Lifecycle & offboarding security checks across 7 apps
Dormant accounts, leavers with access, unowned assets and change-management gaps — the checks that catch what HR processes miss.
Why it matters
Leavers who still have access and accounts nobody has used for months are the findings HR processes miss and attackers look for first. Joiner-mover-leaver evidence is requested in every access review, and a dormant admin account is a critical finding on any framework.
Browse by app
- Microsoft 365 5 checks
- Chrome Enterprise 4 checks
- Amazon Bedrock 4 checks
- ServiceNow 4 checks
- n8n 4 checks
- Jamf Pro 3 checks
- LangSmith 3 checks
Highest-severity checks
The 8 most severe Lifecycle & offboarding checks across all 7 apps — each links to the connector page where the setting, its remediation and its framework mapping are documented.
- Bedrock Agent Failed Status — Amazon Bedrock severity: critical
- Copilot Agent Quarantined — Microsoft 365 severity: critical
- Bedrock Agent Orphaned Owner — Amazon Bedrock severity: high
- Change Approval Not Required — ServiceNow severity: high
- Copilot Agent No Owner — Microsoft 365 severity: high
- Copilot Agent Orphaned Owner — Microsoft 365 severity: high
- LangSmith Agent Orphaned Owner — LangSmith severity: high
- n8n Workflow Agent Orphaned Owner — n8n severity: high
Where to start
Connect Microsoft 365 first — it carries the most Lifecycle & offboarding checks in the catalog(setup guide, read-only access). A first scan takes about 15 minutes and reports every failing check on this page with its remediation steps.