Offboarding someone in ioMoVo is mostly handled for you, but there are two steps that are not automatic. Both are quick, and both matter if you are audited.
Step 1: disable the user upstream
Disable or deprovision the account in your identity provider as you normally would. This stops any new sign in.
Step 2: allow for the session window
Access tokens last 30 minutes. Someone who was already signed in when you disabled them can continue working for up to that long before their session stops renewing. For a routine departure this is fine. For an urgent removal, plan for it, and do not treat the moment you clicked disable as the moment access ended.
Step 3: expire outstanding share links
This is the one people miss. Share links are not governed by the user's identity provider. A link stays live until one of two things happens: an admin expires it, or it reaches an expiration date that was set when the link was created. Disabling the account does neither.
So as part of offboarding, an admin should review any links the departing user issued and expire the ones that are still open.
The better habit is upstream of that. Set an expiration date at the moment a link is created, as a matter of routine. A link that expires on its own is one you never have to remember to clean up, and it removes most of the work from this step entirely. It is worth making that a house rule rather than a case by case decision.
Step 4: reassign what they owned
Check projects where they were the only member, and anything they owned that another person now needs. Doing this at offboarding is much easier than reconstructing it later.
Quick checklist
Disabled in the identity provider
Removed from tenant membership
Waited out or accounted for the 30 minute session window
Reviewed and expired their outstanding share links
Reassigned owned projects and assets
