Skip to main content
Abnormal Extends Behavioral AI to Identity and AI SecurityLearn more

Jul 29, 2026

The Employee Who Left but Can Still Log In

Offboarding is a message. When an app never receives it, the door stays open

A user leaves the company. HR closes them out, the IdP account gets disabled, and offboarding is marked complete. But one downstream application never got the message. Its local account for that user is still active, the password still works, and from that app's point of view nothing has changed. Weeks later, someone signs in with those credentials.

Offboarding is a message. Every system has to receive it.

When Deprovisioning Doesn't Arrive

Deprovisioning isn't one switch. It's an event that has to propagate from HR to the IdP to every connected application, usually over SCIM or a provisioning connector. Any link in that chain can fail quietly. A connector drops the sync. An app was never wired into automated offboarding. A manual step nobody owned gets skipped. The account in that app stays live, and because the departed user can log in normally, nothing looks anomalous. The credential is valid. It just belongs to someone who left.

Reconcile Every Identity Against Who Still Works Here

The right approach doesn't trust that offboarding completed. Attune baselines every identity against employment status and flags any credential still active for someone who has departed, wherever it lives: the IdP account, the app-local login, and the API tokens that outlive their owner. Severity climbs when the exposure is provable. A credential or token showing activity after the departure date is live access that survived offboarding, and it should be cut immediately, not queued for the next cleanup pass.

When someone leaves your organization, how many systems actually find out?

See the latest from Abnormal's product and engineering teams.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.