Offboarding Runbook
This runbook defines the minimum offboarding steps for users, seats, and tenant access in VaultCrux.
Offboarding triggers
- Employee/contractor departure.
- Role change requiring access reduction.
- Tenant closure or contract termination.
- Security incident requiring immediate revocation.
Immediate revocation steps
- Revoke seat(s) in team management flow or API.
- Invalidate active seat sessions.
- Rotate affected API keys and shared credentials.
- Confirm access denial on protected routes.
Tenant-level offboarding
- Export required records/receipts for retention and audit.
- Revoke remaining seats and API keys.
- Disable automated integrations and webhooks.
- Run data retention/deletion workflow per contract and policy.
- Record closure evidence and approval chain.
Verification checks
- Revoked users cannot create authenticated sessions.
- Revoked users cannot access tenant-scoped routes.
- New API key issuance is blocked for closed tenants.
- Audit evidence includes actor, timestamp, and result.
Timing targets
- Critical revocations: immediate.
- Standard personnel offboarding: same business day.
- Full tenant closure package: by agreed contract timeline.

