SOC2Prep

SOC 2 onboarding and offboarding evidence

Joiners and leavers are the easiest control to run and the easiest evidence to lose, because both halves live in someone's inbox rather than in a system.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

For onboarding, an auditor wants a dated record per hire showing the accounts created, the access approved, the confidentiality agreement signed and the security training completed. For offboarding, they want the last working day and the timestamp of access removal in every system, and they compare the two. The gap between those two dates is the whole control. If your policy says access is removed within one business day, a departure at four days is an exception.

1 business day The commitment most small companies write and then miss once

Joiner population
Everyone who started during the observation window, employees and contractors both, including anyone who started and left inside the window.
Leaver population
Everyone whose engagement ended during the window, voluntary and involuntary, plus contractors whose statement of work simply expired.
Last working day
The date the person stopped working, not the date payroll ended or the date HR closed the file. Auditors measure removal against this.
Revocation timestamp
The moment the account was disabled or deleted in a given system, taken from that system's own log rather than from a checklist tick.

What is the population, and how much gets sampled?

You will be asked for a complete list of joiners and a complete list of leavers for the window, generated from a system rather than assembled by hand. The auditor then selects from each. The numbers below are what a forty-person company with normal turnover tends to hand over for a twelve month window.

Illustrative joiner and leaver populations, 40-person company, 12-month window
PopulationItemsTypically sampledSource system
Employee hires113HR system
Contractor engagements62Procurement or finance
Employee departures73HR system
Contractor ends52Contract end dates
Internal role changes41HR system
Total population3311Five separate lists, one reconciliation

The reconciliation is the part teams skip. Take your identity provider's list of accounts created during the window and compare it to the joiner list. Every account with no matching joiner is either a service account, an error, or a person your HR system never knew about. All three are worth finding before the auditor does. The evidence collection page covers why an incomplete list is more damaging than a missing artifact.

Which timestamps does the auditor compare?

  1. Start date from HR against account creation date in the identity provider. Access granted a week before the start date needs an explanation.
  2. Start date against the acceptance timestamp on the confidentiality agreement. Signed three months in is a finding on the HR control.
  3. Start date against training completion. Your policy names a deadline, often thirty days, and the record has to fall inside it.
  4. Last working day against identity provider revocation. This is the number the auditor will actually compute.
  5. Last working day against removal in systems that sit outside single sign-on: the cloud console with a local account, the database, the code repository, the support tool with its own password.
  6. Last working day against device return or remote wipe, where your policy commits to one.

The systems outside single sign-on are where this fails

Offboarding evidence usually looks perfect for the identity provider and falls apart on the four tools that were bought on a credit card and never connected to it. Build the offboarding checklist from the vendor register rather than from memory, and re-derive it whenever a tool is added, otherwise the checklist quietly describes the company you were two years ago.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What do you do about a departure you handled badly?

Something inside the window will have gone wrong: a contractor whose GitHub access lived on for six weeks, or a resignation where the last working day moved and nobody told IT. Do not hide it, and do not backdate anything.

  1. Write the incident down with real dates, in the same place you keep the rest of the offboarding records.
  2. Establish and record whether the account was used after the last working day. Pull the authentication log. An unused stale account is a control exception; a used one is a security event and follows your incident process.
  3. Record the root cause in one sentence, naming the mechanism rather than the person.
  4. Change the mechanism, and date the change. A checklist item added, a deprovisioning script, a monthly reconciliation between HR and the identity provider.
  5. Tell your auditor before fieldwork rather than letting them find it. A disclosed exception with a dated fix is discussed; an undisclosed one that turns up in a sample gets tested harder.

An exception here does not necessarily cost you a clean opinion. What costs you is a pattern of them, or one you were aware of and did nothing about. If several departures went the same way, expect the auditor to expand the sample rather than accept the first explanation.

Why does joiner and leaver evidence come back?

The record is usually rejected for its shape rather than its substance.

  • A completed checklist with ticks and no timestamps. The tick shows intent; the auditor is testing timing, so a checklist with no dates cannot pass.
  • A screenshot of a disabled account with no date in frame. It proves the account is disabled today, which was never the question.
  • A leaver population built from the HR system alone, so contractors are absent. The same completeness failure that undermines access reviews.
  • Removal evidence for the identity provider only, when the person also had a local database login and a standing cloud key.
  • An offboarding record signed by the departing employee's manager after the fact with no supporting system evidence at all.

A joiner and leaver record that holds up

0 of 8 done ·

The evidence tracker produces the joiner and leaver rows with the owner and cadence filled in, and the access review evidence page covers the periodic control that catches whatever the leaver process missed. If training is the item your joiner records keep failing on, the training records page deals with that on its own.

Get joiner and leaver evidence in order

Offboarding is where a single missed revocation becomes an exception on the report. Send your scope and compare firms that will tighten the process first.

Get matched

Common questions

How fast do we have to remove access when someone leaves?

Whatever your policy says, which for most small Canadian SaaS companies is one business day. SOC 2 sets no number. Pick a target you can hit on a Friday afternoon in December and write that one down, because a policy promising four hours creates exceptions that a policy promising one business day would not.

Do contractors count as joiners and leavers?

Yes, if they had access to anything in scope. This is the most common gap in this control. Contractors are engaged through procurement or a founder's email rather than through HR, so they never reach the list the auditor is given. How contractors and offshore staff are treated across the whole report is on contractors and remote teams.

Is a completed offboarding checklist enough on its own?

Usually not. A checklist is your assertion that something happened, and auditors prefer system evidence for the timing. Pair the checklist with the revocation log entries for the two or three systems that matter most and it will be accepted without argument.

What about someone who left before the observation window opened?

They are out of the population, and you do not need offboarding evidence for them. What you do need is for their accounts to be gone by the time your access reviews run, because a review that lists a person who left two years ago raises questions the auditor will follow.

Can we evidence onboarding with an email thread?

It works but it scales badly. Email is acceptable evidence when it carries dates, named people and an approval, which is why an approval email beats a checklist tick. Move to tickets before the population gets past about a dozen a year.