602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Threat Assessment for Terminated Employees: A Guide

Abstract illustration of an empty office chair and closed door symbolizing the risk period surrounding employee termination

Terminating an employee is one of the highest-risk moments in the employment lifecycle, and the risk does not end when the meeting does. A structured behavioral threat assessment before, during, and after a termination identifies warning signs early, allows security and HR to plan the separation itself to minimize confrontation, and puts a monitoring plan in place for the weeks that follow, when most workplace-violence incidents tied to job loss actually occur.

Most employers treat termination as an HR and legal event: paperwork, final pay, COBRA notices, a signature on a separation agreement. Few treat it as a security event, even though separations, layoffs, and disciplinary actions are consistently identified as precipitating stressors in workplace violence cases. The gap between how organizations plan a termination and how much risk that termination actually carries is where Honeybadger’s threat assessment work sits: a structured, evidence-based process that treats every high-risk separation as a security-planning exercise, not just a personnel one.

Understanding the Risk Window Around Termination

Behavioral threat researchers describe an “injustice collector” pattern in a subset of workplace violence cases: an individual who fixates on a perceived wrong, ruminates on it, and eventually acts. Job loss is one of the most common triggering injustices, particularly when the individual perceives the termination as unfair, retaliatory, or humiliating. The risk window is not limited to the moment of termination itself. It typically spans three phases:

  • Pre-termination: the period during which performance issues, disciplinary actions, or interpersonal conflicts are escalating and the employee may sense that separation is coming.
  • The termination event: the meeting itself, where emotions are acute and the individual’s reaction is least predictable.
  • Post-termination: days to months afterward, during which grievance can calcify into a fixed, targeted grievance against specific individuals or the organization as a whole.

Each phase calls for a different set of controls. Pre-termination calls for documentation and behavioral observation. The termination event calls for logistical and physical security planning. Post-termination calls for monitoring, access revocation discipline, and a defined re-engagement protocol if the individual attempts to return or make contact.

Behavioral Warning Signs Before and After Separation

No single behavior predicts violence with certainty, and threat assessment professionals are careful to avoid profiling based on demographics, diagnosis, or personality alone. What the field relies on instead is a pattern-based approach: looking at trajectory, context, and specificity rather than any one red flag in isolation. Behaviors that warrant closer attention and documentation include:

  • Explicit or veiled threats toward supervisors, coworkers, or the organization, whether spoken, written, or posted on social media.
  • A marked increase in grievance-focused talk, a sense of persecution, or statements that the person has “nothing left to lose.”
  • Fascination with or references to prior workplace violence incidents or attackers.
  • Sudden acquisition of weapons, or references to weapons access, by someone who previously showed no interest.
  • Stalking, surveillance, or excessive interest in a supervisor’s or coworker’s schedule, home address, or family.
  • A pattern of escalating disciplinary incidents coupled with externalizing blame rather than accepting responsibility.
  • Withdrawal combined with leakage — telling a third party, including on social media, about intent to harm.

The FBI’s behavioral analysis of active-shooter cases has repeatedly found that attackers display multiple observable concerning behaviors before an attack, often to more than one person, and that those behaviors are rarely reported through a formal channel. That finding is the single strongest argument for a formal, known, and trusted reporting mechanism rather than relying on informal hallway conversations to surface risk.

The Behavioral Threat Assessment Framework

Structured professional judgment is the standard in modern workplace threat assessment: assessors use a validated framework of risk and stabilizing factors rather than gut instinct or a rigid checklist, and they weigh those factors against context, trajectory, and access to means. Applied to a termination, the process generally works through four stages:

  1. Identification. A concern is reported — by a supervisor, HR, a coworker, or observed directly — and routed to a designated threat assessment team rather than left to an individual manager’s judgment.
  2. Inquiry. The team gathers facts: documented behavior, disciplinary history, statements made, access to weapons, personal stressors, and any history of violence. This is investigative and fact-based, not speculative.
  3. Assessment. The team evaluates the level of concern using a structured framework, considering escalation trajectory, specificity of any threat, access to the target and to weapons, and stabilizing factors such as support systems or lack of prior violence.
  4. Management. The team designs a case management plan — which may range from routine HR handling to a fully security-planned termination with law enforcement liaison, protective coverage, and post-separation monitoring.

This framework is consistent with the American National Standard developed jointly by ASIS International and the Society for Human Resource Management (SHRM) for Workplace Violence Prevention and Intervention (WVPI), which calls for a standing threat assessment team, defined escalation pathways, and documented case management — not an ad hoc response improvised after a red flag appears.

Structuring a High-Risk Termination

When a threat assessment flags a termination as elevated risk, the logistics of the meeting itself become a security plan, not just an HR checklist. Elements a professionally structured high-risk termination typically addresses:

  • Timing: scheduling to minimize the audience, avoid Friday-afternoon isolation dynamics, and allow for immediate departure support.
  • Location: a room with two exits where possible, away from high-value targets (executives, sensitive systems, firearms-adjacent areas), with security positioned discreetly nearby rather than inside the room unless risk warrants direct presence.
  • Attendee control: a defined, minimal set of participants — typically HR and one manager — with security staged nearby rather than confronting the individual directly unless behavior escalates.
  • Access revocation sequencing: IT access, badge credentials, and building access disabled to take effect at the moment of notification, not hours later, to prevent a return to systems or the premises.
  • Property and belongings: a plan for personal item retrieval that does not require the individual to re-enter the building unescorted after the meeting.
  • Communication plan: a scripted, unified message to remaining staff that avoids speculation and directs any safety concerns to a single point of contact.
  • Departure logistics: arrangements for transportation off-site if the individual’s emotional state or documented risk warrants it.

None of this requires treating every termination as a security event — the overwhelming majority of separations are routine. The point of a threat assessment process is precisely to identify, in advance, which small subset of terminations warrants this level of planning, so that resources go where the actual risk is rather than being applied uniformly or ignored entirely.

Coordinating HR, Legal, and Security

High-risk terminations fail most often at the seams between departments: HR moves on its own timeline, legal is focused on documentation and litigation exposure, and security is looped in late or not at all. A functioning threat assessment team closes that gap by bringing HR, legal, and security to the same table before the separation happens, with clearly assigned roles:

  • HR owns the personnel history, documentation trail, and the termination conversation itself.
  • Legal reviews the separation for compliance and litigation risk, and advises on what can and cannot be said or restricted (including any non-disparagement or return-of-property terms).
  • Security owns the physical and behavioral risk assessment, the logistics of the meeting, and the post-termination monitoring plan.

This is also where an outside, licensed investigative and security partner earns its keep: an internal HR team rarely has the training to run a structured behavioral risk interview, and an internal security guard function rarely has the investigative capability to verify a threat, check for a protective-order history, or corroborate a report. Coordinating those functions under one engagement — rather than three disconnected vendors — is what keeps the plan from falling apart under time pressure.

Protective Coverage During and Immediately After Separation

For terminations assessed as elevated or high risk, temporary protective coverage is a proportionate control, not an overreaction. This can include a uniformed or plainclothes security presence at the facility on the day of termination and for a defined period afterward, protective coverage for a specifically named supervisor or executive if the threat assessment identifies them as a targeted individual, and coordination with local law enforcement so responding officers already have context if a call comes in. Honeybadger’s investigative and executive protection teams work in-house and are dispatched nationwide for exactly this kind of engagement — the assessment, the protective coverage, and the follow-up investigation are handled by the same organization rather than handed off between vendors at the moment risk is highest.

Post-Termination Monitoring and Case Management

Case management does not end when the individual leaves the building. A defined post-termination period — commonly 30 to 90 days depending on the risk level — should include a plan for what happens if the individual attempts to contact former coworkers, shows up at the facility, or makes statements online that escalate the original concern. This is where a threat assessment case stays open rather than closed: the team designates a point of contact for any further reports, documents any contact attempts, and re-assesses risk if new information surfaces. Where warranted, this includes a licensed investigative review of public social media activity, corroboration of any reported contact, and coordination with law enforcement if the individual’s conduct crosses into criminal territory such as stalking, harassment, or a direct threat.

Building a Standing Threat Assessment Team

Organizations that handle high-risk terminations well are rarely improvising for the first time. They have a standing, cross-functional threat assessment team — HR, legal, security, and often an outside behavioral threat consultant — with a defined intake process, a documented case management protocol, and a relationship with local law enforcement established before a crisis, not during one. Building that capability, and rehearsing it through tabletop exercises before it is needed for real, is itself a core part of a mature workplace violence prevention program.

Documentation and Legal Considerations

Every stage of a threat assessment should generate a written record: the initial report, the facts gathered during inquiry, the risk factors weighed during assessment, and the decisions made during case management. This documentation serves two distinct purposes. First, it creates continuity — if a case reopens weeks or months later, the team is not starting from memory. Second, it establishes that the organization acted reasonably and consistently, which matters if a termination is later challenged, whether through a wrongful-termination claim, a workers’ compensation dispute, or litigation following an incident the organization is accused of failing to foresee. Counsel should review the documentation practice itself, not just individual case files, to confirm it does not inadvertently create discoverable material that undermines the organization’s position, and to confirm that any restrictions placed on a departing employee — non-disparagement language, return-of-property terms, or no-contact provisions — are enforceable in the relevant jurisdiction. Documentation should describe observed behavior and stated facts, not diagnostic labels or speculation about mental health, which are both legally risky and clinically inappropriate for non-clinicians to render.

Common Mistakes That Undermine a Termination Security Plan

In practice, most failures in high-risk termination planning trace back to a handful of recurring mistakes rather than an unforeseeable event:

  • Waiting for a single dramatic red flag. Most cases that end badly showed a pattern of smaller concerning behaviors that were individually dismissed rather than aggregated and assessed together.
  • Treating the threat assessment team as a one-time committee. Teams that only convene after an incident lack the practiced coordination to act quickly when a real case appears; the standard is a standing team with a defined intake process.
  • Delaying access revocation. IT and badge access disabled hours after notification, rather than at the moment of notification, gives a motivated individual a practical window to act on impulse.
  • Excluding security from the planning conversation until the day of termination. Security brought in the morning of a termination cannot meaningfully assess risk, coordinate with law enforcement, or plan facility logistics; that input needs to happen during the inquiry and assessment stages, not after the decision is finalized.
  • Assuming risk ends at the exit door. Organizations that stand down all monitoring the moment an employee leaves the building miss the post-termination window where grievance most often escalates.
  • No documented escalation path for informal reports. When coworkers do not know who to tell or believe nothing will happen if they do, the behaviors the FBI’s research identifies as commonly observable before an attack go unreported.

Testing the Plan Before It Is Needed

A threat assessment protocol that has never been exercised is a document, not a capability. Tabletop exercises — structured walk-throughs of a hypothetical high-risk termination scenario with HR, legal, security, and facility leadership in the room — surface gaps that are invisible on paper: who actually has the authority to disable badge access on short notice, whether the designated meeting room really has a second exit, whether the security vendor’s response time matches what the plan assumes, and whether frontline supervisors know who to call the moment they see a concerning behavior. Running this exercise annually, and after any significant change in facility layout, staffing, or a real case that tested the process, keeps the plan current rather than theoretical. Honeybadger’s threat assessment and security consulting teams build and facilitate these exercises as part of a broader workplace violence prevention program, so that the first time a high-risk termination plan is executed for real is not also the first time it has ever been run.

About Honeybadger Solutions LLC

Honeybadger Solutions LLC is a licensed, bonded, and insured Arizona security and investigations firm founded and led by veterans and former law enforcement professionals. Our in-house threat assessment, investigative, and executive protection teams are deployed nationwide for high-risk terminations, workplace violence prevention program development, and post-incident investigations, while our armed guard services operate from our Casa Grande headquarters and offices in Phoenix and Oro Valley, Arizona. Every engagement is handled by trained, credentialed professionals — never subcontracted to an unvetted third party. To discuss a high-risk termination, an active threat concern, or building a standing threat assessment capability for your organization, call us directly at 602-725-2818.

Sources and further reading

Honeybadger Solutions delivers Blockchain Forensics, Blockchain Consulting and Cyber Investigations from its Arizona office for clients across the United States and internationally. This casework is performed remotely under Arizona licensure, so there is no geographic limit on where a client can be based.