Barakat helps employers identify every active account, centralise identity control, revoke access cleanly when staff leave, and maintain ongoing oversight in a way that supports Section 55 of Sierra Leone's Cyber Security and Crime Act, 2021 and reduces the wider management and corporate exposure addressed in Section 56.
For many organisations, access sprawl does not look dramatic until an ex-employee still has a login, a contractor account never expired, or a privileged mailbox remains active without review. This engagement turns account ownership, offboarding, and oversight into a clearer control system instead of a last-minute scramble between HR and IT.
Section 55 of Sierra Leone's Cyber Security and Crime Act, 2021 requires an employee, upon disengagement from employment, to relinquish or surrender all codes and access rights to the employer within a reasonable time. That makes offboarding more than an internal HR checklist. It is a direct control obligation touching accounts, passwords, tokens, VPN access, devices, Wi-Fi credentials, and any other access path still tied to the person who has left.
Section 56 extends the issue beyond the departing employee. It provides for liability where a person exercising management or supervisory authority fails to exercise reasonable and proper control, and it also exposes the legal person where an offence occurs because of lack of supervision or control. In practice, access governance, leaver controls, and account oversight are part of how management shows that reasonable control exists.
Best suited to employers that rely on multiple systems, shared services, remote access, or fast staff turnover and want stronger control over who still has access to what, when, and why.
Most access-control failures start with incomplete visibility. If no one can confidently list every active account, privileged identity, remote-access path, or shared credential, offboarding will always be inconsistent. We begin by making the identity landscape visible and cross-checking it against the current staff reality.
Once the account map is clear, the next step is tightening how access is granted and revoked. We help organisations move away from fragmented administration by using a stronger identity source, documenting lifecycle rules, and enforcing extra protection where compromise would matter most.
The riskiest offboarding failures are often simple ones: a mailbox still active, a VPN token still usable, a Wi-Fi password unchanged, or a finance system account that no one remembered. We design a practical offboarding workflow so revocation is immediate, documented, and repeatable under real operational pressure.
An access project loses value quickly if it ends with a one-time cleanup. We help organisations maintain a recurring view of who still has access, how long they have had it, what privilege they hold, and which anomalies need review before they become the next control failure.
Deliverables: Access management policy, offboarding checklist, monthly access audit reports, and an access register showing who has access to what.
Urgency: If an ex-employee, expired contractor, or forgotten admin account could still sign in today, the organisation is carrying a live control failure that should be closed before it turns into a breach, dispute, or management problem.
Book Access Control Review