our company has a security and IAM hygiene practice to not only deactivate, but also delete identities from applications if users are not working at the company anymore. We also need to do this from a control and compliance perspective.
We are going to automate to delete deactivated users 30 days after they have offboarded from the company.
Questions:
- is there any negative impact in removing users from a Jira or Confluence aspect, for example even when this deactivated users has a task assigned. ?
- are the audit logs preserved related with actions which this user in the past did ?
- what is the recommended security best practice in Atlassian cloud if the users are have offboarded from the company ?