
Observability of trajectories in organizational offboarding
Compliance with each individual point does not guarantee compliance with the overall process. A checklist verifies a single moment in time. The pattern that matters is established before that moment, and no auditor checking only that specific point can see it. The question is not whether the protocol was followed. It is whether anyone can observe what happens before there is a protocol to follow.
There is a well-known problem in auditing and compliance that is rarely phrased in these terms: most control mechanisms are designed to monitor points, not trajectories. A point is a verifiable state at a given moment: it is access granted, a document signed, an action recorded in a log. A trajectory is the sequence of points over time, and it is within this sequence, not in any isolated point, that certain patterns of non-compliance truly manifest.
This distinction is not merely academic. It is the difference between a system that can say "this action, at this moment, complied with the policy’ and a system that can say "this set of actions, over this period, and viewed as a whole, constitutes a deviation". Most organisational audit processes are only capable of answering the first question.
In distributed information systems, this problem has a name: the compliance of each node, assessed in isolation, does not guarantee the compliance of the system as a whole. It is possible that each component, when observed at its own control point, is perfectly correct, and yet the aggregate behaviour of the system, when these points are correlated over time, reveals a pattern of risk that no individual audit point was designed to detect. It is not that the audit fails due to negligence. It fails because of its architecture: each auditor sees their own fragment, and the breach is not in any single fragment; it lies in the seam between them.
Organisational offboarding processes are structured exactly in this way. An employee’s departure is not a one-off event, even though HR systems often treat it as such, typically a date, a checklist, a handover meeting. In practice, it is an extended period, often beginning well before the formal notification, during which multiple stakeholders, such as colleagues, team managers, asset managers and systems administrators, make independent decisions regarding resources, access rights and responsibilities previously associated with that individual. Each decision, taken in isolation, may be administratively justifiable. The reallocation of equipment before the official departure date may have a legitimate operational reason. The early assignment of a responsibility may simply reflect planning. None of these actions, viewed in isolation, triggers any compliance alarm.
The problem arises when one looks at the bigger picture. Not at a single action, but at the temporal pattern of various actions converging before the point at which, formally speaking, there would not yet be grounds for taking them. It is precisely the sort of signal that eludes any single audit point, because no single audit point has visibility over the entire trajectory, only over its own segment of it.
The typical institutional response to offboarding is a checklist: revoking access rights, retrieving equipment, transferring documentation, within a set timeframe from the departure date. It is a point-based mechanism which checks, on a specific date X, that a set of conditions has been met. It is useful and necessary, but structurally blind to what happens before date X, which is precisely where the problematic pattern of early reallocation tends to be concentrated.
This has a direct parallel with a central argument regarding data protection: compliance with the GDPR is not achieved simply by ensuring that, at any given moment, the data is formally protected. Compliance is achieved by ensuring that the entire data journey, across all processors and sub-processors involved, adheres to the principles of Article 5 (data minimisation, purpose limitation, integrity) over time, not just at a single point in time. A system may pass all one-off audits and still process personal data in a non-compliant manner, precisely because the breach arises from the distributed flow of data across systems, and no single audit point has sufficient visibility to detect it. The architecture of the problem is the same: replace "organisational resources assigned to a person" with "personal data processed by a system", and the structure of the supervisory failure remains identical.
The technical solution to this type of problem in distributed information systems does not lie in increasing the number of audit points, but in correlating signals over time, across multiple nodes, to detect patterns that no single node reveals. Applied to organisational offboarding, this would mean treating the departure period not as a single date but as a time window to be observed as a whole: recording not only what happens on the formal date, but the sequence of decisions relating to a person’s assets, access rights and responsibilities, starting well before that date, and flagging when that sequence begins to diverge in an anomalous way.
This is not about monitoring people. It is about recognising that the correct unit of analysis, whether in data protection or organisational governance, is rarely the single point. It is the trajectory. And as long as control mechanisms continue to be designed around dates and checklists, they will remain structurally incapable of seeing what only becomes apparent when one looks at the entire sequence.
Perhaps the most useful question an organisation can ask itself is not "have we followed the exit protocol?", but rather: "have we even managed to observe what happens before there is a protocol to follow?".
Duarte Dionísio 

