What Your Business Actually Needs to Do When an Employee Leaves (The IT Offboarding Checklist)

When someone hands in their notice, there’s a fairly well-worn routine most businesses fall into. HR sorts the paperwork. There’s a leaving card going round the office. Someone books the pub for Friday. The laptop gets handed back, and everyone moves on.

But somewhere in all that, one job often gets rushed, half-done, or forgotten entirely – properly closing off that person’s access to your systems. And it’s a job that matters far more than most people realise.

Because the day someone walks out of your door, they can still have a surprising amount of access to your business. Emails. Shared drives. Cloud apps. That accounts system they logged into from their home laptop. If nobody deals with it, that access just sits there – open, unwatched, and waiting to cause a problem.

Why leftover access is such a risk

Most of the time, people leave on good terms. They’re off to a new job, they wish you well, and they’ve no interest in causing trouble. So why does it matter?

It matters because access that nobody’s watching is access that nobody’s protecting. An old account belonging to a former employee is a gift to an attacker. Nobody’s logging into it day to day, so nobody notices when someone else does. The password might get reused on some other website that later gets breached. And because it’s a “real” account with real permissions, it can be a quiet way into your business that sails straight past your other defences.

Then there’s the smaller number of cases where someone doesn’t leave happily. A disgruntled ex-employee who still has access to your customer list, your files or your email is a genuine problem – and one that’s entirely avoidable with a bit of process.

Either way, the risk isn’t really about trusting the person. It’s about the fact that an open door is an open door, regardless of who left it that way.

The bit everyone forgets: it’s not just email

When people think about cutting off access, they usually think of the obvious things – the work email account, the login to the main computer. Those matter, of course. But modern businesses run on a sprawling web of accounts, and it’s the forgotten ones that catch you out.

Think about everything a typical member of staff touches. Their Microsoft 365 account. Shared folders and cloud storage. The accounting software. The CRM. Social media logins. Any project tools the team uses. Remote access into the network. Their mobile phone, if it’s a company one. Building or door-entry fobs. Even subscriptions signed up for with a company card.

Each of those is a thread that needs tidying up. Miss one, and you’ve left a loose end that could unravel months later – long after anyone remembers the person even had access.

A practical offboarding checklist

You don’t need anything fancy here. What you need is a consistent routine that gets followed every single time someone leaves, so nothing slips through. Here’s a sensible starting point.

Disable, don’t just delete. On their last day, disable the person’s main accounts rather than immediately deleting them. This cuts off access straight away while preserving anything you might need – emails, files, records – for handover or compliance.

Reset and revoke. Change passwords on any shared accounts they had access to, and revoke access to cloud apps, remote connections and third-party tools. Don’t forget multi-factor authentication – remove their device as an approved method.

Handle their email sensibly. Rather than just switching it off, consider forwarding it or setting up an auto-reply so customers and suppliers aren’t left in the dark. Redirect anything important to whoever’s picking up their work.

Reclaim the hardware. Collect laptops, phones, tokens and any other kit – and make sure company data is wiped or secured before that device goes anywhere near anyone else.

Sort the physical stuff too. Door fobs, alarm codes, keys. Security isn’t only digital.

Check the sneaky bits. Company card subscriptions, personal devices that were syncing work email, any accounts they set up personally for the business. These are the ones that hide.

Keep a record. Note what was done and when. If a question ever comes up later, you’ll be glad you did.

Why doing this by hand is harder than it sounds

On paper, that checklist looks manageable. In practice, it falls apart in a busy business for one simple reason: nobody’s quite sure what everyone actually has access to.

Access builds up quietly over the years. Someone gets added to a folder for one project, an app for a trial that became permanent, a system for cover during someone’s holiday. By the time they leave, their access is a patchwork that no single person fully remembers. So offboarding becomes a scramble of “did we get everything?” – and often, you don’t.

This is where having your systems set up properly in the first place pays off. When accounts and permissions are managed centrally and kept tidy, switching someone off is quick and complete. When they’re scattered across a dozen services with no overview, it’s guesswork.

Get it right before you need to

The best time to sort your offboarding process is well before anyone hands in their notice. A clear, repeatable routine – backed by systems that give you a proper view of who can access what – turns a stressful scramble into a ten-minute job.

If you’re not confident that leavers are being cleanly and completely cut off from your systems, that’s worth addressing now rather than after the next resignation. We help East Midlands businesses get their user accounts, permissions and access properly managed, so offboarding is one less thing to worry about.

Speak to Provident IT about getting your systems and user access under control – find out more about our Managed IT Support here.

About Provident IT

From ad-hoc technical support through to fully managed IT support, the Provident IT team can be your own internal IT department – but with more resources and lower costs. We work with businesses of all sizes and in all kinds of different capacities, with a proven track record for improving productivity, increasing security and reducing IT spend for our clients.

Recent Posts

Session Hijacking: How Attackers Skip Your Password Entirely

Strong passwords and MFA are essential, but session hijacking skips both entirely. By stealing the token that keeps you logged in, attackers can walk straight into your accounts. We explain how it works in plain English, why it slips past your usual defences, and the practical layers that actually help.

Read More