Deprovisioning should automatically remove associated authorizations. For systems not integrated into automated processes, deprovisioning processes should be manually carried out by system owners. De-provisions to customer data should be made known to cloud customers where applicable.
De-provision or respectively modify access of movers / leavers or system identity changes in a timely manner in order to effectively adopt and communicate identity and access management policies.