Key takeaways
- Begin offboarding from a current register of users, service accounts, keys, integrations, shared assets, data copies, and ownership roles.
- Revoke interactive and machine access, rotate shared secrets, transfer business-owned assets, and stop scheduled exports and jobs.
- Decide return, deletion, anonymization, legal hold, and retention by data class and purpose.
- Verify from both sides and monitor for residual access instead of treating a disabled login as completion.
01
The visible login is rarely the whole relationship
An agency user is removed from the CRM. Its service account still exports leads nightly, an API key remains in a script, a shared analytics property still has an owner, and campaign assets live in a personal account. The contract is closed while the technical relationship continues.
Maintain a register of named users, groups, service accounts, OAuth grants, API keys, webhooks, SFTP, shared inboxes, domains, profiles, ad accounts, analytics, repositories, storage, dashboards, data exports, devices, physical keys, and primary ownership. Tie every item to purpose, owner, approver, expiry, and removal method.
Swipe to compare every column
| Control | Action | Evidence |
|---|---|---|
| Access | Disable and remove identities and grants | Provider and application logs |
| Secrets | Rotate keys, tokens, passwords, certificates | New version and failed old credential |
| Assets | Transfer company ownership and custody | Owner and recovery test |
| Data | Return, delete, retain, or hold by rule | Scoped attestation and sampling |
02
Plan exit while access is being granted
Use named identities, least privilege, company ownership, expiration, isolated credentials, and auditable transfer paths from onboarding. Avoid shared passwords and partner-owned primary accounts. The cheaper onboarding shortcut becomes the expensive exit dependency.
NIST control guidance treats account management, least privilege, external system use, access review, and credential management as ongoing controls. Adapt the controls to the system’s risk rather than applying one checklist blindly.
03
Separate deletion from preservation
Classify customer data, creative, contracts, financial records, consent evidence, logs, models, prompts, and derived data. Define what must be returned, deleted, anonymized, retained for a lawful period, or placed on legal hold. A blanket “delete everything” instruction can destroy evidence; “keep a backup” can preserve unjustified copies forever.
Require the partner to identify subprocessors and backups within scope. Get qualified legal and security advice for the actual agreement, jurisdictions, and incident state.
04
Prove the old route no longer works
Attempt access with test or logged old credentials where safe, inspect recent sign-ins, watch API and export logs, verify ownership and recovery, sample shared storage, and monitor for calls after termination. Reconcile exceptions with an owner and expiry.
Track overdue removals, residual grants, unrotated secrets, orphaned assets, post-exit access, incomplete deletion, and time to verified closure. Offboarding is finished when custody, access, and data state match the agreement—not when HR or procurement closes a ticket.
Primary sources and further reading
Use the source material to validate details against your own context and current platform configuration.
- NIST SP 800-53 Rev. 5 security and privacy controls
- European Commission: Principles of the GDPR
- NIST Cybersecurity Framework 2.0
This field note follows the XenGrowth editorial policy: primary sources where available, visible limitations, material review dates, and no invented first-hand experience.
Stay with the problem



