Skip to content

Offboarding & data requests

When someone leaves — an employee, a student, a customer contact, a member of a cohort — you off-board them from the directory. Lurno offers three outcomes behind one guided flow: block sign-in and keep everything, revoke access and anonymize, or queue a full erasure of their personal data. Two of those three are requests rather than instant actions: they wait for a second person’s approval before anything is destroyed.

There is one control, Off-board…, and it covers every departure. The wizard asks what’s happening, shows you what’s attached to the person before you commit, records a reason for the audit trail, and then either acts immediately or files a request.

Data export is a separate thing entirely, and it is self-service: people download their own data from their own account. There is no administrator screen that generates someone else’s data package.

  • Decide whether records must be retained — for transcripts, compliance, or auditing — before you choose anything permanent. The two permanent options cannot be undone once they execute.
  • Check whether the person leads a group or has invitations outstanding. The wizard tells you, but it’s easier to plan a handover before you start.
  • If the person is a guardian or has guardians linked to them, review Guardians first.
  • You cannot off-board your own account from here. Ask a colleague, or use the self-service route below.
  1. Open People and click the person’s row to open their record.
  2. Scroll to the Off-board this member section at the bottom and choose Off-board….
  3. Step 1 — What’s happening? Pick one of the three options described below.
  4. Step 2 — Review impact. Lurno shows live counts of the groups this person leads, their active role assignments, and any invitations they sent that are still pending, with sample names. Future scheduled sessions and taught cohorts are not yet included in this preview.
  5. Step 3 — Reason. Optional for the first two options, and recorded on the audit trail. Required for a full deletion.
  6. Step 4 — Confirm. Read the summary and choose Confirm off-boarding.

Tick people on the People list — or use Select all matching to take everyone behind your current filter — then open More actions on the selection bar and choose Off-board…. The wizard is the same; the impact preview and the confirmation are aggregated across everyone selected.

Option What happens When it happens
Temporary leave Sign-in is blocked. Nothing is deleted, nothing is anonymized, and they can be brought back with everything intact. Immediately
Permanent All access is revoked and the person’s identifying details are scrubbed in place. Historical records and enrollment lineage survive. Filed as a request
Permanent + delete personal data The erasure route for a GDPR Article 17 request. The sign-in identity is removed entirely and a one-way hash is kept so a later directory sync can’t quietly recreate the person. Filed as a request

The two permanent options do not take effect when you click confirm. They create a deletion request carrying your reason, and a second person has to approve it — the requester can never approve their own request. Once approved, a scheduled pass executes it. If the organization has only one person who could approve, the request approves itself automatically after 48 hours and then executes.

The wizard’s confirmation screen mentions a 30-day cooling-off window. That window belongs to the self-service deletion described further down, not to a request an administrator raises here — so treat Confirm off-boarding as the point of no return and cancel straight away if it was a mistake. Cancelling an administrator-raised request is done from the operator queue; see Privacy & incident queues.

Bringing someone back after Temporary leave is not a button on this screen today. Ask Lurno support to reactivate the account; the reactivation is written to your audit log either way.

Every person exports their own data, from their own account.

  1. Open Account from the avatar menu and choose the Privacy card.
  2. Under Your data rights, choose Download next to Export your data.
  3. A JSON file containing the personal data Lurno holds about them downloads immediately.

The same download is available from My access, which also lists every role they hold and where.

If someone asks you for their data, point them at that button rather than trying to assemble it yourself. If they can’t sign in because they no longer belong to any organization, they land on a stripped-back page that offers the same download, plus a request to be reinstated.

The Export button on the People screen is a different thing: it downloads your directory as a CSV for your own operational use. It is not a subject-access package.

The Privacy card also carries Start deletion, a three-step flow ending in a typed confirmation. It is deliberately narrow: it only completes for someone who no longer belongs to any organization. Anyone still a member is told to leave first. In practice that means an administrator off-boards the person, and the person then finishes the erasure themselves — or the administrator’s own request covers it.

A self-started deletion carries a genuine 30-day cooling-off window, and while it’s pending a banner sits at the top of the person’s screens with a control to cancel it. That cancel only works on a request someone started for themselves.

Action Sign-in Enrollments Assessment records Personal details
Temporary leave Blocked Kept Kept Kept
Permanent Removed Kept as history Kept Scrubbed
Permanent + delete personal data Removed entirely Kept as anonymized history Kept as anonymized history Removed

Certificates that were already issued are verified through a public page keyed on the credential’s own code, not on a Lurno account, so an issued credential stays checkable after the holder leaves. See Certificates.

Term What it means
Off-board The single wizard covering every departure.
Temporary leave Suspension. Immediate, reversible, keeps everything.
Permanent Anonymization. Filed as a request.
Permanent + delete personal data Erasure. Filed as a request.
Reason Free text on the request. Optional for the first two options, required for erasure.
Impact preview Groups led, active role assignments, and pending invitations sent, shown before you commit.
Deletion request The queued item a second person approves and a scheduled pass then executes.

Confirming was refused. You can open a person’s record and start the wizard without holding the permission for the outcome you picked — the refusal comes at the end. Temporary leave, anonymization, and erasure are granted separately; see Roles & permissions.

I tried to off-board myself and it was refused. That’s deliberate. Someone else has to do it.

I confirmed a permanent off-board but nothing changed. That’s expected. Permanent options file a request; the person keeps their record until it is approved and the scheduled pass runs.

I need to cancel a deletion I requested. Requests are cancellable until they execute, but the cancel control lives in the operator queue. Contact Lurno support with the person’s email and the reason you recorded — and do it promptly, because approval can land at any time.

The person still appears in reports. Temporary leave removes them from active counts; historical reports keep past activity by design. Only an erasure removes the underlying personal data.

A learner’s guardian link is affected. Off-boarding a learner leaves any guardian links pointing at a record that is going away. Review them on the learner’s record before you start — see Guardians.

Someone wants a copy of their data and can’t sign in. They can’t be helped from the directory. Raise it with Lurno support; an account with no remaining membership gets a self-service download page of its own.