Offboarding in one step

Remove someone in your directory. LayerT ends their sessions and their access everywhere.

A row of paper doors closing, the nearest one teal.

The problem

When someone leaves, their account in your identity provider is switched off. But the shared passwords they knew still work, and nobody has a complete list of which ones those were.

How LayerT handles it

  1. They never knew the passwords. Shared accounts were signed in for them by LayerT.
  2. Deactivate them in your directory, as you already do. SCIM tells LayerT at once.
  3. LayerT ends their access everywhere: console sessions immediately, shared-account sessions and requests revoked, and their browsers signed out of those accounts within about a minute.
  4. Their browsers un-enrol within the hour, because they can no longer refresh their credentials.
  5. The audit log shows it, step by step.

Good to know

  • LayerT won’t let your directory deactivate the last active Owner, so you can’t lock yourself out.
  • Built for JumpCloud today.

Put a layer on the browser.

LayerT is pre-launch and taking demo requests. Tell us what you want to solve, and we’ll show you the product doing it.

A teal paper sheet with a window cut out, lifted over a cream paper browser window.