Skip to content
ZK
ZAIN KHALIL KHAN
PORTFOLIO
All projects

Interactive build

Offboarding Orchestrator | Access Removal Assurance

Offboarding workflow model that tracks every access path an identity holds across identity provider, network, cloud keys, tokens, MFA enrolment, non-SSO SaaS, endpoint, and physical badge, computing the residual access window rather than assuming one account disable is sufficient.

Live demo readyOffboarding + Identity Lifecycle
OffboardingIdentity LifecycleAccess ManagementIT OperationsInsider RiskComplianceCase study / interactive demo

Case study

From problem to working system

Problem

Offboarding workflow model that tracks every access path an identity holds across identity provider, network, cloud keys, tokens, MFA enrolment, non-SSO SaaS, endpoint, and physical badge, computing the residual access window rather than assuming one account disable is sufficient.

My role

Full-stack software engineer

Solution

Offboarding workflow model that tracks every access path an identity holds across identity provider, network, cloud keys, tokens, MFA enrolment, non-SSO SaaS, endpoint, and physical badge, computing the residual access window rather than assuming one account disable is sufficient.

Architecture

The implementation combines the following technologies and system concerns.

OffboardingIdentity LifecycleAccess ManagementIT OperationsInsider RiskCompliance

How it was built

  • Modelled offboarding as a set of independent access paths, because long-lived cloud keys, personal access tokens, and non-SSO accounts all survive an account disable.

Security decisions

  • Computed the residual access window as the latest open access path, which is the real security metric rather than checklist completion.
  • Distinguished access-granting tasks from hygiene tasks such as resource reassignment, so the security clock is not diluted by administrative items.

Major challenges

  • Separated session revocation from account disabling, since a disabled account with live refresh tokens keeps working for hours.
  • Flagged MFA device unenrolment, which is missed almost universally and is what allows a re-enabled account to complete step-up.
  • Compressed access-granting SLAs under an involuntary termination scenario while leaving hygiene tasks on their normal timeline.

Verified evidence

Results and measurable impact

  • Flagged MFA device unenrolment, which is missed almost universally and is what allows a re-enabled account to complete step-up.
  • Compressed access-granting SLAs under an involuntary termination scenario while leaving hygiene tasks on their normal timeline.
  • Computed the residual access window as the latest open access path, which is the real security metric rather than checklist completion.
  • Distinguished access-granting tasks from hygiene tasks such as resource reassignment, so the security clock is not diluted by administrative items.

No separate numeric outcome is documented, so this section shows shipped technical evidence without inventing metrics.

Screenshots and access

Product view

Interactive Demo

A scoped, fully functional recreation of this project's core feature runs below, live in your browser. Reset it, resize it, or expand it to full screen.

Offboarding

Identity shutdown orchestration

OffboardingWorkspace3 updates

EXIT CASE / ZK-2048

Access revocation command

Shutdown timeline

Deprovisioning runbook

2/11 COMPLETE

T+15M

6 TASKS

T+60M

1 TASKS

T+24H

2 TASKS

LATER

2 TASKS
Zain Khalil Khan