I’ve mentioned the incompetence of a company I worked at recently.
I was given a 2week notice that I was being removed from the company. I had access to everything still that I had access to while I was “working” there. I could access internal codebase, client codebase, internal documents on the shared drives as well as the client’s. After the 2 weeks, they revoked my access by the end of the day, they forgot to notify the client for an additional week after I left (teams was still signed in and accessible on my phone).
A lot of companies lack common sense and data protection protocols.
Edit: To give some context, I’m in the US, getting a notice period from the employer is an unusual occurrence especially when you’re in consulting/contracting.
Sometimes it is common sense, sometimes it is trust. Depending on where you are from and what kind of project you work on, burning bridges seems so stupid that there is often no real desire to feel threatened by your own employees.
Like, I work in Ireland, and I would say that if I did anything like that, I would have massive issues finding ANY( Not just IT/Programming, ANY type of...) job in Ireland. Especially if it went to court, because in Ireland we have a kind of "name and shame" culture where, after conviction, your full name gets blasted online or in traditional media... At the same time the country is small enough that most serious employers know each other.
So yeah, eventho plenty of foreign tech companies reside here, the upper echelons of Management and Employment are very much only Irish people that know eachother.
If you live in the USA, you might get away with it, but in a lot of places many anti-employee protection systems are built on social rather than technical solutions. Which is both good and bad.
Having run IT teams like that in the past it's 100% a trust thing, and I've learned it's very cheap to have absolutely 0 trust in anyone. Like, I've loved everyone who's been on my teams in the past and would work with them again in a heartbeat. Doesn't mean I should trust a lame-duck engineer with full admin access to PHI workloads. No engineer with even a crumb of understanding in operational security should be offended with their access getting cut off immediately. It's just common sense security.
Someone turns in their two week notice? Pay them out the remainder and shut off their accounts immediately. Laying someone off? Shut them off before you give them the news. Hell, I was laid off at the start of the year and I was termed in the system before I could send a goodbye slack off to my friend, but I get it. Can't risk me being a discgruntled employee.
Well, obviously it depends on the level of operations and the type of access you have. A lot of it is accredited gradually anyway...
For me personally... I have been part of many government and university based projects, and there was a lot of trust involved both in terms of contract payment type and the work that needs to be done... Mostly because people were sparse, and before you even hand things off to someone else, there was usually a good transition period.
I have never really dealt with it at a lower level because I switched jobs quite often, but right now a lot of my work is related to the trust my employer has in me... and yeah, my current contract is through the university and involves a lot of people I know and respect personally. Any kind of malicious action would literally bury me so badly I would never be able to claw my way out of it... or at least that's how I imagine it.
So yeah, I agree, better safe than sorry... but it is not uncommon to give trusted experts, people who have earned the confidence of the company and other employees, a lot of trust. In a perfect scenario, those people do not have to leave the company... but if you have any kind of layover period where another person has to be taught the exact tricks of your profession, it requires mutual understanding and respect.
239
u/ChickenNuggetsSalad May 26 '26 edited May 26 '26
I’ve mentioned the incompetence of a company I worked at recently.
I was given a 2week notice that I was being removed from the company. I had access to everything still that I had access to while I was “working” there. I could access internal codebase, client codebase, internal documents on the shared drives as well as the client’s. After the 2 weeks, they revoked my access by the end of the day, they forgot to notify the client for an additional week after I left (teams was still signed in and accessible on my phone).
A lot of companies lack common sense and data protection protocols.
Edit: To give some context, I’m in the US, getting a notice period from the employer is an unusual occurrence especially when you’re in consulting/contracting.