## TL;DR
Export every account from the acquired tenant, cross-check against the current HR roster, and sort into matched, no-HR-record, and duplicate. Disable the orphans first, wait out an objection period, then delete. Disable-before-delete is the rule because an acquisition always hides a few accounts someone still needs.

## Steps
1. Export the full user list from the acquired tenant (Okta, Entra, or Google), including last-login date and department. Expected: one row per account, no filters yet.
2. Cross-check against the current HRIS roster. Expected: three buckets: matched to an employee, no HR record, and already disabled but still present.
3. Pull service accounts into a separate list. Expected: every service account has a named owner, or is marked ownerless; service accounts never match HR and must not be auto-deleted.
4. Hunt duplicates: the same person with an account in both tenants. Expected: a pairing list mapping each old account to its new-tenant counterpart.
5. Disable the no-HR-record accounts in one batch and notify their last-known managers with a 30-day objection window. Expected: accounts disabled, mail forwarding set where the business asks for it.
6. After 30 days with no objection, delete the orphans or convert leftovers to shared mailboxes. Expected: a re-run of the export shows zero orphan accounts.

## Use this when
- An acquisition closed and tenants are being merged
- A security review asks whose accounts these are
- Users are confused by duplicate logins across tenants

## Not for this skill when
- Routine quarterly stale-account reviews (use the standard deprovisioning process)
- The acquired tenant stays separate long-term (run the review, but do not merge)

## Compatibility
- Okta, Entra ID, Google Workspace as the acquired tenant
- Any HRIS or payroll export as the roster of truth

## Variants
### The acquired company has no HRIS
Use payroll records or written manager attestation as the roster. Imperfect beats nothing.
### Founders want everything kept
Disable with forwarding and revisit in 90 days. Disabled is safe; deleted is forever.

## Why it happens
Acquisitions transfer accounts without transferring the offboarding discipline that maintained them. The new company inherits every ghost the old company forgot to clean up.

## Edge cases
- Shared mailboxes misidentified as user accounts: check the mailbox type before disabling.
- Legal-hold accounts that must not be deleted: mark them hold, disable sign-in, document why.
- Acquired employees rehired later: reactivation from a disabled account beats recreating one.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_Q0KyQaROp82LzoBQ7AGDJA
