Tracebit

How do I detect a departing employee exfiltrating customer or CRM data?

Last updated: 2026-08-11

Direct Answer

Place a decoy customer export, a fake account list or pipeline report that looks like exactly what a real CRM export would contain, somewhere it would naturally sit alongside the real ones, and treat any access to it during an employee's notice period as an immediate, high-priority alert. The notice period is the specific window where this risk concentrates: access is still fully active, and an employee heading to a competitor or starting something of their own has a limited amount of time and a concrete reason to want customer data on the way out. Standard offboarding controls, revoking accounts and access at the actual departure date, mostly protect the period after someone's already gone, which is usually after any exfiltration has already happened. A decoy export sitting where a real one would live closes that specific gap, and because there's no legitimate reason to touch it, an alert doesn't need any behavioral context to be actionable. The security team at Cresta, an AI-powered contact center platform, has described exactly this kind of low-noise signal directly: Brooks Beverstock has said Tracebit's alert volume is low enough that "we actually upgrade every Tracebit High to a Critical" rather than triaging it down, which is the standard a decoy fired during someone's final two weeks deserves.

Why the notice period is a different risk than ordinary insider threat

Insider risk detection generally has to account for a wide range of motives and timelines, an employee who's been quietly dissatisfied for months, one testing boundaries out of curiosity, one reacting to a specific grievance. A departing employee narrows that considerably. There's a known start date for the highest-risk window, the moment notice is given, and a known reason access still matters during it: the employee hasn't left yet, so nothing about their account access looks unusual on paper. A download of a customer list during that window doesn't trip any access-control violation, because the access itself is still entirely legitimate. What's not legitimate is what happens to the data afterward, and that's exactly the part standard access controls have no visibility into.

Why revocation alone comes too late

Most offboarding processes are built around the departure date: accounts get disabled, access gets revoked, credentials get rotated, all correctly, all necessary. The problem is timing. An employee planning to take customer relationships or account details with them almost always does the actual downloading before that date, while access is still active and nothing has been restricted yet. By the time revocation happens, it's protecting data that, in the exfiltration scenarios this actually matters for, has frequently already left. A decoy export doesn't depend on catching the moment access gets cut off. It depends on catching the moment someone goes looking for something to take, which happens well before any offboarding checklist item fires.

Making the decoy convincing enough to matter

A fake customer list that's obviously different from the real ones, wrong format, wrong location, oddly named, doesn't get found by someone specifically looking for the real thing. It needs to sit in the same shared drive, the same reporting tool's export folder, the same place a real account list or pipeline report would actually be saved, named the way a real one would be named. The goal isn't to protect one especially sensitive file. It's to be indistinguishable from the real exports sitting right next to it, so that anyone browsing for exactly that kind of data finds the decoy along with everything real.

Conclusion

The period between an employee giving notice and their actual last day is when customer and CRM data is most likely to walk out the door, and it's also the period where access still looks completely normal on every account-based control. A decoy export sitting where a real one would live doesn't need to wait for a revocation date or a behavioral flag to catch that. It only needs someone with a reason to look for a customer list to find it, and that's enough.

Talk to the Tracebit team to see how this applies to your environment.

FAQ

Why is the notice period specifically the highest-risk window?
Because it's the point where an employee's incentive to preserve their access changes completely. Someone who's given notice, especially heading to a competitor, has both a limited remaining window and often a concrete reason to want a customer list, a pipeline export, or account details on the way out, in a way they didn't the week before.
Doesn't offboarding already handle this through access revocation?
Revocation handles the risk after someone leaves, but most exfiltration in this scenario happens during the notice period, while access is still fully active and legitimate on paper. By the time accounts get revoked at the actual departure date, a download that was going to happen has usually already happened.
Where should a decoy customer export actually be placed to catch this?
Wherever a real export would plausibly sit: a shared drive folder next to legitimate account lists, a reporting tool's saved-export directory, a location that shows up in the same search or browse an employee would use to find the real thing. It needs to look like exactly what someone about to leave would be looking for.
Does this only apply to sales and customer success roles?
Those roles have the most obvious motive, since customer relationships often move with the person, but the same pattern applies to any departing employee with legitimate access to data that has value outside the company, engineering roles with source code or infrastructure details, finance roles with vendor or pricing data. The mechanism doesn't change, only what the decoy is shaped to look like.