The short answer
When an employee leaves, their internal access should end and their outward-facing professional identity should stop appearing as currently company-authorized. The organization can deactivate records it controls, but it cannot reliably delete every business card, QR image, saved contact, signature, background or profile reference already copied elsewhere.
The practical objective is therefore revocation of company authorization, not a promise of universal deletion. A recipient following an old verification link should be able to discover that the live identity is no longer active.
Why external identity persists
Professional identity spreads beyond systems the employer administers. Customers save contact files. Colleagues forward signature blocks. QR codes appear in presentations or print. Branded meeting backgrounds remain on personal devices. Search results and third-party directories may repeat a former job title.
Deleting the employee row from one application does not retract those artifacts. Worse, deletion may remove the organization’s ability to show a clear inactive status. Retaining a minimal governed status record can provide a safer answer without continuing to expose unnecessary personal data.
A complete offboarding control
Assign an owner and effective time for deactivation. Remove internal access through IAM, revoke externally published authorization, replace or disable controlled public destinations, recover physical brand materials where feasible, and notify teams that maintain directories or shared collateral. Preserve only the records required by policy and law.
Also define exceptions. A contractor’s end date, an employee on leave and a person changing subsidiaries may need different states. The public result should be accurate and restrained: it should communicate authorization status, not disclose confidential HR reasons.
What CardIQ deactivation means
CardIQ allows company administrators to manage and deactivate the professional identity destination under their control. This changes the current authorization signal at that destination. It does not remove a former employee’s copies from third-party systems, prevent every possible brand misuse or erase the history of earlier contact sharing.
That boundary is precisely why verification should use a live company-controlled status instead of treating an old static asset as permanent proof.