Offboarder connects to the places where
access still exists.
Start with our current connector ecosystem, then expand it around your environment. If you have a data source, SaaS app, cloud platform, developer tool, local account store, database account table, or access repository that matters to the offboarding process, Offboarder can work with you to build the connection and manage account removal.
Current connectors
Vendor integrations across AD, Entra, Okta, Google Workspace, AWS, GitHub, ADO, PAM, local account stores, and database accounts.
Growing ecosystem
New connectors can be prioritized around customer demand and audit scope.
Any data point
API, CSV, ticket, HRIS event, contractor roster, local account table, database account table, or system export.
Managed offboarding
Resolve the account, take the configured action, and retain connector-level evidence.
Connect the systems your offboarding process depends on.
Access often lives outside the primary identity provider. Offboarder connects those systems into one offboarding path so accounts can be managed, disabled, removed, or escalated for review.
Current vendor connectors
Use recognizable vendor integrations across identity, cloud, developer, PAM, local account, and database account systems.
Customer-driven expansion
Connect the data sources that matter to your offboarding workflow: APIs, exports, account tables, scripts, and event feeds.
Account management for offboarding
Identify the account, perform the configured offboarding action, and retain evidence of the result.
Current connector ecosystem
These are the systems Offboarder uses to manage account removal, access revocation, suspension, group cleanup, local account discovery, database account discovery, and audit evidence.
Identity & Directory
Active Directory
Disable on-prem accounts and remove privileged group memberships through Offboarder’s lightweight agent model.
Microsoft Entra ID
Disable cloud identities, revoke sign-in sessions, remove cloud groups, and remove app role assignments.
Okta
Clear sessions, remove app assignments, remove groups, suspend users, or deactivate accounts.
Google Workspace
Sign users out, suspend accounts, revoke OAuth grants, and remove privileged group membership.
JumpCloud
Remove groups, unbind systems, suspend accounts, and support directory-as-a-service environments.
Cloud & Developer Tools
AWS
Revoke IAM Identity Center assignments, disable IAM keys, remove IAM groups, and detach policies.
GitHub
Remove organization access, remove team membership, and support SAML, SCIM, and mapping-based resolution.
Azure DevOps
Remove users from Azure DevOps organizations and preserve dev-tool access removal evidence.
Privileged Access
Delinea Secret Server
Disable Secret Server users, remove group memberships where configured, and support PAM-vault evidence.
Local Accounts
Microsoft Local Accounts
Discover and manage Microsoft local accounts during offboarding, including disable-only workflows, local administrator review, and evidence capture.
Linux Local Accounts
Discover Linux local users, identify sudo or privileged access where configured, disable accounts, and retain host-level offboarding evidence.
Database Accounts
Microsoft SQL Database Accounts
Identify SQL logins and database users tied to departing users, disable configured accounts, remove role memberships, or route exceptions for review.
Have a data point we should connect to?
Bring us the source: an API, CSV, HRIS field, contractor table, ticketing workflow, SaaS export, local account table, database account table, or application admin action. Offboarder can work with your team to turn that data point into an offboarding connection.
The goal is simple: identify the account, manage the configured offboarding action, and produce evidence that the access path was handled.
- Data source and API feasibility review
- Identity matching strategy for UPN, email, employee ID, display name, aliases, contractor ID, or mapping table
- Supported offboarding action: disable, suspend, remove membership, revoke session, disable local account, or route to review
- Evidence design: matched account, timestamp, action status, and exception handling
- Build path for approved pilot or annual subscription customers
From one offboarding data point to a managed connector.
The implementation path stays practical: confirm the system, understand the account model, test matching, then turn it into a repeatable offboarding action with evidence.
Identify the data point
HR event, contractor roster, app export, account table, API object, local account source, or ticketing workflow.
Map the account
Define how Offboarder matches a person to an account across UPN, email, employee ID, display name, aliases, or mapping tables.
Confirm the action
Disable, suspend, remove group, remove assignment, revoke session, disable local account, or route to human review.
Prove the outcome
Store connector-level evidence showing what was matched, what happened, when it happened, and what needs follow-up.
Evidence for the controls auditors keep asking about.
Offboarder focuses on logical access removal and proof. The ecosystem exists to close the gap between the HR event and the many places access still exists.
SOC 2
Logical access removal, evidence, and exception follow-up.
ISO 27001
Identity lifecycle and access control evidence alignment.
PCI DSS
Access termination evidence for controlled environments.
SOX ITGC
Support for access termination control operation and review.
Connect the systems that matter to your offboarding process.
Offboarder’s ecosystem is built to grow with your environment: current vendor connectors, customer-driven data points, managed account actions, and evidence by default.