Skip to main content
Secure Employee Exit Infrastructure

One click.
Zero doors left open.

When an employee leaves, every minute matters. PurpletGo revokes access, recovers assets, and logs everything to a tamper-evident audit trail - in one workflow, not a checklist of manual steps.

Free plan available · No credit card required

Connects with 30+ tools your team already uses

Google WorkspaceMicrosoft 365 / Azure ADOktaJumpCloudOneLoginPing IdentitySlackMicrosoft TeamsBambooHRWorkdayRipplingGustoADP Workforce NowGitHubGitLabJiraFigmaAsanaLinearNotionAWSZendeskFreshdeskServiceNowDocuSignAdobe Acrobat SignDropbox SignCalendlyGoogle CalendarHubSpotMailchimpSalesforceGoogle WorkspaceMicrosoft 365 / Azure ADOktaJumpCloudOneLoginPing IdentitySlackMicrosoft TeamsBambooHRWorkdayRipplingGustoADP Workforce NowGitHubGitLabJiraFigmaAsanaLinearNotionAWSZendeskFreshdeskServiceNowDocuSignAdobe Acrobat SignDropbox SignCalendlyGoogle CalendarHubSpotMailchimpSalesforce
SOC 2 ReadyGDPR CompliantISO 27001 AlignedAES-256 Encrypted

Offboarding breaks in three places. PurpletGo closes all three.

Access stays open

Employees leave. Accounts don't - until someone manually closes every one.

Revoke access in one click

No more missed accounts across Google, Slack, GitHub, and every connected tool.

33 live integrations, one action

Assets go untracked

Laptops, badges, and credentials are easy to lose sight of without a system watching.

Track and recover assets

Know what's assigned, returned, or overdue - flagged automatically.

Unreturned-asset reports, built in

Compliance gaps go unnoticed

Without a logged trail of every action, gaps surface only when an audit goes looking.

Stay audit-ready

Every action logged, every step tracked - audit-ready without extra work.

Actor, timestamp, and org logged - every time

How it works

From notice to closed, in four steps

A structured, enforced workflow that prevents any step from being skipped - so you never have to guess whether an ex-employee still has access.

Repeats for every departure

Security & trust

Your data is in safe hands

Security isn't a feature we added later - it's built into every layer of PurpletGo. Your employee records, compliance documents, and team credentials are protected the way your compliance team expects.

Your credentials are never at risk

Even if our database were ever breached, your passwords cannot be recovered or reused. Every credential is protected with industry-standard one-way encryption before it ever touches storage.

Your data is completely isolated

Every organisation's data is isolated at the database row level using strict org_id partitioning - enforced in every query, not just application code. One tenant's records are never accessible to another.

Compliance documents stay private

NDAs, exit interviews, and sensitive files are stored in a private vault with no direct public links. Only authorised users can view them, and every access automatically expires - no accidental exposure.

Every integration credential is encrypted at rest

API tokens, keys, and secrets for every connected app - Jira, Slack, AWS, and more - are encrypted with AES-256-GCM before they ever touch the database. A database breach alone can never expose a working credential.

Complete paper trail for every action

Know exactly who did what and when - every access revocation, document upload, and team change is logged with full context. Invaluable for HR disputes, compliance reviews, and security investigations.

Two-factor authentication for every account

Every team member can enable TOTP-based two-factor authentication directly from their profile. A time-based one-time code is required at login - so a stolen password alone is never enough to get in.

All traffic encrypted with TLSNo cross-tenant data access - everFile uploads validated for type and sizeRole-based permissions on every actionNo third-party tracking in the product

Every feature you need

No more offboarding blind spots

PurpletGo covers every dimension of a secure employee departure - from the first day of notice to the final compliance report, with enterprise integrations built in.

CoreCore Workflow

One-Click Access Revocation

Suspend accounts across Google Workspace, Slack, GitHub, Okta, and more - every revocation logged.

AutomationCore Workflow

No manual follow-ups

No-code rules that notify HR, auto-assign checklists, and advance stages automatically.

WorkflowCore Workflow

Checklist Templates

Reusable checklists per separation type, with owners, due dates, and task comments.

WorkflowCore Workflow

Offboard 200 people as easily as one

Bulk-create up to 200 offboardings from a CSV or directory selection in one operation.

WorkflowCore Workflow

Bring your whole team in, in one upload

Import up to 500 employees via a guided wizard with auto column mapping.

WorkflowCore Workflow

Track whatever your org actually needs

Add custom text, number, date, or checkbox fields to capture org-specific data.

43 features across 5 categories

Want to learn more? Check out our comprehensive FAQ.

Explore FAQ →

Pricing

Simple, transparent pricing

Start for free. Scale as your team grows. No surprises.

MonthlyAnnual

Free

Free

For solo HR or IT admins evaluating secure offboarding.

  • 5 employees · 1 seat · 25 assets · 2 offboardings/mo
  • IT access revocation (Google, GitHub, Okta…)
  • Audit log & CSV export
  • In-app & email notifications
  • Google OAuth login
Get Started Free

Starter

$39/mo

For growing teams automating employee exits.

  • 20 employees · 5 seats · 100 assets · 5 offboardings/mo
  • Checklist templates & task comments
  • Compliance uploads & PDF export
  • Bulk offboarding & CSV import
  • Slack notifications
Get Started

Growth

$129/mo

For teams adding e-signatures and structured exit interviews.

  • 50 employees · 10 seats · 250 assets · 10 offboardings/mo
  • E-signatures via DocuSign / Adobe Sign / Dropbox Sign
  • Exit interview tracking
  • Priority email support
Get Started
Most Popular

Team

$249/mo

For companies that need reliable, audit-ready offboarding.

  • 100 employees · 20 seats · 500 assets · 20 offboardings/mo
  • Compliance Policy Engine (SOC 2, GDPR, HIPAA)
  • Exit interview scheduling & onboarding bridge
  • AI HR Copilot & predictive alerts
  • Multi-step approvals & SLA dashboard
  • IT ticketing, SMS & offboarding calendar sync
  • Scheduled reports & REST API
Get Started

Enterprise

Custom

For organizations with strict compliance and scale.

  • Unlimited employees, seats, assets & offboardings
  • SAML SSO, SCIM, directory sync & HRIS sync
  • Azure AD / MS 365 deprovisioning & ADP sync
  • White-label branding & custom portal
  • Tamper-evident audit log with legal hold
  • AI exit-letter drafting & risk predictions
  • Multi-org hierarchy & SIEM export
Contact Sales

Start for free - no credit card required. Upgrade or downgrade at any time. Need a custom invoice? Contact us.

FAQ

Questions we get a lot

57 questions answered - search or browse by topic.

The Workflow Automation Engine lets you build no-code rules that trigger actions automatically as an offboarding progresses. You define a trigger - such as a status change (e.g., "entered IT Revocation"), a time condition (e.g., "7 days before exit date"), or an event (e.g., "all checklist items completed") - and pair it with an action: send an in-app notification, fire a templated email, auto-assign a checklist template, or advance the offboarding to the next stage. Rules run silently in the background, eliminating the manual follow-up that usually falls through the cracks. You can test any rule instantly from the Settings → Automations panel before activating it in production.

SCIM (System for Cross-domain Identity Management) is an open standard that lets identity providers push user lifecycle events - provisioning, updates, and deprovisioning - directly to connected apps. In PurpletGo, Enterprise plans can generate a per-org SCIM 2.0 Bearer token in Settings → Integrations. You paste the PurpletGo SCIM endpoint URL and token into your IdP (Okta, Azure AD, JumpCloud, OneLogin, or any SCIM-compatible provider), and from that point on, whenever your IdP deprovisions a user, PurpletGo automatically creates a termination offboarding record for that employee. No polling, no manual triggers - the entire offboarding process is initiated the instant the IdP signals a user removal.

PurpletGo has live connectors for seven identity providers: Google Workspace (account suspend, session sign-out, token revoke), GitHub (org member removal), Okta (user deactivation + session clear), JumpCloud (account suspend), OneLogin (account suspend), Ping Identity (account disable), and Microsoft 365 / Azure AD (account disable, sign-in session revoke, license removal, mailbox OOO). When an employee is offboarded you simply tick the providers to revoke, and PurpletGo handles each one in parallel. Every action is timestamped in the audit log.

When 'Azure AD' is added to the access revocation list on an offboarding, PurpletGo executes four deprovisioning steps in parallel using the Microsoft Graph API: (1) Disable the Azure AD account - this immediately blocks access to every connected Microsoft app, including Teams, SharePoint, and OneDrive. (2) Revoke all active sign-in sessions - any existing browser or mobile session is invalidated within minutes. (3) Remove all assigned Microsoft 365 licenses - recovering the seat for reallocation the same day. (4) Set an out-of-office auto-reply on the departing employee's mailbox, redirecting senders to the manager. Each step is attempted independently so a partial failure doesn't block the others. Every action is logged in the audit trail.

PurpletGo has live integrations with Google Workspace, Slack, GitHub, Okta, JumpCloud, OneLogin, Ping Identity, and Microsoft 365 / Azure AD. HRIS sync is supported for BambooHR, Workday, Rippling, Gusto, and ADP Workforce Now - with automatic termination detection that creates offboarding records without any manual step. IT ticket auto-creation with two-way sync is supported for Jira, Freshdesk, ServiceNow, and Zendesk. Enterprise plans also include a SCIM 2.0 endpoint so any IdP can push deprovisioning events directly to PurpletGo.

Yes - PurpletGo supports three court-admissible e-signature providers:

  • **DocuSign** - connect using your DocuSign account ID and access token. PurpletGo creates a DocuSign envelope, sends the signing email, and receives webhook callbacks via DocuSign Connect when the document is signed or declined.
  • **Adobe Acrobat Sign** - connect with your OAuth access token. PurpletGo uploads the document as a transient asset, creates an agreement, and receives status updates via Adobe Sign webhooks.
  • **Dropbox Sign** (formerly HelloSign) - available as a shared integration on Team and Enterprise plans without additional configuration.

Connect your preferred provider in Settings → Integrations → E-Signature Providers. Once connected, a 'Send for Signature' button appears on every uploaded compliance document (NDAs, severance agreements, exit letters, IP assignments, etc.). Signing status is tracked in real time - pending, signed, declined, or cancelled - and every signed event is written to the tamper-evident audit log.

HR sends a departing employee a secure magic link - no account creation required. The portal gives the employee a complete offboarding experience: My Tasks, Equipment Return, Benefits & COBRA, Reference Letters, and Alumni Network. Every interaction is timestamped in the audit log so HR has a complete record without any back-and-forth.

Knowledge transfer items are structured tasks attached to an offboarding that track which documentation, credentials, and responsibilities have been handed off before the exit date. Each item has a title, description, assignee, and completion status - separate from the main checklist so they can be reviewed independently.

Still have questions?

Email us and we'll get back to you personally.

Email us
Free plan available · No credit card required for the Free plan

Close every departure with confidence

Access revocation, e-signatures, HRIS sync, knowledge transfer, exit interviews, self-service portals, workflow automations, advanced analytics with bottleneck detection, and a tamper-evident audit trail - all in one place.

SOC 2 Ready
GDPR Compliant
ISO 27001 Aligned
TLS Encrypted