1 min lesson
Inventory and patch cadence as standing practice
Talk this through in your own words: "A fully remote engineer is terminated. Walk through what should happen to their device and access and the one failure mode you're most guarding against." Finish with the next move.
Step 1 of 2
Inventory and patch cadence as standing practicethe unglamorous half of the job
- Inventory as source of truth. Live counts, current assignment, compliance state and lifecycle stage per device - reconciled against MDM, not hand-maintained.
- Patch and vulnerability cadence. A regular rhythm for OS and critical-app updates across all four platforms, with deferral windows but a hard backstop so nothing rots unpatched.
- Audit-ready reporting. Encryption coverage, patch compliance and assignment reports that regenerate on demand for SOC 2 / ISO 27001 evidence.
- Reclaim and reuse. Recovered hardware re-enters the pool clean, so spend tracks headcount instead of drifting upward.
The classic offboarding gap is the unreturned remote-worker laptop. If your only offboarding plan assumes the device comes back to a desk, a remote leaver leaves a live, unwiped machine in the wild. The answer is remote lock/wipe tied to the leaver event plus a documented recovery-or-remote-destroy path - and saying so unprompted shows you've run real offboarding, not just read the runbook.
"Offboarded" is a claim until you confirm it. A mature process verifies each leaver: account disabled, sessions killed, SaaS deprovisioned, device locked/wiped and inventory updated - ideally as an automated check that flags any half-finished offboarding. An access review that surfaces a terminated employee with a still-active token is the exact finding a SOC 2 auditor lives for.