Post-Termination Activity Detection (UAR)
A clean, fast win for IT controls testing: feed in the HR termination log, get back every case of system activity that happened after someone left — with time zone differences handled correctly from the start.
- Plugin
- audit-fieldwork-toolkit
- Version
- v1.0.8
- Impact
- High
- Complexity
- Low
How it works
- Input
- The HR termination log (employee ID, name, last working day) and the system activity logs (logins, journal entry postings, approvals) for the same period
- What it does
- Converts every timestamp to one common time zone before comparing anything → matches each terminated employee to their system activity → flags anything that happened after their last working day
- What has to hold true
- No dates are compared until they've been converted to the same time zone — this step can't be skipped. Every flagged item shows both the original and the converted timestamp, so it can be double-checked independently.
- Output
- A list of exceptions: employee, termination date, the activity flagged, both timestamps, and which system it came from
The part that makes it reproducible
Building blocks it runs on
Shared, independently tested components. They ship bundled inside this skill — there is nothing extra to install.
What you'll need to change for your firm
This runs as published, but every audit function documents things its own way. These are the places it assumes a house format:
- Your HR export format — which columns carry employee ID, name, and last working day
- Which systems are in scope, and the shape of each activity log
- The organization time zone of record
- What counts as activity worth flagging versus routine automated events
Built for Claude
Install it into Claude Cowork and point it at your files.
- 1Download the skill bundle — everything it needs, including the shared building blocks, is inside.
- 2Add it to Claude Cowork as a plugin (audit-fieldwork-toolkit).
- 3Point it at your own files and run it against one period you already know the answer to.
Free. We'll send the bundle and the setup notes.
Running on ChatGPT Enterprise or Copilot? We port these into your environment.
Want Post-Termination Activity Detection (UAR) fitted to your methodology?
We adapt it to your control matrix, your workpaper template, and your thresholds — then hand it over so your team can run it themselves.