Onboarding gets attention because someone is waiting on it. Offboarding does not, because the person is already gone and nothing visibly breaks if it is late.
That is exactly why it is one of the most common gaps we find. Accounts sit active for weeks or months. Sometimes years. It is also one of the specific things cyber-insurance applications now ask about, so it has stopped being a purely internal matter.
Why it matters more than it looks
An account belonging to someone who no longer works for you is an unmonitored door. Nobody is watching for odd logins, because nobody expects any logins at all.
There is also a mundane version that costs money: you keep paying for licences for people who left. In most small businesses we review, that is a few hundred dollars a year quietly leaking.
And there is the awkward version. Departures are not always amicable, and access that outlives goodwill is a problem.
Do this on the last day, not the last week of the month
The single biggest improvement is timing. Same day, every time, from a written list. It does not need to be sophisticated. It needs to be consistent.
The checklist
1. Identity first
Disable the account in Microsoft 365 or Google Workspace before anything else. This is the master switch and it cuts most access in one move. Disable rather than delete, so you do not lose data you still need.
Then revoke active sessions and sign-outs. Disabling an account does not always kick out a session that is already running, and a phone with a live session can keep working for a surprisingly long time.
Reset the password too. It sounds redundant after disabling, but it closes gaps in how some connected apps behave.
2. Multi-factor and recovery
Remove their authenticator registration and any recovery phone or email on the account. This matters because recovery paths can be used to get back in later.
3. Email
Decide what happens to mail. Common options: convert to a shared mailbox so the team keeps access to history, or forward to a manager for a defined period. Both are fine. Leaving the account fully active so someone can "keep an eye on it" is not.
Also check for forwarding rules the departing person set up. This is an old trick and it still works.
4. Files
Transfer ownership of files and shared drives before you remove the licence. On both platforms, deleting a user can take their personally-owned files with them after a grace period. This is the step people discover too late.
5. Third-party apps
This is where small businesses lose track. Anything not tied to your main identity provider needs handling separately:
- Accounting software
- CRM and job management
- Password manager
- Banking and payment platforms
- Social media and marketing tools
- Domain registrar and hosting
- Any vendor portal they were the named contact on
Keep a list of these somewhere permanent. Building it once takes an hour and saves the guessing every time.
6. Shared credentials
If they knew a password that other people also use, change it. Shared logins are a bad idea in general, but they exist in almost every small business, usually for a bank portal or a utility account.
7. Devices
Collect the laptop and phone if they are company owned. If devices are managed, you can lock or wipe remotely, which matters when someone is remote or has already left the country.
Wipe and re-enrol before reissuing. Do not hand a machine to the next person with the previous person's profile on it.
8. Physical and financial
Building access, alarm codes, and any company card. IT usually stops at the laptop, but these belong on the same checklist because they get forgotten the same way.
9. Licences
Now reclaim the licences you are paying for. Doing this last, after files are transferred, avoids the accidental data loss that comes from doing it first.
What to keep
Retain the mailbox and files according to whatever your industry requires. Legal, accounting, and healthcare all have retention obligations that outlast employment. Note the date you disabled the account, because "when did access end" is a question that occasionally gets asked much later.
Make it boring
Write the list down. Put it somewhere the whole team can find. Run it the same way every time.
That is the whole trick. Offboarding failures are almost never a knowledge problem. They are a memory problem, and checklists fix memory problems.
If you would like us to build this into a same-day process you do not have to think about, that is part of what we do. The free check is a good place to start.