Hey folks, been setting up our offboarding workflow in Drata this quarter and wanted to share what we've landed on. It's been a game-changer for audit prep and keeping everything tidy. The key is making the process *automatic* and leaving a clear, time-stamped trail.
Here’s our step-by-step, which kicks off the moment HR notifies us in our #offboarding Slack channel:
* **Trigger & Task Creation:** We use a Zapier automation that watches that Slack channel. A new message creates a dedicated "Employee Offboarding" task in Drata, tied to the specific person.
* **Document Everything in the Task:** All communication, screenshots of access being revoked (think Google Workspace, GitHub, internal tools), and even the forwarded final paystub go into the comments of that Drata task. We *never* do this via email alone anymore.
* **System Access Checklist:** Drata has a built-in list, but we expanded ours. We confirm revocation in:
* SSO/Identity Provider (Okta for us)
* Email & Calendar
* Code Repositories
* Marketing Platforms (Klaviyo, HubSpot)
* CRM & Sales Tools
* Project Management (Jira, Asana)
* **The big one:** Any shared passwords in our password manager (we rotate these).
* **Final Step - The Compliance Check:** Once our checklist is done, we mark the task complete in Drata. This automatically updates the employee's status in the compliance dashboard and generates the activity log for that user. All the evidence is already attached to the task.
The biggest pitfall we avoided was letting evidence live in separate systems. Having it all centralized in the Drata task thread means during an audit, we just pull up the employee record and everything—notes, proof, completion times—is right there.
Anyone else have a slick integration or a step they found crucial? Always looking to improve our checklist!
Always A/B test.
Oh, that's interesting! We're looking at Drata too, but I'm still trying to figure out if it's overkill for our team size. I like the idea of a single task that holds everything.
When you say you *never* do this via email anymore, does that mean you actually copy-paste important email confirmations into Drata as well? We get a lot of "access revoked" confirmations sent to a shared IT inbox and I'm not sure how to handle those.
Also, the shared password one is huge for us. What do you do if the departing person was the only admin on some random legacy tool? That's my biggest fear.