What is post-employment access?¶
The practical answer¶
Post-employment access is access used after a person’s employment, contract or authorised relationship has ended.
The key evidential caution¶
The dangerous assumption is that any login after departure proves the former employee deliberately returned.
It may not.
Access may continue because:
Key points¶
- the account was not disabled
- a token remained active
- a shared account was used
- a device retained a session
- an application permission survived
- an automated process continued
- another person used the credentials
What investigators should establish¶
Investigators should establish:
Key points¶
- the termination date and time
- what access should have ended
- which accounts, tokens and devices remained active
- what authentication occurred
- which device and source were involved
- what activity followed
- whether the former user retained equipment or credentials
Failure to remove access may explain opportunity.
It does not prove personal use.
Evidential limits¶
Likewise, a former employee may knowingly use access that the organisation failed to revoke.
Preserve HR, identity, device, session, provider and access-revocation records.
Post-employment access may also arise through personal copies of data retained before departure rather than a new login. Preserve earlier downloads, synchronisation, removable-media activity and cloud sharing. Later possession does not always require later system access.
Where access continued through a personal device or cloud account, establish whether organisational data had been synchronised before departure. The later availability of that data may result from an earlier authorised setup, an earlier unauthorised copy or a continuing provider session.
Operational takeaway¶
Compare the employment end point with the actual account, token and device lifecycle, and prove who used the surviving access rather than assuming it was the former employee.