Skip to main content

Removing a user's access: the offboarding checklist

What happens automatically when you deprovision someone, and the two things you still need to do by hand.

Written by Zakaria Waletski

Offboarding someone in ioMoVo is mostly handled for you, but there are two steps that are not automatic. Both are quick, and both matter if you are audited.

Step 1: disable the user upstream

Disable or deprovision the account in your identity provider as you normally would. This stops any new sign in.

Step 2: allow for the session window

Access tokens last 30 minutes. Someone who was already signed in when you disabled them can continue working for up to that long before their session stops renewing. For a routine departure this is fine. For an urgent removal, plan for it, and do not treat the moment you clicked disable as the moment access ended.

Step 3: expire outstanding share links

This is the one people miss. Share links are not governed by the user's identity provider. A link stays live until one of two things happens: an admin expires it, or it reaches an expiration date that was set when the link was created. Disabling the account does neither.

So as part of offboarding, an admin should review any links the departing user issued and expire the ones that are still open.

The better habit is upstream of that. Set an expiration date at the moment a link is created, as a matter of routine. A link that expires on its own is one you never have to remember to clean up, and it removes most of the work from this step entirely. It is worth making that a house rule rather than a case by case decision.

Step 4: reassign what they owned

Check projects where they were the only member, and anything they owned that another person now needs. Doing this at offboarding is much easier than reconstructing it later.

Quick checklist

  • Disabled in the identity provider

  • Removed from tenant membership

  • Waited out or accounted for the 30 minute session window

  • Reviewed and expired their outstanding share links

  • Reassigned owned projects and assets

Did this answer your question?