Your credentials are never at risk
Even if our database were ever breached, your passwords cannot be recovered or reused. Every credential is protected with industry-standard one-way encryption before it ever touches storage.
When an employee leaves, every minute matters. PurpletGo revokes access, recovers assets, and logs everything to a tamper-evident audit trail - in one workflow, not a checklist of manual steps.
Free plan available · No credit card required
Connects with 30+ tools your team already uses
Access stays open
Employees leave. Accounts don't - until someone manually closes every one.
No more missed accounts across Google, Slack, GitHub, and every connected tool.
33 live integrations, one actionAssets go untracked
Laptops, badges, and credentials are easy to lose sight of without a system watching.
Know what's assigned, returned, or overdue - flagged automatically.
Unreturned-asset reports, built inCompliance gaps go unnoticed
Without a logged trail of every action, gaps surface only when an audit goes looking.
Every action logged, every step tracked - audit-ready without extra work.
Actor, timestamp, and org logged - every timeHow it works
A structured, enforced workflow that prevents any step from being skipped - so you never have to guess whether an ex-employee still has access.
Repeats for every departure
Integrations
PurpletGo connects directly to your identity, HR, collaboration, and ticketing stack. No scripts, no manual processes - one click revokes access everywhere at once.
Suspend accounts, remove group memberships, and revoke Drive access instantly.
LiveSends real-time alerts, and can deactivate the account and revoke sessions with an admin token.
LiveSyncs your directory and auto-triggers offboarding on termination.
LiveRemove org membership and revoke repository access across all teams.
LiveAuto-creates tickets with offboarding context, closed automatically when resolved.
LiveCourt-admissible e-signatures for NDAs and exit documents, sent from the record.
LiveAuto-generates booking links so employees self-schedule exit interviews.
LiveStream tamper-evident audit events to Splunk, Datadog, or any webhook target via HMAC-signed payloads.
Security & trust
Security isn't a feature we added later - it's built into every layer of PurpletGo. Your employee records, compliance documents, and team credentials are protected the way your compliance team expects.
Even if our database were ever breached, your passwords cannot be recovered or reused. Every credential is protected with industry-standard one-way encryption before it ever touches storage.
Every organisation's data is isolated at the database row level using strict org_id partitioning - enforced in every query, not just application code. One tenant's records are never accessible to another.
NDAs, exit interviews, and sensitive files are stored in a private vault with no direct public links. Only authorised users can view them, and every access automatically expires - no accidental exposure.
API tokens, keys, and secrets for every connected app - Jira, Slack, AWS, and more - are encrypted with AES-256-GCM before they ever touch the database. A database breach alone can never expose a working credential.
Know exactly who did what and when - every access revocation, document upload, and team change is logged with full context. Invaluable for HR disputes, compliance reviews, and security investigations.
Every team member can enable TOTP-based two-factor authentication directly from their profile. A time-based one-time code is required at login - so a stolen password alone is never enough to get in.
Every feature you need
PurpletGo covers every dimension of a secure employee departure - from the first day of notice to the final compliance report, with enterprise integrations built in.
Suspend accounts across Google Workspace, Slack, GitHub, Okta, and more - every revocation logged.
No-code rules that notify HR, auto-assign checklists, and advance stages automatically.
Reusable checklists per separation type, with owners, due dates, and task comments.
Bulk-create up to 200 offboardings from a CSV or directory selection in one operation.
Import up to 500 employees via a guided wizard with auto column mapping.
Add custom text, number, date, or checkbox fields to capture org-specific data.
43 features across 5 categories
Want to learn more? Check out our comprehensive FAQ.
Explore FAQ →Pricing
Start for free. Scale as your team grows. No surprises.
For solo HR or IT admins evaluating secure offboarding.
For growing teams automating employee exits.
For teams adding e-signatures and structured exit interviews.
For companies that need reliable, audit-ready offboarding.
For organizations with strict compliance and scale.
Start for free - no credit card required. Upgrade or downgrade at any time. Need a custom invoice? Contact us.
FAQ
57 questions answered - search or browse by topic.
The Workflow Automation Engine lets you build no-code rules that trigger actions automatically as an offboarding progresses. You define a trigger - such as a status change (e.g., "entered IT Revocation"), a time condition (e.g., "7 days before exit date"), or an event (e.g., "all checklist items completed") - and pair it with an action: send an in-app notification, fire a templated email, auto-assign a checklist template, or advance the offboarding to the next stage. Rules run silently in the background, eliminating the manual follow-up that usually falls through the cracks. You can test any rule instantly from the Settings → Automations panel before activating it in production.
SCIM (System for Cross-domain Identity Management) is an open standard that lets identity providers push user lifecycle events - provisioning, updates, and deprovisioning - directly to connected apps. In PurpletGo, Enterprise plans can generate a per-org SCIM 2.0 Bearer token in Settings → Integrations. You paste the PurpletGo SCIM endpoint URL and token into your IdP (Okta, Azure AD, JumpCloud, OneLogin, or any SCIM-compatible provider), and from that point on, whenever your IdP deprovisions a user, PurpletGo automatically creates a termination offboarding record for that employee. No polling, no manual triggers - the entire offboarding process is initiated the instant the IdP signals a user removal.
PurpletGo has live connectors for seven identity providers: Google Workspace (account suspend, session sign-out, token revoke), GitHub (org member removal), Okta (user deactivation + session clear), JumpCloud (account suspend), OneLogin (account suspend), Ping Identity (account disable), and Microsoft 365 / Azure AD (account disable, sign-in session revoke, license removal, mailbox OOO). When an employee is offboarded you simply tick the providers to revoke, and PurpletGo handles each one in parallel. Every action is timestamped in the audit log.
When 'Azure AD' is added to the access revocation list on an offboarding, PurpletGo executes four deprovisioning steps in parallel using the Microsoft Graph API: (1) Disable the Azure AD account - this immediately blocks access to every connected Microsoft app, including Teams, SharePoint, and OneDrive. (2) Revoke all active sign-in sessions - any existing browser or mobile session is invalidated within minutes. (3) Remove all assigned Microsoft 365 licenses - recovering the seat for reallocation the same day. (4) Set an out-of-office auto-reply on the departing employee's mailbox, redirecting senders to the manager. Each step is attempted independently so a partial failure doesn't block the others. Every action is logged in the audit trail.
PurpletGo has live integrations with Google Workspace, Slack, GitHub, Okta, JumpCloud, OneLogin, Ping Identity, and Microsoft 365 / Azure AD. HRIS sync is supported for BambooHR, Workday, Rippling, Gusto, and ADP Workforce Now - with automatic termination detection that creates offboarding records without any manual step. IT ticket auto-creation with two-way sync is supported for Jira, Freshdesk, ServiceNow, and Zendesk. Enterprise plans also include a SCIM 2.0 endpoint so any IdP can push deprovisioning events directly to PurpletGo.
Yes - PurpletGo supports three court-admissible e-signature providers:
Connect your preferred provider in Settings → Integrations → E-Signature Providers. Once connected, a 'Send for Signature' button appears on every uploaded compliance document (NDAs, severance agreements, exit letters, IP assignments, etc.). Signing status is tracked in real time - pending, signed, declined, or cancelled - and every signed event is written to the tamper-evident audit log.
HR sends a departing employee a secure magic link - no account creation required. The portal gives the employee a complete offboarding experience: My Tasks, Equipment Return, Benefits & COBRA, Reference Letters, and Alumni Network. Every interaction is timestamped in the audit log so HR has a complete record without any back-and-forth.
Knowledge transfer items are structured tasks attached to an offboarding that track which documentation, credentials, and responsibilities have been handed off before the exit date. Each item has a title, description, assignee, and completion status - separate from the main checklist so they can be reviewed independently.
Still have questions?
Email us and we'll get back to you personally.
Access revocation, e-signatures, HRIS sync, knowledge transfer, exit interviews, self-service portals, workflow automations, advanced analytics with bottleneck detection, and a tamper-evident audit trail - all in one place.