Picture a former employee, maybe one who didn't leave on the best terms. Their login still works. Their email still forwards. They can still open the customer database, the cloud storage, and the project tool. That isn't a worst-case hypothetical. For a lot of small businesses, it's just what happens when someone leaves and nobody formally shuts the door behind them.
When a team member departs, their access doesn't vanish on its own. Every login, account, and permission they collected has to be deliberately switched off. When that doesn't happen in a tidy way, you're left with an open door long after the person is gone, and most of the time it isn't malice, just an honest oversight. Old accounts become easy targets for attackers, forgotten subscriptions keep billing you, and sensitive files linger in personal inboxes.
Why a handshake and a returned laptop isn't enough
People accumulate access over the years they're with you: email, your customer system, cloud storage, social media logins, financial software, internal servers. A returned laptop covers exactly one of those. Without a clear list to work from, something is almost guaranteed to slip through the cracks.
Leftover accounts are a favorite target for attackers. If a former staffer reused a work password somewhere that later gets breached, that old account can hand a stranger trusted access to your systems. Security professionals consistently flag access left behind by former employees as one of the most overlooked weak spots a business has, and depending on your industry, it's a compliance problem too.
What a solid offboarding process looks like
Good offboarding is a security measure, not just an HR errand. It needs to be quick, thorough, and the same every time, whether someone resigns, retires, or is let go. The job is to systematically remove a person's entire digital footprint from your business.
It should start before the final day, with your HR and IT efforts working in step. And it begins with one thing: a single, central list of every asset and account the person has. You can't switch off what you don't know exists.
Your offboarding checklist
A checklist turns "we should probably handle that" into clear steps nobody forgets. Here's a core framework you can adapt:
- Cut network access right away. The moment someone leaves, revoke their main login, remote-access connection, and any way in from outside the office.
- Reset shared passwords. Social media accounts, shared mailboxes, and any folders or workspaces the whole team uses.
- Pull cloud permissions. Remove them from Microsoft 365, Google Workspace, your chat tool, your project software, and the rest. A single sign-on setup, one secure login that controls access to everything, makes this far easier.
- Reclaim every device. Collect company laptops and phones, and securely wipe them before they're handed to anyone else. Don't forget tools that let you wipe a phone or tablet remotely.
- Redirect their email. Forward it to a manager or replacement for a month or two, then archive or close the mailbox. An auto-reply noting the change and a new contact keeps things tidy.
- Move their files. Make sure nothing important lives only on a personal device, and transfer ownership of shared documents and projects.
- Check the access logs. Look at what they opened in their last few days. Was sensitive customer data downloaded? Did it need to be?
What it costs when this is skipped
The fallout is very real. A departing salesperson could walk out with your entire client list; a disgruntled developer could alter or delete critical work. Even accidental leftover data on a personal device can break privacy laws and lead to fines. There's a quieter cost, too: subscriptions that keep billing you for people who left months ago. Individually small, but collectively a sign that nobody's minding the store.
Build a habit of secure goodbyes
The strongest version of this makes offboarding part of how your business runs from day one, even mentioned in security training, so everyone understands that access is a temporary part of the job, not a permanent keepsake. Write down each step as you go, too. That record proves the work was done, and it makes the process repeatable as you grow.
Treat every departure as a chance to review who has access to what and clean up anything stale. The same "only the access you need" thinking that powers a zero-trust approach applies here, and tightening up sign-ins generally is covered in our guide to stopping account hacks.
Don't let former employees linger in your systems. A clear, written process is your best defense against this quiet insider risk, and if you'd like help building one (or automating it so it runs the same way every time), that's exactly the kind of thing we set up for businesses across the Denver area.