Insights

The Departing Employee and the Pattern Before They Leave

May 10, 2026 Hilt 6 min

Your most valuable data leaves on access you granted on purpose. A departing employee exfiltrates on access they still legitimately hold, so each move passes. How runtime governance surfaces the pattern before the notice period ends.

The Departing Employee and the Pattern Before They Leave cover image

A researcher gives two weeks notice on a Monday. Her badge still opens the lab. Her VPN credential still resolves. Her read access to the model weights is the access you granted her on purpose, for the work she did on Friday. Over the next eleven days she copies the model out in pieces, off-hours, through a transfer path she has used a hundred times for legitimate work. Every move is allowed. On day twelve she is gone, and so is the model.

Nothing about her permissions changed. Her intent did. Intent does not show up in an access log.

That is what makes this case hard. The data leaves on access that is still legitimately held, so the move that matters passes the same check as the move that does not.

What the obvious controls catch, and where they stop

You revoke access on the last day. You run DLP rules that flag a customer database mailed to a personal Gmail, or a bulk export from the CRM the afternoon before someone walks. Those controls are real. They catch the careless cases. Screenshot a dashboard, forward it to a personal address, get caught. Zip the shared drive in one motion, trip a threshold.

Two problems. Revocation happens at the end, and the deliberate theft happens before it. The window that matters is the notice period, and often the weeks before notice, while the person is still inside and still moving data through channels they are supposed to use.

The deliberate version also does not look like the careless version. The researcher who wants the model does not bulk-download it on her last afternoon. She takes it in small pieces, over two weeks, off-hours, through an approved path. The salesperson who wants the pipeline does not export the whole CRM. He pulls the accounts he owns, one region at a time, into a sync he already had permission to run. Each action is permitted. Each one looks like a Tuesday. No policy breaks. No alert fires. The stack is expensive, and nothing triggered.

Every move is permitted. The pattern is the breach.

The danger is not in any single move. It is in the pattern across moves: this identity, reading these high-value paths, at this hour, into this destination, at a volume and cadence that does not fit how this person normally works.

A permission check cannot see that. It answers one question, was this move allowed, and the answer is yes every time, because you allowed it on purpose. The question that decides the case is a different one: does this pattern of movement fit what this identity normally does?

There is one place to answer it. At runtime, while the data moves. Not before, where predictive tools guess who might be a flight risk and bury the team in false positives. Not after, where forensics reconstructs what left once the person and the data are already gone. While it forms.

What runtime governance sees during the notice period

Hilt watches data movement at the kernel, metadata only by default, off the path. It does not sit between the data and where it is going, and it does not read your data to do its job. Each move resolves to a probabilistic, source-dependent identity: which user, which job, which destination, and whether this fits what that identity normally does.

When the departing researcher starts copying the model in pieces, the deviation shows up across layers at once. The job is unusual for her identity. The access pattern is a repeated read of high-value paths in a window she rarely touches. The destination volume drifts up week over week through a channel that is approved but historically light. Take any one of those signals alone and it is noise. Score them together against months of how her data has actually moved, and they form a pattern. A pattern is a case, not an alert.

The case is the payoff. Instead of a queue of permitted actions that each look fine, the team gets one written narrative: this identity, this class of move, this deviation from her own baseline, here is why it is unusual. A human can act on that during the notice period, while there is still time to have the conversation, freeze the channel, or isolate the host.

The response stays off the path too. When a pattern crosses the line, Hilt responds with host-level network isolation, quarantine, from the control plane. It does not sit inline, and it does not block, drop, or alter traffic to do this. The collector observes the move; the control plane acts on the host. The dangerous session gets cut without rewriting a firewall rule and without breaking the legitimate work of everyone around her.

Where this fits with what you already run

This does not replace offboarding or DLP. Offboarding still revokes access on the last day. DLP still catches the careless forward to a personal account. Hilt can stand in for your endpoint sensor, and many teams retire their EDR once it is in place; keep an EDR alongside only if you want the malware and intrusion layer too. Keep what serves you.

None of them was built to evaluate the pattern of movement across permitted actions by a legitimate, still-employed person. That is the blind spot, and it is exactly where a departing insider lives: full access, real intent, every move clean. Runtime data movement governance adds that layer.

The performance objection that usually kills a new agent does not apply. The collector runs on the order of 0.1% of one core and 4 to 8 MB of memory per host, single-tenant inside your own cloud, with events that never leave your account. There is no inline penalty because nothing sits inline.

The window you actually have

The window is the notice period, sometimes two weeks. Often it opens earlier, in the weeks before anyone gives notice, when the decision to leave is made but not announced. The person is trusted, permitted, inside. The only way to know that their data movement has changed is to watch the movement itself, resolved to the identity behind it, scored against how that identity normally works.

Ask your current stack one question: what did this person's data actually do, resolved to the job behind it and scored against her own history, in the three weeks before she gave notice? If it cannot answer, the deliberate departing-employee case is the one you read about after, in the disclosure letter, instead of catching while it formed.

If you want to see how the pattern surfaces, the fastest path is a 30-minute technical call, engineer to engineer, where we walk through exactly what the collector sees on a host and how a case gets written.