how to audit github org membership for departed employees
Audits GitHub org membership for departed employees: finding and removing stale members. Use for quarterly access reviews or after offboarding gaps. Not for repo permission design.
TL;DR
Departed employees linger in GitHub orgs when offboarding misses the step. Audit by comparing the member list against HR records, remove stale members, and automate the check so it stops recurring.
The query
how to audit github org membership for departed employeesUse this when
- quarterly access review of the GitHub org
- offboarding audit found stale members
- proving to auditors that ex-employees are gone
Not for
- designing team and repo permission models
- removing outside collaborators with active contracts
- GitHub Enterprise Server (similar, different UI)
Steps
- Export the full org member list from GitHub. Expected output: complete member roster
- Compare against the current employee roster from HR. Expected output: stale members identified
- Check each stale member for recent activity before removing, to catch contractors. Expected output: no active contributors removed by mistake
- Remove departed employees from the org. Expected output: org membership clean
- Add GitHub removal to the offboarding checklist if it was missing. Expected output: process gap closed
- Schedule the audit quarterly and keep the reports. Expected output: recurring evidence
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_ywF4hphd4iQYv-TkpDIrwg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.