The problem
When someone leaves, their account in your identity provider is switched off. But the shared passwords they knew still work, and nobody has a complete list of which ones those were.
How LayerT handles it
- They never knew the passwords. Shared accounts were signed in for them by LayerT.
- Deactivate them in your directory, as you already do. SCIM tells LayerT at once.
- LayerT ends their access everywhere: console sessions immediately, shared-account sessions and requests revoked, and their browsers signed out of those accounts within about a minute.
- Their browsers un-enrol within the hour, because they can no longer refresh their credentials.
- The audit log shows it, step by step.
Good to know
- LayerT won’t let your directory deactivate the last active Owner, so you can’t lock yourself out.
- Built for JumpCloud today.

