Joiner · Mover · Leaver

Onboard, change roles, and offboard without leaving a door open.

The day someone joins, moves, or leaves — every account, license, group, and laptop handled, proven, and audit-ready. Real deprovisioning and the human tasks, in one tracked run.

Join

Create accounts, grant least-privilege access, assign a device — from a role template.

Move

Role or department change: grant the new access and revoke the old — the step most tools forget.

Leave

Disable accounts, revoke sessions, reclaim licenses, demand the laptop back — and prove every bit of it.

What a glorified checklist can't do

At the price of a checklist app, Passage gives an SMB real deprovisioning, device return, and an audit trail an assessor will accept.

Real provisioning + human tasks

One run where automated steps disable accounts and revoke sessions, and manual steps (collect badge, transfer files) are tracked to completion with an owner.

Edge vs BambooHR & Okta
💻

Device return enforced

Assign on join via Cairn; on leave a return task blocks run-closure until the laptop is back or written off. No IGA competitor does this.

Edge vs Okta · Lumos
🛡️

Closure proves itself

Every offboarding emits timestamped, hash-anchored evidence that auto-satisfies access-control & termination controls across your frameworks.

Nobody else closes this loop
🔓

No SSO tax, no impl fee

Okta gates lifecycle behind a $14 base; others charge $2k–$20k to implement. Passage's free tier actually disables accounts. AI is BYO-key.

The market wedge

The 4:55pm-on-a-Friday problem

27%

of cloud breaches in 2024 involved misuse of dormant credentials — many tied to orphaned accounts that offboarding never disabled. The HR action ("Jane is leaving Friday") and the IT action ("disable Jane's accounts") live in separate systems, on separate timelines. That gap is where former-employee access lingers.

Passage runs the leaver as a single tracked run: accountEnabled=falserevokeSignInSessions → reclaim licenses → convert mailbox → device return → evidence. A critical step can't be skipped — the closure gate won't let the run finish until it's done or waived with a reason.

Offboarding that proves itself

One completed run, evidence across every framework — collected once, satisfies many.

HIPAA

§164.308(a)(3)(ii)(C) termination procedures — the access-removal proof your Security Officer needs.

SOC 2

CC6.2 / CC6.3 — logical access provisioned and de-provisioned, with timestamped action logs.

NIST 800-171 / CMMC

3.1.1 / 3.5.6 account management and least privilege — straight into your Bastion SSP & SPRS narrative.

NIST CSF 2.0

PR.AA identity & access — posture flips green in Sightline with Passage as the evidence source.

ISO 27001

A.5.18 access rights & A.5.11 return of assets — device-return enforcement on the record.

Portable evidence

Hash-anchored, signed, exportable. Take it with you — no renewal-escalation lock-in.

Connects to your identity backbone

Four identity connectors modeled end-to-end — Microsoft 365 / Entra, Google Workspace, Okta, and JumpCloud — each with provider-correct disable, session-revoke, license/app, and group steps. JumpCloud app access is handled the right way: through group membership. Live provisioning rolls out per connector.

Microsoft 365 / Entra ID Google Workspace Okta JumpCloud Cairn — device lifecycle HRIS triggers · soon

Per managed employee. No platform fee, no SSO tax.

Annual billing −15%. The free tier actually disables accounts.

Free

$0

Local-first / privacy-first

  • 1 connected tenant
  • M365 or Google
  • Unlimited manual-step runs
  • 5 automated runs/mo
  • CSV evidence export

Team

$7/user/mo

Compliance-driven

  • HRIS trigger ingestion
  • App connectors
  • SLA timers + escalation
  • Manager self-service
  • BYO-key AI features

MSP

$3/user/mo

Volume, annual

  • Multi-tenant console
  • Per-client branding
  • Cross-client reporting
  • Consolidated billing

Nobody keeps access they shouldn't.

Run your first offboarding in minutes — local-first, no card, no implementation call.

Start free