remediation step you run yourself
3 tiers
standard, sensitive and hostile departure playbooks
How it works

Three steps to your risk profile

Quick Scan

Answer 3 questions about your access control. Get an instant risk score in 60 seconds.

Deep Assessment

Optionally answer 7 more questions to see radar analysis, benchmarks, cost estimates, and compliance gaps.

Evidence Roadmap

Get a personalized remediation report with MTTFAR targets, control gaps, and connector priorities.

Why this tool exists

A senior engineer at €80k/year isn't a password-reset queue. Automation is.
- Michal Jatczak, founder · ITSailor
Microsoft 365 live evidence scan

Turn the quiz into tenant evidence.

Connect with Microsoft admin consent to inspect disabled users, sign-in activity, OAuth grants, app roles, directory roles, Conditional Access, Intune devices, OneDrive presence and security alerts. No remediation permissions are requested.

What you are granting, and why
What you get

See exactly what Offboarding Evidence delivers

One scan turns a departure into auditable evidence. Offboarding Evidence keeps it live in a tenant workspace, hands you the runbook to fix it, and tracks the trend. Every shot below is a real, shipped surface.

From one scan

The exposure, documented

Connect Microsoft read-only. In minutes you get the evidence pack: access residue on disabled users, the non-human identities offboarding forgets, and any active leaver still in flight.

Evidence pack · offboarding
58%
Exposure
elevated8 findings

Evidence completeness

86%

critical24h

Former users retain OAuth grants

Graph oauth2PermissionGrants

high7d

Disabled users still hold paid licenses

Graph subscribedSkus

high7d

Forwarding on disabled mailboxes

Exchange inbox rules

The evidence pack
Non-human identities
52app registrations mapped
App registrations owned by disabled users2
Client secrets that never expire4
Service principals with no owner9

The identities offboarding forgets: secrets, tokens and workload apps that outlive the person who made them.

Non-human identities
Active leaver · live trigger
privileged in flight

Revocation due now

A privileged leaver was flagged by the HRIS trigger. Offboarding Evidence opens the clock against your target window and tracks what is still open.

24h

Target

11

Access paths

IT Sec

Owner

The active-leaver trigger

What Offboarding Evidence adds

Evidence control, not a one-off scan

Offboarding Evidence re-scans on your cadence, keeps every result, and turns findings into an executable runbook. The workspace becomes your offboarding system of record.

Your tenant workspace
Offboarding Evidence Watching

Contoso Ltd · 240 users

Connector

Healthy

Last scan

1 Jul 2026

Evidence

86%

MTTFAR

19h

3 disabled users still hold OAuth grants.

A tenant workspace
Remediation runbookdry-run default

# Reclaim licenses from disabled users

$targets = Get-MgUser -Filter 'accountEnabled eq false'

if ($Apply) {

Set-MgUserLicense -RemoveLicenses $skus ...

} else { "WHATIF: would remove 5 licenses" }

Every fix ships as an idempotent PowerShell runbook (.ps1 + .md). Destructive actions are gated on $Apply, with a rollback line per step. You run it in your own tenant.

An executable runbook
Posture trend · every scan retained
58improvingexposure
72
66
61
58

Offboarding Evidence keeps every scan, so you can prove the direction of travel to an auditor or the board - not just today's number.

Posture over time
Also includedBoard-ready PDF evidence packFindings + remediation CSVStandard / sensitive / hostile playbooks24h / 60m / 15m target revocation windowsMicrosoft 365 connector (Okta + Google in build)Drift alerts on new exposure

Do not take our word for it.

Download the exact sample evidence pack a customer gets - no login, no admin consent.

Offboarding Evidence

Leaver access evidence, sold as a product.

The free scan exposes the risk window. Offboarding Evidence turns that signal into a tenant workspace: recurring evidence, connector health, MTTFAR tracking, exportable packs and a billing trail your team can manage without a heavy identity governance rollout.

Connector Health

Track Microsoft evidence access, scan freshness and re-auth needs from one client workspace.

Evidence History

Keep each scan, risk band, severity count and evidence completeness score tied to a tenant timeline.

MTTFAR Trend

Measure mean time to full access revocation against standard, sensitive and hostile departure targets.

Export Pack

Produce board-ready PDF, findings CSV, remediation CSV and summary evidence for audit reviews.

Offboarding Evidence Pro

30-day money-back guarantee.

€199/mo billed annually

EUR 2388/yr

Prices excl. VAT. VAT is calculated at checkout.

Prefer a scoped assessment call?
1 / 3
Access Control
Question 01

How long does it take to completely revoke an employee's access to ALL systems?

Email, Slack, GitHub, Jira, Notion, CRM, VPN, AWS, Figma - absolutely everything.

Integrations

Offboarding Evidence reads across your whole stack.

Microsoft 365, Entra and Intune are the offboarding core - where most leaver access actually lives - and they scan live today. Google Workspace, ticketing, SIEM, collaboration and HRIS are in active build. One evidence model, never an integration we do not have.

Identity & SSOLive

Microsoft 365 · Entra

Devices & MDMLive

Intune · Jamf · NinjaOne

Google WorkspaceBuilding

Directory · Drive

TicketingBuilding

Jira Service Management

SIEMBuilding

Splunk · Sentinel · Elastic

CollaborationBuilding

Slack · Atlassian · Notion

HRISBuilding

Personio · HiBob · BambooHR

Code & ReposRoadmap

GitHub · GitLab

PSA / MSPRoadmap

HaloPSA · ServiceNow

CRMRoadmap

Salesforce · HubSpot

Live scan today Building now On the roadmap
What each connector reads and produces
SystemStatusReadsProduces
Microsoft 365 / Entra IDLive
  • User state, licenses, sign-in activity, OAuth grants and service principals
  • Admin MFA registration, directory role assignments and app role assignments
  • Conditional Access, Intune devices, OneDrive presence and Security alerts
  • Disabled account with license, recent sign-in, OAuth grant, role or device residue
  • Conditional Access gaps around admin MFA and legacy auth
  • Security alerts and OneDrive ownership evidence requiring leaver review
Jira Service ManagementBuilding
  • Offboarding request, approval and task status
  • Target-window timestamps for disablement, device return and mailbox handover
  • Linked remediation tickets generated from findings
  • Finding-to-ticket traceability
  • Owner, due date and acceptance criterion per remediation task
  • MTTFAR measured from HR trigger to final access-revocation proof
HaloPSA / ServiceNow / Freshservice / ConnectWise / AutotaskRoadmap
  • Leaver ticket workflow, approvals and closure evidence
  • Task assignments across identity, endpoint, mailbox and SaaS owners
  • Exception notes and breach reasons for late revocation
  • Ticket-backed remediation backlog
  • Target-window and exception audit trail
  • Customer-ready evidence review queue for MSP operations
Personio / HiBob / BambooHRBuilding
  • Termination date, employment status and manager ownership
  • Department, role profile and high-risk leaver classification
  • HR trigger timestamp for measuring access-revocation lag
  • HR trigger to IT action timeline
  • Sensitive-role or hostile-departure routing evidence
  • Manager sign-off requirement for mailbox and file handover
WorkdayBuilding
  • Worker status, termination event and supervisory organization
  • Role and location metadata for regulated handover routing
  • Scheduled leaver events for enterprise customers
  • Enterprise HR trigger evidence
  • Scheduled departure risk queue
  • SOX/DORA-friendly joiner-mover-leaver timeline
Google WorkspaceBuilding
  • Suspended user state, last login, aliases and admin roles
  • OAuth tokens per user/application
  • Drive ownership and endpoint management state
  • Former user not suspended
  • App tokens still present after departure
  • Drive or mailbox ownership not transferred
Okta / OneLogin / JumpCloudLive
  • User lifecycle status from IdP
  • Assigned applications and SCIM provisioning result
  • System log evidence for app membership removal and failed deprovisioning
  • SaaS app still active after IdP deactivation
  • SCIM failures or apps without SCIM coverage
  • Role profile drift between joiner and leaver workflows
GitHub / GitLabRoadmap
  • Organization membership, teams and outside collaborators
  • SSH keys, personal access tokens and deploy keys
  • Recent activity for sensitive repositories
  • Former user remains repository collaborator
  • Deploy keys or PATs still owned by departed engineer
  • Privileged code access missing owner transfer
Slack / Atlassian / NotionBuilding
  • Workspace membership and guest/external collaborator status
  • Admin roles, shared channels and workspace-level access
  • Recent activity and ownership of critical spaces or projects
  • Former user remains in collaboration workspace
  • External guest or shared-channel access survives departure
  • Knowledge-space ownership transfer needed
Salesforce / HubSpotRoadmap
  • User active state, role/profile and permission sets
  • Owned pipeline/accounts and shared inbox or sequence ownership
  • API/integration users tied to departed staff
  • Former sales user still active or API-enabled
  • Customer ownership not transferred
  • Revenue-system access closure proof
Intune / Jamf / Kandji / NinjaOne / AteraLive
  • Managed device ownership and compliance state
  • Wipe or retire command status
  • Last check-in and serial-number asset mapping
  • Departed user still owns a managed device
  • Wipe command missing or not completed
  • Device return past its target window
Sentinel / Splunk / ElasticBuilding
  • Former-user sign-in attempts
  • Impossible travel and data exfiltration indicators
  • Alert rule coverage for leaver events
  • Post-departure login attempt evidence
  • Tier-2 or tier-3 investigation timeline
  • Control coverage for NIS2/DORA monitoring evidence
Why this matters

Offboarding is a security problem, not an HR checklist.

Shadow IT compounds for years

Employees sign up for dozens of SaaS apps with a corporate email. Notion, Loom, Miro, Figma, Zapier. Nobody audits them.

Access ≠ Account

Deleting a Microsoft 365 account does not revoke OAuth tokens, API keys, or GitHub forks. Access can outlive the employee by years.

Regulators expect evidence

GDPR, NIS2, and ISO 27001 require a documented offboarding trail. No procedure = audit findings and potential fines.

Need professional help?

Ship an offboarding runbook in 2 weeks.

From a DIY runbook kit to a full security assessment, we build the procedure, automate the tooling, and deliver compliance evidence.