The client left months ago
A managed client gave notice and moved to another provider at the end of their contract. There was a final service review and a polite goodbye email. Three months later, your SIEM is still ingesting logs from their firewall. The EDR console still shows their agents, and your vendor invoice still includes them. Two of your analysts' accounts still exist in the client's Microsoft 365 tenant. The client has asked, through their new provider, for an export of the last year of their alert history.
Nobody forgot on purpose. Onboarding was a project with a plan and an owner. Offboarding was a date in the contract.
Each loose end creates cost, risk or an awkward conversation. Some of them could be a problem for the client, too, which is not how you want to be remembered.
And the new provider is watching. How cleanly you hand over is part of the story they will tell the client about you.
Why offboarding is left loose
- It happens at the end of a relationship, when nobody is motivated to spend time on it.
- What was set up for the client is spread across several tools, with no single list.
- Some steps depend on the client or their new provider, such as uninstalling agents.
- Data handover and retention depend on the contract, which nobody has reread.
- There is no checklist, so each offboarding is improvised.
What loose ends cost
| Loose end | Consequence |
|---|---|
| Agents and seats not removed | Vendor charges continue |
| Logs still ingested | Storage cost, and data held without purpose |
| Your team's access not removed | Risk for the client and for you |
| Data handover not agreed | Delays and disputes with the new provider |
| No closing record | Unclear what was done if questions arise later |
The offboarding tracker we build
- When notice is given, an offboarding plan is created with a date and an owner.
- Everything set up for the client is listed from your records and tools by API: agents and tenant in the EDR platform, log sources and data in the SIEM, scanner targets, licences, accounts your team holds in the client's environment, integrations, and scheduled reports.
- Each item becomes a task: remove, disable, hand over or retain under the contract, with the responsible party (your team, the client, or their new provider).
- Data handover and retention are set out from the contract terms, as recorded by your team, with the format and date agreed with the client.
- After the leaving date, the tracker checks your tools to confirm items are really gone: no agents reporting, no logs arriving, no seats billed, no accounts active.
- A closing record is produced for the client, listing what was removed, handed over and retained, with dates.
What you retain and for how long is set by your contract and your own policies. The tracker makes sure whatever was agreed actually happens.
A clean exit
The client leaves with a clear record and a handover their new provider can work from. Your vendor bills drop on time. Your team's access is gone. Data is handed back or retained as agreed, with dates. And if the client ever comes back, which happens more often than people expect, you know exactly what was set up before and what was removed.
A normal offboarding with the tracker runs like this. Notice arrives and the plan appears with the contract end date. The tool lists the client's EDR tenant, several log sources, a scanner schedule, four analyst accounts in their tenant and two scheduled reports. Tasks go out: the client's IT lead confirms agent removal is handled by the new provider, your engineer disables log collection and scanner schedules on the day, and analyst accounts are removed. A week later the checks confirm nothing is reporting in, and the closing record goes to the client.
Is offboarding left loose in your business?
- You have found former clients still reporting into your tools.
- Vendor charges continue after clients leave.
- Your team's accounts remain in former clients' environments.
- Data handover is worked out when the new provider asks.
- There is no offboarding checklist.