I Hate Terminating Deceased Accounts
Woke up this morning checked my emails and saw a 25 year old girl that worked for our company got in a motorcycle accident last night and died. Worst part of...
I Hate Terminating Deceased Accounts
Introduction
Woke up this morning checked my emails and saw a 25 year old girl that worked for our company got in a motorcycle accident last night and died.
Worst part of my job is terminating accounts of deceased people. This is the 4th person I’ve had to in the 11 years I’ve been doing it.
Hope you all have an uneventful week with no alerts.
— Reddit post by a DevOps engineer
This opening, familiar to many in the system administration community, captures a rarely discussed aspect of DevOps work. While the public face of DevOps showcases exciting deployments, cloud migrations, and automation triumphs, there sits a more somber responsibility: the termination of accounts belonging to colleagues who have passed away. It’s a task that combines technical precision with human empathy, requiring both systematic approach and personal compassion.
In the 15+ years I’ve spent in infrastructure management, I’ve learned that account termination isn’t merely about revoking access—it’s about respecting the departed, protecting organizational security, and ensuring business continuity. When a team member dies, their digital footprint remains: email inboxes, code repositories, CI/CD pipelines, cloud resources, VPN credentials, and countless other system accesses. Each represents potential security risk, unnecessary cost, and emotional burden for surviving colleagues.
This comprehensive guide explores the practical, technical, and human aspects of terminating deceased accounts in DevOps and infrastructure environments. We’ll cover established procedures, compliance considerations, automation strategies, and the importance of documentation. Whether you’re a sysadmin managing a homelab or a DevOps engineer responsible for enterprise infrastructure, you’ll find actionable insights for handling these difficult situations with professionalism and care.
Understanding the Topic
What This Entails
Terminating deceased accounts refers to the systematic process of disabling, removing, or transferring access credentials and digital assets belonging to employees who have passed away. This isn’t a standard “employee offboarding” scenario—it involves additional legal, emotional, and technical considerations that require specialized handling.
In practice, this process typically involves several interconnected steps:
- Account Identification: Locating all systems where the deceased had access
- Access Revocation: Disabling or deleting user accounts across platforms
- Data Preservation: Determining what data should be archived, transferred, or deleted
- Resource Release: Freeing up IP addresses, ports, licenses, and other allocations
- Documentation: Creating records for compliance and future reference
Why This Matters for DevOps
From a technical standpoint, deceased accounts represent significant security vulnerabilities. Unattended accounts become “zombie credentials”—active but unmonitored access points that could be exploited by malicious actors. Additionally, cloud resources left running under deceased accounts incur unnecessary costs. In regulated industries, failure to properly terminate accounts can result in compliance violations under frameworks like GDPR, HIPAA, or SOX.
From an operational perspective, the task falls to the very people who were closest to the departed—colleagues who must balance grief with professional duties. The Reddit post that opened this discussion resonated because it acknowledges this reality: DevOps engineers often serve as the de facto administrators of their organization’s digital legacy.
Historical Context
The practice of managing deceased user accounts isn’t new, but the DevOps angle has evolved significantly. In mainframe eras, account termination involved physical punch cards and manual mainframe sessions. With the rise of client-server architectures in the 1990s, it became about removing UNIX accounts, Novell NetWare volumes, and early directory services.
The modern era of cloud computing and SaaS proliferation has complicated matters. A single employee might have access to:
- On-premises Linux servers
- AWS, Azure, or GCP accounts
- GitHub, GitLab, or Bitbucket repositories
- CI/CD pipelines (Jenkins, GitHub Actions, GitLab CI)
- VPN and SSH key infrastructure
- Project management tools (Jira, Trello, Asana)
- Communication platforms (Slack, Microsoft Teams, email)
- Knowledge bases and documentation wikis
Each of these requires different termination procedures, making the DevOps engineer’s role increasingly complex.
Key Features of Proper Account Termination
While there’s no single “tool” for this process, effective handling shares several characteristics:
Comprehensive Inventory: Maintaining up-to-date asset inventories that include not just what systems exist, but who has access to them.
Automated Offboarding Scripts: Well-designed scripts that can systematically revoke access across known platforms, reducing manual effort and ensuring nothing is overlooked.
Legal and Compliance Framework: Clear policies addressing data retention, privacy laws, and organizational requirements.
Escalation Paths: Defined procedures for when standard offboarding isn’t applicable, such as in death scenarios.
Documentation and Knowledge Sharing: Ensuring that termination procedures are recorded and accessible, so future administrators can handle these situations appropriately.
Pros and Cons of Current Approaches
Manual Processes:
- Pros: Allow for careful consideration of what should be preserved vs. deleted; enable human judgment about sensitive data
- Cons: Time-consuming; prone to oversight; inconsistent application across systems; emotionally taxing for the administrator
Automated Scripts/Tools:
- Pros: Consistent application; faster execution; reduces risk of missed accounts; can be audited and reproduced
- Cons: May not handle nuanced decisions about data preservation; requires careful testing to avoid accidentally deleting important information; initial setup effort
Hybrid Approaches (recommended):
- Automated scripts handle routine revocation
- Human oversight reviews critical decisions
- Documentation ensures continuity
Use Cases and Scenarios
Immediate Post-Event: Within 24-48 hours of notification, the priority is security—disabling all known access points, changing shared passwords, and securing sensitive systems.
Short-Term (1-4 weeks): Data preservation decisions are made. Email archives may be exported. Code repositories may be tagged with memorial markers. Cloud resources are right-sized or terminated.
Long-Term (1+ year): Final disposition of assets. Some organizations maintain “memorialized” accounts with restricted access. Others complete deletion per retention policies.
Current State and Trends
The industry is moving toward more systematic approaches. Some notable trends include:
- Identity Governance and Administration (IGA) platforms increasingly offering “deceased user” handling as a feature
- Automated lifecycle management tools that can detect inactive accounts and trigger termination workflows
- Policy-as-code approaches where termination rules are defined in configuration management tools like Terraform or Ansible
- Increased recognition of the need for compassionate offboarding procedures, not just for death scenarios but for all employee departures
How It Compares to Alternatives
Traditional IT asset management focuses on active employees. Offboarding tools exist for voluntary departures but rarely address death scenarios. The key difference is that deceased account termination often lacks the usual triggers (exit interviews, badge returns, HR paperwork), requiring alternative notification and verification methods.
Real-World Applications
Organizations approach this variably. Tech companies with strong DevOps cultures often have more mature procedures, recognizing that their engineers face these situations regularly. More traditional enterprises may lack formal processes, leaving the task to whoever happens to notice the situation—which is precisely the scenario described in the Reddit post that inspired this guide.
Prerequisites
Before undertaking account termination procedures, several prerequisites should be addressed:
System Requirements
Access Inventory: A current record of all systems where the deceased had accounts. This might include configuration management databases (CMDBs), directory services (LDAP/Active Directory), or informal spreadsheets.
Privilege Level:
