
Blog Post
The Leaver Window and the Destination Nobody Sees
September 5, 2026
An engineer resigns and works a thirty-day notice. Access stays in place, correctly, because stripping production and repository rights on a resignation without cause breaks the handover the notice period exists for. Over two days in week three they pull a large volume of customer records, mirror repositories they have never cloned before, and move several hundred megabytes into AI assistants.
Nothing is blocked and nothing should have been, because every individual action was permitted and every individual system read it correctly. The exposure exists in the combination, and the part that decides how bad it is arrives last.
Why Is the Notice Period the Hard Case?
Because the compliant leaver and the departing exfiltrator are indistinguishable at the level any single control operates.
The directory holds the leave date and correctly assigns no risk signal, since group memberships still grant the rights the role requires. A large query against production returns rows because the role permits it. Repository clones proceed because a staff engineer clones repositories. Volume to an external destination looks unremarkable to a proxy that cannot inspect the traffic. Each source is complete, accurate and blind to what the others hold.
Doesn't the Leave Date Change the Assessment?
It should and usually does not, because the leave date sits in a system that holds no behavioral data and the behavioral systems hold no leave date. Joining those two is the whole exercise, and it is a join nobody performs by default. The directory knows whose behavior is worth watching more closely, and it has no visibility into behavior.
What Does Each Source Contribute?
A different fragment, and no source holds enough to act on. The distribution is the reason this pattern survives well-instrumented environments.

Identity supplies the leave date and the still-active entitlements. The data platform names what the query returned, which is the only source that knows the extract held production customer records rather than test data. The endpoint captures the staging, meaning the clones assembled into a local archive, with no field for how many bytes later left the machine, which the signals worth forwarding to a SOC covers in more detail. The network supplies the velocity, a volume many times the personal baseline, without content. The browser returns the destination account.
Which of Those Is Load-Bearing?
The destination, and it arrives from the source with the narrowest coverage. Volume tells you something moved. The data platform tells you what it was. Only a view inside the session tells you whose account received it, and that distinction decides the entire response.
Why Does the Destination Account Matter So Much?
Because it separates recoverable data from unrecoverable data, and the same export can produce both.
Content entering a corporate AI account under contract is locatable and deletable on demand, with proof of deletion available. Content entering a personal account sits outside every enterprise agreement, where recovery depends on the individual's cooperation or a court order rather than anything the security team can execute. One export, two destinations, and only one half comes back.
Which Changes What the Response Is
An exfiltration into governed destinations is a deletion request and a documented closure. The same volume into personal accounts is a legal matter, a notification assessment and a negotiation with somebody who no longer works there. Programs that detect volume without destination know something happened and cannot tell which of those two situations they are in, which is the difference between a contained incident and an open one.
Why Doesn't Volume Detection Work Alone?
Because baselines are personal and roles differ enormously. A data engineer moving large volumes is doing their job, and a threshold set to catch them generates alerts nobody can triage.

The useful signal is a multiple of that individual's own history rather than an absolute figure. Someone whose ninety-day median is a few megabytes moving hundreds is a deviation regardless of what the team average looks like. An AI data fabric holds those baselines per identity rather than per source, which is what makes the comparison possible at all. Absolute thresholds catch the wrong people and miss the right ones, which is why behavioral baselines matter more than volume ceilings.
What Makes the Conjunction Reliable?
Three facts together rather than any one. An identity inside a notice window, a volume that is a large multiple of that person's own baseline, and a destination outside enterprise agreements. Each is weak alone and the three together describe a situation with no innocent reading, which is what makes it reportable rather than merely suspicious.
Where Does This Produce False Positives?
Handover work, and stating the limit matters because a control that flags diligent leavers gets turned off.
Somebody documenting their systems before departure legitimately reads widely, exports more than usual and may use AI tools to summarize what they are handing over. Two of the three signals fire and the pattern looks similar. The destination is what separates them, since handover into corporate tools is the behavior the organization asked for, and it is the one signal most programs lack. The content side of the same problem behaves similarly.
Which Argues for Reviewing Rather Than Blocking
A leaver window is a period for closer observation rather than restriction. Blocking access during notice defeats the handover, generates disputes and pushes the same activity onto personal devices. Watching more carefully, with the destination visible, keeps the work possible and the exposure observable, and an AI Interaction Data Fabric is what supplies the destination without adding a restriction.
Does This Only Apply to Resignations?
No, and the resignation case is the easiest one because the date is known. Three other situations produce the same conjunction without a notice period to bound them.
A contractor whose engagement is ending, where the access review runs on a different cycle from the contract. An employee who has been told a role is at risk, where the organization knows the motivation exists and no leave date has been set. A team learning of a reorganization is the third case, where nobody individually is leaving and several people simultaneously have reason to secure their own position. The last is the hardest, since there is no individual date to trigger on.
What Substitutes for a Leave Date?
Any recorded change in the employment relationship, which is a broader feed than personnel systems usually expose. Contract end dates, role-at-risk flags and reorganization scopes are all held somewhere and rarely routed anywhere. Where none is available, the per-identity baseline still works on its own, with a higher review threshold to keep the volume manageable.
Which Direction Should the Threshold Err?
Toward review rather than alert. A deviation during a known transition deserves somebody looking, not an incident record, since most of what turns up is legitimate work and treating it as an incident burns the credibility the control needs when a real case appears. Whether that review is genuine is a separate question with its own measurement.
What Can Be Prepared in Advance?
Four things, and the first two require no new tooling.
- A Notice-Window Feed: Somebody or something has to receive leave dates, since a date sitting in a personnel system nobody watches produces nothing.
- Per-Identity Baselines: Volume history per person rather than per team, which most network and AI telemetry already contains unread.
- Destination Classification: Whether an AI session ran under a corporate or personal account, which is the source most environments lack.
A response rule completes it, deciding in advance what happens at each combination rather than debating it during a notice period. Where the destination is governed, a deletion request and a closed record. Where it is not, counsel and a notification assessment, since producing evidence on somebody else's timeline is considerably harder when the decision is being made for the first time.
How Should the Exposure Be Sized?
Size it by the unrecoverable portion rather than the total, which is a materially smaller number and the only one that matters for a notification decision.
Data recovered from a corporate account with proof of deletion is a handled incident. The exposure is whatever entered destinations the organization cannot reach, valued by the records involved and the regime covering them. Splitting the figure that way also gives the security team something to argue for, since the destination-visibility source is the one that shrinks the unrecoverable half, and AI risk quantification prices that difference rather than asserting it.
The Destination Is the Finding
A departing employee with intact access is compliant in every system that observes them, and correctly so, because notice periods exist for handover and access is not stripped without cause. The exposure lives in a conjunction no single source can see, being an identity inside a leave window moving a large multiple of its own baseline into an account nobody has classified. The destination arrives last and decides everything, because it separates data that can be recalled with proof from data that requires somebody's cooperation after they have gone. Kovrr's AI Security and Governance Platform joins the leave date, the volume and the destination account into one record, which is where that distinction becomes visible.
To see whether AI sessions in your environment can be resolved to corporate or personal accounts, book a demo mapped to your own estate.
Leaver Window FAQs
Speak to an ExpertWhy is the notice period the hardest insider case?
Because a compliant leaver and a departing exfiltrator are indistinguishable at the level any single control operates. The directory holds the leave date and correctly assigns no risk signal, since group memberships still grant the rights the role requires. A large production query returns rows because the role permits it. Repository clones proceed because a staff engineer clones repositories. Volume to an external destination looks unremarkable to a proxy that cannot inspect traffic. Each source is complete, accurate and blind to what the others hold.
Why does the destination account matter more than the volume?
Because it separates recoverable data from unrecoverable data, and the same export can produce both. Content entering a corporate AI account under contract is locatable and deletable on demand with proof of deletion available. Content entering a personal account sits outside every enterprise agreement, where recovery depends on the individual's cooperation or a court order rather than anything the security team can execute. One export, two destinations, and only one half comes back.
Why doesn't volume detection work on its own?
Because baselines are personal and roles differ enormously. A data engineer moving large volumes is doing their job, and a threshold set to catch them generates alerts nobody can triage. The useful signal is a multiple of that individual's own history rather than an absolute figure, so someone whose ninety-day median is a few megabytes moving hundreds is a deviation regardless of the team average. Absolute thresholds catch the wrong people and miss the right ones.
What combination makes the pattern reportable?
Three facts together rather than any one. An identity inside a notice window, a volume that is a large multiple of that person's own baseline, and a destination outside enterprise agreements. Each is weak alone, and the three together describe a situation with no innocent reading. The destination is the load-bearing one and it arrives from the source with the narrowest coverage, since only a view inside the session reveals whose account received the content.
Where does this produce false positives?
Handover work, and the limit matters because a control that flags diligent leavers gets turned off. Somebody documenting their systems before departure legitimately reads widely, exports more than usual and may use AI tools to summarize what they are handing over, so two of the three signals fire and the pattern looks similar. The destination separates them, since handover into corporate tools is the behavior the organization asked for, and it is the signal most programs lack.
Should access be restricted during a notice period?
Generally not, since blocking access defeats the handover the notice period exists for, generates disputes and pushes the same activity onto personal devices where there is no visibility at all. A leaver window is a period for closer observation rather than restriction. Watching more carefully with the destination visible keeps the work possible and the exposure observable, which is a better position than a restriction that moves the activity somewhere unmonitored.




