Skip to content
Partner Access Governance

The Partner Contract Ended. Their Access Often Did Not.

Inventory shared systems and data, revoke access, rotate secrets, transfer ownership and verify deletion without destroying required records.

Operations owner collecting keys, returning files and verifying partner access removal

Field note

By XenGrowth EditorialPublished Reviewed 11 min read

Key takeaways

  • Begin offboarding from a current register of users, service accounts, keys, integrations, shared assets, data copies, and ownership roles.
  • Revoke interactive and machine access, rotate shared secrets, transfer business-owned assets, and stop scheduled exports and jobs.
  • Decide return, deletion, anonymization, legal hold, and retention by data class and purpose.
  • Verify from both sides and monitor for residual access instead of treating a disabled login as completion.

01

The visible login is rarely the whole relationship

An agency user is removed from the CRM. Its service account still exports leads nightly, an API key remains in a script, a shared analytics property still has an owner, and campaign assets live in a personal account. The contract is closed while the technical relationship continues.

Maintain a register of named users, groups, service accounts, OAuth grants, API keys, webhooks, SFTP, shared inboxes, domains, profiles, ad accounts, analytics, repositories, storage, dashboards, data exports, devices, physical keys, and primary ownership. Tie every item to purpose, owner, approver, expiry, and removal method.

Swipe to compare every column

ControlActionEvidence
AccessDisable and remove identities and grantsProvider and application logs
SecretsRotate keys, tokens, passwords, certificatesNew version and failed old credential
AssetsTransfer company ownership and custodyOwner and recovery test
DataReturn, delete, retain, or hold by ruleScoped attestation and sampling

02

Plan exit while access is being granted

Use named identities, least privilege, company ownership, expiration, isolated credentials, and auditable transfer paths from onboarding. Avoid shared passwords and partner-owned primary accounts. The cheaper onboarding shortcut becomes the expensive exit dependency.

NIST control guidance treats account management, least privilege, external system use, access review, and credential management as ongoing controls. Adapt the controls to the system’s risk rather than applying one checklist blindly.

03

Separate deletion from preservation

Classify customer data, creative, contracts, financial records, consent evidence, logs, models, prompts, and derived data. Define what must be returned, deleted, anonymized, retained for a lawful period, or placed on legal hold. A blanket “delete everything” instruction can destroy evidence; “keep a backup” can preserve unjustified copies forever.

Require the partner to identify subprocessors and backups within scope. Get qualified legal and security advice for the actual agreement, jurisdictions, and incident state.

04

Prove the old route no longer works

Attempt access with test or logged old credentials where safe, inspect recent sign-ins, watch API and export logs, verify ownership and recovery, sample shared storage, and monitor for calls after termination. Reconcile exceptions with an owner and expiry.

Track overdue removals, residual grants, unrotated secrets, orphaned assets, post-exit access, incomplete deletion, and time to verified closure. Offboarding is finished when custody, access, and data state match the agreement—not when HR or procurement closes a ticket.

Primary sources and further reading

Use the source material to validate details against your own context and current platform configuration.

This field note follows the XenGrowth editorial policy: primary sources where available, visible limitations, material review dates, and no invented first-hand experience.

Stay with the problem

Explore CRM & RevOps