Use Case: Insider Threat
Departing employee risk
The resignation was submitted Monday. By Wednesday, the employee had accessed 3x their normal volume of IP documents and shared 4 folders externally. ManySignal had the evidence package ready for HR by Thursday.
The two weeks between notice and last day
The window between an employee submitting resignation and their final day is the highest-risk period for insider data exfiltration. The employee still has full system access, they have legitimate reasons to access any files related to work they're wrapping up, and they have a strong motivation — their new employer may benefit from what they know.
Traditional security controls have no special awareness of this window. ManySignal's HR integration changes that: the moment a departure is recorded, the behavioral monitoring baseline shifts to flag activity that would be normal for an average employee but is concerning for someone who is leaving in two weeks.
workflow: departing_employee_monitoring
trigger: hr_event.departure_date_set
actions:
immediate:
- elevate_insider_risk_score: departing_multiplier = 2.5x
- enable_enhanced_dlp: file_access_logging, email_monitoring
- alert_threshold_reduction: 50% lower for all DLP events
monitoring_period: departure_date_minus_30d to departure_date:
- file_access_volume: flag if > baseline_p75 (vs p95 for non-departing)
- external_sharing: any new share to non-company domain
- download_events: any bulk download > 100 files
- usb_events: any removable media connection
output: daily_summary to [insider_threat_team, legal_hold_if_triggered] MITRE ATT&CK mapping
Departing employee FAQ
When does ManySignal begin monitoring a departing employee?
At the moment an HR termination date is recorded in the connected HR system. ManySignal receives this via webhook and immediately elevates the employee's insider risk score, enabling enhanced monitoring of file access, email forwarding, external sharing, and USB activity for the remaining duration of their employment.
How does ManySignal balance monitoring with employee privacy?
Enhanced monitoring applies only to business systems — corporate devices, company-owned SaaS accounts, and corporate network activity. Personal device activity on personal networks is outside scope. Monitoring data is restricted to the insider threat investigation team and legal counsel, not visible to the employee's manager without separate authorization.
What's the typical behavioral pattern for malicious departing employees?
Research from CERT/CC and the Ponemon Institute identifies a consistent pattern: file access volume spikes in the 2-4 weeks before departure, with interest concentrated on IP, customer lists, and competitive intelligence. The access often occurs outside normal hours. External sharing or download events appear in the 1-2 weeks before the final day.
Does ManySignal help with non-malicious data hygiene at offboarding?
Yes. Many employees inadvertently copy work materials to personal storage without malicious intent — syncing their work folder to Google Drive for convenience, emailing documents to their personal address. ManySignal identifies these events for HR and legal review, distinguishing between inadvertent and deliberate data removal with behavioral analysis.
Protect your IP during the highest-risk offboarding window
HR-triggered behavioral monitoring with legal-hold integration — active from resignation to last day.