- 28 Jun 2024
- 2 Minutes to read
- Print
- DarkLight
- PDF
Offboarding Validation Checklist
- Updated on 28 Jun 2024
- 2 Minutes to read
- Print
- DarkLight
- PDF
Before you begin
Verify each application in your environment is either set to disable or delete services users on termination.
Verify any Dynamic Database applications have the appropriate disable or delete queries provided in the Application SQL configuration
You only need one or the other (Disable or Delete)
Verify that each Application has the correct Trust Permission
Create custom “Identity Terminated” workflow with a Condition to limit the scope of the workflow
Provide a name that makes it obvious this Role is for testing
Add Trigger: Identity Terminated
Add Condition: Identity Attributes or Identity Roles (to limit the scope of workflow for testing)
Configure the Conditions scope to save
Optional: Add any approvals (Action: Termination - Approval Request) in the workflow before the provisioning step.
Configure the options to save.
Add Action: DeProvision Identity
Add Action: Terminate an Identity
Optional: Add any notifications (Action: Send Email - Termination Alert) to the workflow as needed for your process.
Click the blue Save button in the upper right
Modify or disable your original “Identity Terminated” workflow so it does not terminate users (your custom workflow above handles the scope of your testing).
Remove Action: DeProvision Identity
Remove Action: Terminate an Identity
Optional: Remove Action: Send Email - Termination Alert
Enable your custom Identity Terminated workflow
Record the list of applications and entitlements attached to the Identity you plan to use for testing.
Using an existing Test user in your HRIS with the appropriate attributes to match your Organizational Units
Terminate this user
Wait or Sync the above application to trigger Clarity to pull in the user changes
After the sync is complete, refresh your webpage, and search for your Test user.
Verify in Clarity that you see both Entitlements have been removed and application service users disabled or deleted (depending on your configuration).
For each application previously on the Identity, check that the downstream Service User was deleted or disabled as configured (Not all connectors have both options disable and delete, if one is not available this is due to API limitations of the vendor).
For each application configured for disable on termination, check if the list of entitlements previously associated with the Identity have been removed.
Disable any custom workflows created for testing (these typically have additional steps such as Conditions, which limited the scope for testing.
Re-Enable or add the steps removed above from your original Identity Terminated workflow
Duplicate any desired approvals or notifications from your tests.
If you have any problems, contact your customer success team. You can also get in touch with our general support via email, open a support ticket. Our general support team is available Monday - Friday from 8:00 AM - 6:30 PM CST.