Offboarding is not finished when the network account closes. The real test is whether every conversation, group and document follows the employee out of the door.

On Thursday at eleven, Tarek handed back the laptop.

The badge followed. He signed the clearance form, shook his manager's hand, and left after four and a half years.

Eleven minutes. Every step done correctly.

That evening, on his personal phone: nine work groups nobody removed him from. Eight contracts sitting in the device's memory as auto-saved files. Photos of the pricing sheet a colleague sent two months ago. A full thread about a client who still hasn't signed. And three voice notes from a meeting that was never meant to be recorded.

He took none of it. All of it has been there since day one, because that is where the organisation asked him to work.

01What the organisation actually got back

A clearance form is built to recover what you can see and own: a device, an access card, a drawer key, a vehicle, a network account.

Visible assets. You know they exist, you know the count, you know who holds them.

What nobody recovered on Thursday is everything that moved through a personal messaging app over four and a half years. Nobody knows how much. Nobody ever could. No log, no inventory, no single screen you can put in front of a security manager that says: here is what Tarek is holding right now.

The network account was disabled before he reached the car park. The nine groups are still running, and his phone is still in them.

02The problem is not Tarek

This is exactly where most people get the diagnosis wrong.

Tarek broke no policy. He smuggled nothing out. He used the channel he found on his first day, the one his manager uses, the one his first instruction arrived through. When the unofficial channel is the only one that moves fast enough, it becomes the official one in practice. Using it is compliance, not misconduct.

The colleague who sent the pricing sheet did nothing wrong either. He was trying to finish before the end of the day.

The failure isn't individual behaviour. It's that the organisation has no one place it can go to end Tarek's access. It has a control for email, one for the network, one for the finance system. It has nothing at all for a group living on a phone it doesn't own.

03Who is the user, actually?

In personal messaging apps, identity is a phone number. Perfectly sensible for personal use. Ungovernable inside an institution.

The number belongs to the employee, not to you. It travels to his next job, and to a competitor if that's where he lands. And it carries no link to his employment status: the app has no idea Tarek left, and there's no way to tell it.

In Tawasol, the organisation defines identity. Employees sign in with organisational credentials or role, and you can relabel the login fields to match your own terminology — Employee ID, National ID, Passport Number. Identity can be tied to Active Directory so sign-in is unified and controlled from one place. Each user gets granular permissions that follow their role.

The practical difference is clean. Tarek's membership isn't nine separate relationships on a phone. It's one line inside your organisational structure. When he leaves, an admin removes him from the member list in the dashboard: one step, one confirmation. And when ten people leave in the same month, there's bulk removal from a single file.

Nobody has to remember nine groups, because there's only one thing to remember.

04Where do the files actually live?

The second question, and it always gets asked late: where are the documents that passed through those conversations?

In personal messaging apps, files sit on the provider's servers, outside your perimeter. The conversations are encrypted, yes. But the data has left your control, and your ability to apply your own policy left with it.

Tawasol deploys inside your own data centre, or in a private cloud, running over the internet or over a purely local network. Data is encrypted in transit (TLS) and at rest (AES-256), and files stay on servers inside the organisation — your keys, your infrastructure, no third party in the middle.

This isn't a row in a comparison table. It's the paragraph an auditor reads when they ask where the data sits and who holds the keys — and in Egypt and Saudi Arabia today, that's the first question asked, not the last.

Before you read on, run this yourself. Ask HR for the last three people who left. Then ask IT, name by name: what actually closed the day they walked out, and what is still open? Open any old work group and search for their numbers. Half an hour, and you need nobody from outside the organisation. What you end up holding is the size of your current exposure, in your own handwriting.

05Downloading is not a permanent right

This is the difference that shows up months after someone leaves.

In a personal group, attachments are freely downloadable. Every file reaches every member, saves to every device, and that's it. When the employee leaves, he keeps everything he ever downloaded. There is no second stage and no way back.

In Tawasol, downloading an attachment requires prior permission. The corporate library is central, and every file in it carries a security status that determines whether it can be downloaded at all. Permissions follow job role: a document reaches the people whose role requires it, not everyone who happened to be in a conversation.

And the part that matters on Thursday: a departing employee's permissions are revoked when they leave, and their access to files goes with them.

That changes what the asset is. The document stops being a copy that spread irreversibly and becomes a resource that stays under management.

06What if someone photographs the screen?

Fair objection: if he can photograph it, what did any of this achieve?

Which is why leakage isn't handled by access control alone.

In Tawasol, screenshots and screen recording can be blocked or restricted, and dynamic watermarking is applied to sensitive documents. Two effects: casual copying gets expensive, and when a document does leave, the image carries a trace back to its source.

The difference between a leak you can attribute and one you can't is the difference between an incident that closes and an incident that stays open forever.

Replay Thursday Same scene. Everything above in place.

Tarek signs at eleven. At five past, an admin opens the dashboard and removes him from the member list. One step, in one place. His membership in all nine groups ends, and his library permissions are revoked with it.

The eight contracts were never copies on his device. They were documents in a central library he reached by virtue of his role, and some of them were never downloadable in the first place. The role ended, and the access ended with it.

The pricing sheet was never photographed, because the screen was restricted. And the one document that genuinely was printed carries a watermark that knows exactly who was looking at it, and when.

He returned the laptop and the badge. This time, he returned the access too.

The whole difference is that access became something the organisation owns and can see, instead of something living on a device it neither owns nor sees.

07The missing page in your clearance form

Someone will leave your organisation this month. The form they sign covers the laptop, the badge, and the drawer key, and says nothing about four years of conversations and documents. It was written for a world where assets were things you carried in your hand.

The failure was never Tarek. The failure is that the form doesn't know to ask about the part that matters.

Send us your current offboarding steps and we'll return them written up as an Offboarding Exposure Report: at each step, what actually closes, what stays open after the employee leaves, and who owns the decision to close it. A written document for your risk committee, not a slide deck. Send it to contactus@tawasolapp.com with "Offboarding Exposure Report" in the subject line.

Tawasol. Your team, connected.