[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-deprovisioning::en":3,"gloss-cluster-deprovisioning::en":20,"gloss-next-deprovisioning::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"deprovisioning","security","Deprovisioning","Deprovisioning is the process of removing a person's access to systems and data when they leave the organisation, change role, or finish an engagement. It is the closing half of identity lifecycle management, and it is systematically weaker than the opening half for a structural reason: provisioning is blocked until it happens, because somebody cannot start work without access, while deprovisioning blocks nothing at all. Nobody is waiting on it, so nothing forces it, and the failure is invisible until an audit or an incident. What is left behind is more than a bill. A live account belonging to someone no longer at the company retains whatever data access it had, sits outside the identity provider's control if it was created with a local password, and is an attractive target precisely because nobody is watching it. Personal API keys, OAuth tokens issued to third-party apps, service accounts created for a project and shared credentials in a team vault all survive the same way, and none of them appear in a seat count. The controls that work are structural rather than procedural. SCIM tied to the identity provider makes deactivation in the directory propagate to the application automatically. An offboarding checklist that enumerates every system, owned by IT rather than by the departing person's manager, catches the tools SCIM does not reach. Periodic access reviews find what both missed. And key rotation matters as much as account deletion, since a revoked user's API token may keep working if it was issued to an application rather than to a session. Measure it: time from termination in the HR system to access removal across all systems is the single number that tells you whether deprovisioning actually works.","Deprovisioning is the removal of a user's access when they leave — the step that gets skipped, leaving live accounts and billed seats behind.",null,[11,14,17],{"slug":12,"name":13},"least-privilege","Principle of Least Privilege",{"slug":15,"name":16},"scim","SCIM (System for Cross-domain Identity Management)",{"slug":18,"name":19},"seat-sprawl","Seat Sprawl",[21,25,29,33,36,39,42,45,48,51,54,57],{"slug":22,"category":5,"name":23,"updated_at":24},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":26,"category":5,"name":27,"updated_at":28},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":30,"category":5,"name":31,"updated_at":32},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":34,"category":5,"name":35,"updated_at":32},"bridge-letter","Bridge Letter",{"slug":37,"category":5,"name":38,"updated_at":32},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":40,"category":5,"name":41,"updated_at":24},"byok","Bring Your Own Key (BYOK)",{"slug":43,"category":5,"name":44,"updated_at":32},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":46,"category":5,"name":47,"updated_at":28},"data-classification","Data Classification",{"slug":49,"category":5,"name":50,"updated_at":32},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":52,"category":5,"name":53,"updated_at":32},"data-minimization","Data Minimization",{"slug":55,"category":5,"name":56,"updated_at":32},"data-poisoning","Data Poisoning",{"slug":58,"category":5,"name":59,"updated_at":32},"data-processing-agreement","Data Processing Agreement (DPA)"]