Ask Actually

How do I check that my IT provider removed a former employee's access?

In short

Pick one recent departure and ask your IT provider which systems it reports removing that person's access from, and for any records of those steps. Sort each reply into reported, record supplied, or unanswered. One departure can inform a keep, improve, renew or replace discussion, but it cannot judge the provider overall.

The Canadian Centre for Cyber Security's guidance on securing access in volunteer-based organizations calls offboarding a complex process. It names several places access can sit: on-premises accounts, cloud accounts, federated accounts, third-party software accounts with their own sign-in, and sessions that stay signed in through unexpired tokens. That guidance is written for volunteer-based organizations. We use its list here only as a prompt for what to ask about.

What to ask your provider about one departure

Choose one person who left recently. Before you ask anything, write your own list of the systems that person used. Consider email and file storage, payroll or accounting software, any business applications with a separate login, remote access, and any phone or laptop used for work, including a personal one.

The Cyber Centre's baseline controls for small and medium organizations recommend listing which systems are in scope, whether owned, contracted or otherwise used, and giving a rationale for any exclusions. If you already have a list like that, start from it.

The items in that request follow elements the Cyber Centre lists in its recommended offboarding process for volunteer-based organizations: disabling accounts, revoking certificates and tokens, revoking cloud service authentication tokens, disabling access from personal devices, and wiping organizational data from those devices.

How to record each reply

For each system on your list, use one of four categories. Reported: the provider states that access was removed. Record supplied: you received a ticket, screenshot, export or log, so note what the record reports, its date and the systems it names. Check performed: write what you compared, who compared it and the narrow result, such as whether a date in a ticket matches a date in an export. Unanswered or outside agreed scope: note the open question and who you asked.

If the provider explains a difference between two records, write down the explanation, what you compared, and whether a corrected record was promised or received. Keep that separate from questions that are still unresolved.

What these records can and cannot tell you

A supplied record reports what someone entered or exported. Receiving it does not confirm that it is complete or accurate. A record that names one system says nothing about systems it does not name. A missing record does not prove that access is still active, and it does not prove that the removal happened. One departure is also one case, so it cannot tell you how every departure was handled.

A slow or partial reply is consistent with several explanations, such as workload, an unclear request, or records held by someone else. The cause stays unresolved, so treat it as a follow-up question rather than a finding.

Using what you recorded in a keep, improve, renew or replace decision

Bring your list of reported items, records supplied, checks you performed and open questions to your next conversation with the provider. Ask who owns each open item and what would close it. Depending on the answers, you might keep the arrangement, ask for changes to how departures are handled, or look further before renewal. For the wider evaluation, see how to evaluate the managed IT provider you already have.

actually. offers an independent review of evidence about your existing IT provider.

The review is a paid service.

If you want someone outside the relationship to look at the evidence with you, see the actually. review.

Sources

This is one question. An independent review answers the rest, with evidence.

Request an Independent Review