Scope: identify every approved departure, role change, or task-lane closure affecting outsourced personnel in one defined period and system set. Record the required removal time under the policy in force for each event. Include transferred, suspended, reactivated, service, and shared accounts as separate categories.

Methodology: join the approved change record, identity directory, access request, system permission export, disable event, exception approval, and verification timestamp by stable identifiers. Calculate lag only when both trigger and removal are evidenced. Classify unverified cases separately and have a second reviewer inspect a risk-based sample.

Inference boundaries: CISA, NIST, and GAO support identity governance, least privilege, and control evidence. They do not certify a removal workflow, set one universal deadline, or prove that delayed removal caused misuse. The audit reports documented state transitions for the selected systems.

Limitations: synchronization delay, emergency exceptions, shared credentials, incomplete logs, time-zone conversion, and retroactive tickets can bias elapsed time. A disabled account does not prove every token or downstream permission was revoked, so report the systems and verification limits explicitly.