BETAVotra is in public beta — every feature on this page is live, and your feedback shapes what we build next.

Compliance

Employee offboarding evidence your auditor can read

When an employee leaves, someone has to prove that what they owned was reassigned to the right person — and that the reassignment actually took effect. Votra turns offboarding into a controlled, approved, verifiable operation and produces signed evidence of every item it moved.

The uncomfortable truth about most offboarding is that the evidence lives in a spreadsheet, a ticket, or an inbox. Something changed, someone approved it, and six months later nobody can say which SharePoint library still belonged to an employee who left in March. That is a finding waiting to happen in any audit that samples access changes.

What auditors actually sample

Offboarding shows up in access reviews, joiner-mover-leaver controls, and most SOC 2 and ISO 27001 frameworks as evidence of a terminated user's access being removed and their data being dispositioned. The questions repeat:

  • Who initiated the change, and who approved it? Were they the same person?
  • What exactly changed — which files, libraries, sites and mailboxes?
  • How do you know the change took effect, rather than merely being requested?
  • What happened to the items that failed? Were they silently dropped?
  • Who owns these resources now, and is that recorded anywhere durable?

The four controls Votra implements

1. Separation of duties, enforced not assumed

Approval requires a distinct permission. The initiator of an operation cannot approve it, and there is no configuration in which that check is skipped. This is the single control that converts an admin action into a business process, and it is a property of the role model rather than a convention people are asked to follow.

2. An approval gate before anything changes

A policy can require approval for every operation. When it does, discovery runs and produces a reviewable plan — but nothing moves until a separate approver acts. The discovery-then-approve-then-execute sequence means the approver sees the actual inventory rather than a promise that it was handled.

3. Verification against the provider, not against the request

Provider APIs can return success for a change that did not fully land. After each transfer, Votra re-reads the resource from Microsoft 365 and records the observed state. Failed and skipped items are surfaced individually with retry available — a partial transfer is visible as a partial transfer, never rounded up to a completed one.

4. Signed evidence export

A completed operation produces a tamper-evident export covering what changed, when, who initiated it, who approved it, and the post-change provider state. This is the artefact you attach to a control testing workbook — it is designed to be read months later by someone who was not there.

Audit retention, enforced automatically

Retention is a plan property and a maintenance sweep, not a promise. History older than your window is deleted on a schedule, so the record you keep is bounded and known:

PlanAudit history
TrialTrial period
Starter3 months
Growth1 year
EnterpriseCustom window, agreed at contract

If your evidence must outlive the subscription, export the signed report before the window closes. Retention that is enforced is also retention you can actually evidence.

What Votra does not claim

Votra is not currently SOC 2 or ISO 27001 certified, and this page does not suggest otherwise. A vendor page that implies a certification an auditor will not find costs you more credibility than it wins. What exists today is the control set those frameworks examine, implemented in the product and open to your own reviewers — and if a completed report is a hard procurement requirement, tell us before you sign.

Why it matters beyond the audit

The same evidence answers an operational question far more often than a compliance one: when someone asks in eight months why a specific folder belongs to their team, there is a record. Offboarding that is only verified for the auditor's sample is still, in practice, mostly guesswork.

Frequently asked

Does Votra provide a SOC 2 report?
Not yet, and we would rather say so than imply otherwise. What exists today is the control set that a SOC 2 audit examines — enforced separation of duties, approval gating, least-privilege delegated permissions, immutable audit history and signed evidence exports — implemented in the product and available for your own reviewers to examine. Contact sales if a completed report is a procurement requirement for you.
How long does Votra keep audit records?
Retention is set by plan and enforced by an automated maintenance sweep rather than left to run indefinitely: 14 days on the trial, 90 days on Starter, 365 days on Growth, and a custom window on Enterprise. Audit history older than the window is deleted. If your evidence has to outlive the subscription, export the signed report before the window closes.
Can the person who runs an offboarding approve it?
No. Approval requires a distinct permission that the initiator does not hold, so an operation can never be initiated and self-approved. Where a policy requires approval, the operation cannot proceed to execution at all until a separate approver acts on it.
Does Votra store a copy of my employees' files?
No. Votra's architecture is metadata-only. It reads and writes ownership, permission and sharing metadata through Microsoft 365 APIs and never downloads, caches or analyses file contents, so offboarding evidence can be produced without creating a secondary copy of company data.
What if a transfer partially fails — is the record still accurate?
Yes, and this is the part that matters for an audit. Each item is transferred individually and re-checked against the provider afterwards, so a success response that did not actually change ownership is caught. Failed and skipped items are surfaced per item rather than rolled into a single green status, and the evidence export records the exception.

Run one real operation and read its evidence

The 7-day trial runs one complete, verified offboarding operation end to end — discovery, approval, transfer, provider re-read, signed export — before any payment. You will have seen the artefact your auditor would ask for. More detail on security and on the metadata-only architecture.