CydentiCydenti
NHI Glossary

What Is Offboarding / Deprovisioning?

Offboarding, also called deprovisioning, is the process of formally removing an identity's access to systems, applications, and data once it is no longer needed — typically when an employee leaves, a contractor's engagement ends, an application is retired, or an integration is decommissioned. For human users, offboarding usually means disabling accounts and revoking single sign-on access. For non-human identities (NHIs) — service accounts, API keys, OAuth tokens, and automation bots — offboarding means deleting or rotating credentials, revoking API scopes, and removing the identity from every system it touched. Unlike human offboarding, NHI offboarding is rarely tied to a single HR event, so it is often skipped or delayed.

Why It Matters

Offboarding failures are one of the most common ways non-human identities become dangerous. When a project ends, a vendor relationship terminates, or an employee who owned a service account leaves, the credential itself frequently survives — becoming an orphaned account or dormant token that nobody monitors or rotates. Because NHIs can outnumber human employees 45 to 1, and a typical 100-person company runs 2,000+ of them, incomplete deprovisioning at scale creates a large, growing pool of forgotten access. OWASP's NHI Top 10 (2025) reports that 80% of identity breaches involve a non-human identity, and stale credentials with no active owner are exactly the kind of access attackers look for, since nobody notices when they are used. Under NIS2, ANSSI's ReCyF Objective 13 explicitly calls out lifecycle management of service accounts and machine credentials, making timely deprovisioning a compliance expectation, not just a hygiene practice.

How Cydenti Helps

Cydenti continuously maps every non-human identity across your environment and links each one back to the human owner, application, or process that created it. When an owner leaves, a project closes, or an integration is removed, Cydenti flags the associated credentials automatically instead of relying on someone to remember to revoke them. This turns offboarding from a manual checklist into a visible, trackable workflow, closing the gap where orphaned service accounts and forgotten API keys normally slip through. See how this fits into Cydenti's broader approach to identity lifecycle and threat detection.

Explore →

Frequently Asked Questions

What's the difference between offboarding a human and deprovisioning a non-human identity?

Human offboarding is usually triggered by a single HR event and handled through a defined process like disabling SSO access. NHI deprovisioning has no equivalent trigger — a service account or API key can outlive the project, employee, or vendor relationship that created it, so it must be actively discovered and traced rather than assumed to be caught automatically.

Why do organizations struggle to deprovision non-human identities?

Most NHIs are created ad hoc by developers or third-party integrations without centralized tracking, so there is no reliable inventory linking a credential to its owner or purpose. Without that link, security teams cannot confidently identify which service accounts, tokens, or API keys are safe to revoke, so they often get left active indefinitely.

Ready to secure your future?

Discover the machine identities you didn't know you had — in 27 minutes, for free.

NIS2 enforcement begins October 1, 2026. The Audit Flash delivers your complete NHI exposure snapshot — service accounts, orphaned credentials, OAuth grants, AI agents — with a first report in 3 hours. No commitment.

No commitment • No credit card • Data hosted in Europe • Response within 24h

What Is Offboarding / Deprovisioning? | Cydenti