Jeyki SecurityCybersecurity consulting
Offboarding

Employee Offboarding Security Checklist: Revoking Access the Right Way

A practical checklist for small businesses to remove a departing employee's access cleanly, covering accounts, devices, shared logins, and the data they leave behind.

← Back to guidesPublished 2026-08-20 · Updated 2026-08-20

Why offboarding is a security control, not just an HR task

A surprising number of small-business incidents trace back to access that should have been removed months or years earlier: a former employee's account still active, a shared login never rotated, a personal phone still receiving company email. Offboarding is one of the highest-leverage, lowest-cost security controls a small business has, and it is the one that gets skipped most often under time pressure.

The order of operations matters

Rushing straight to deletion can lose important data. Blocking access too slowly leaves a window open. A short, ordered sequence handles both.

  • Block sign-in immediately: reset the password and revoke active sessions the moment departure is confirmed
  • Preserve needed data: convert the mailbox to shared, or export files another staff member will need
  • Reassign ownership: shared documents, calendars, and recurring meetings owned solely by the departing employee
  • Reclaim the license once data is secured, since licenses are a recurring cost even for disabled accounts
  • Delete the account only after data has been preserved and reassigned

Accounts and access beyond the main email login

The primary email account is the obvious one. Most gaps happen in the accounts nobody thinks to check on the way out.

  • Shared logins for social media, the domain registrar, hosting, and vendor portals
  • VPN or remote-access credentials
  • Password manager access and any vaults they could view
  • Third-party apps connected via 'Sign in with Google/Microsoft' that may retain access tokens
  • Physical access: building keys, alarm codes, and any shared PINs they knew

Devices: company-owned and personal

Device access is where offboarding is easiest to forget, especially for remote or hybrid staff.

  • Collect and wipe company-owned laptops and phones before reissuing them
  • Remove company email and app access from personal devices under a bring-your-own-device policy
  • Revoke access from any personal device where the person set up an authenticator app tied to shared accounts

A same-day checklist for a standard departure

For most voluntary, low-friction departures, aim to complete the following on the last working day.

  • Disable sign-in and force a password reset on the primary account
  • Revoke active sessions and re-authenticate any shared devices
  • Remove from all group memberships, shared mailboxes, and distribution lists
  • Rotate any shared credentials the person had visibility into
  • Confirm with their manager that all owned documents and calendars have a new owner

Frequently asked questions

How is offboarding different for a difficult or involuntary departure?

Timing shifts: access should be revoked before or at the moment the person is informed, not afterward, since delayed revocation is one of the most common causes of retaliatory access in involuntary terminations. Coordinate the access cutoff with HR and management so it happens at the right moment.

Do we need to keep a former employee's mailbox forever?

Not usually forever, but converting it to a shared mailbox or applying a retention hold for a defined period lets colleagues access needed history without keeping an active, licensed account open indefinitely. Set a review date to eventually archive or remove it once the data is no longer needed.

What is the single most commonly forgotten offboarding step?

Shared logins for accounts outside the main email system, particularly social media, the domain registrar, and vendor portals, which often live in a spreadsheet or a founder's memory rather than a managed system. A password manager with proper offboarding controls closes this gap.

Official resources