The real cost of manual offboarding, and how it quietly adds up
Victor Lindqvist

Every account you forget to deactivate is a door left open. Most teams don't find out how many doors are open until something goes wrong.
Offboarding feels like a small task. Someone leaves, IT gets a ticket, a few accounts get disabled, and everyone moves on. In practice, it rarely goes that cleanly. The average employee touches a dozen or more tools by the time they leave a company, and most offboarding checklists only cover the obvious ones: email, Slack, the core HR system.
The accounts nobody remembers
The real risk lives in the tools that never made it onto the checklist. A marketing contractor's access to the analytics dashboard. A former engineer's API key that still works two years later. A shared login to a vendor portal that three people have used and nobody owns.
None of these show up in a spreadsheet-based offboarding process, because spreadsheets only track what someone remembered to write down.
The cost of manual offboarding isn't the time it takes. It's the accounts it misses.
Why this keeps happening
It's not a discipline problem. Even well-run IT teams miss accounts, because the information they need lives in too many places at once. Access decisions get made in onboarding docs, Slack threads, and one-off admin panels, and none of it is connected.
Access is granted ad hoc, often outside any central system
Offboarding checklists age faster than the tools they're meant to cover
Nobody owns the full picture of who has access to what
What automated offboarding actually looks like
The fix isn't a longer checklist. It's removing the need for one. When access is centrally managed, offboarding becomes a single action: deactivate the person, and every connected system responds automatically. No forgotten accounts, no follow-up tickets, no audit surprise six months later.
That's the difference between hoping someone remembered and knowing the system did.

