Onboarding gets attention because someone is waiting on it. Offboarding does not, because the person is already gone and nothing visibly breaks if it runs late.
Which is why it is one of the most common gaps we find. Accounts sit active for weeks or months, sometimes years. Cyber-insurance applications now ask about it specifically, so it has also stopped being a purely internal matter.
Why it matters more than it looks
An account belonging to someone who no longer works for you is an unmonitored door. Nobody watches it for odd logins, because nobody expects any logins at all.
There is a mundane version that costs money: you keep paying for licences for people who left. In most small businesses we review, that is a few hundred dollars a year quietly leaking.
And there is the awkward version. Departures are not always amicable, and access that outlives goodwill is a problem.
Do it on the last day
The single biggest improvement is timing. Same day, every time, from a written list. Nothing about it needs to be sophisticated, only consistent.
The checklist
1. Identity first
Disable the account in Microsoft 365 or Google Workspace before anything else. This is the master switch and it cuts most access in one move. Disable rather than delete, so you do not lose data you still need.
Then revoke active sessions. Disabling an account does not always kick out a session that is already running, and a phone holding a live session can keep working for a surprisingly long time.
Reset the password too. It sounds redundant after disabling, but it closes gaps in how some connected apps behave.
2. Multi-factor and recovery
Remove their authenticator registration and any recovery phone or email on the account. Recovery paths are a way back in, and they outlive the password.
3. Email
Decide what happens to the mail. Convert it to a shared mailbox so the team keeps the history, or forward to a manager for a defined period. Both work. Leaving the account fully active so someone can keep an eye on it does not.
Check for forwarding rules the departing person set up. Old trick, still works.
4. Files
Transfer ownership of files and shared drives before you remove the licence. On both platforms, deleting a user can take their personally-owned files with them once a grace period expires. This is the step people discover too late.
5. Third-party apps
Where small businesses lose track. Anything not tied to your main identity provider needs handling separately:
- Accounting software
- CRM and job management
- Password manager
- Banking and payment platforms
- Social media and marketing tools
- Domain registrar and hosting
- Any vendor portal they were the named contact on
Keep that list somewhere permanent. Building it once takes an hour and saves the guessing every time after.
6. Shared credentials
If they knew a password other people also use, change it. Shared logins are a bad idea generally, but they exist in almost every small business, usually for a bank portal or a utility account.
7. Devices
Collect the laptop and phone if they are company owned. Managed devices can be locked or wiped remotely, which matters when someone is remote or has already left the country.
Wipe and re-enrol before reissuing. Do not hand a machine to the next person with the previous person's profile still on it.
8. Physical and financial
Building access, alarm codes, any company card. IT usually stops at the laptop, but these belong on the same checklist because they get forgotten the same way.
9. Licences
Now reclaim the licences you are paying for. Leaving this until after the files are transferred avoids the accidental data loss that comes from doing it first.
What to keep
Retain the mailbox and files according to whatever your industry requires. Legal, accounting and healthcare all carry retention obligations that outlast employment. Note the date you disabled the account, because "when did access end" is a question that surfaces much later.
Make it boring
Write the list down. Put it where the whole team can find it. Run it the same way every time.
Offboarding failures are rarely a knowledge problem. They are a memory problem, and checklists are what we invented for those.
We build this into a same-day process for the businesses we run, so nobody has to hold it in their head. If yours is currently improvised, the insurance-readiness review will tell you what is still open.
Related guides
- The IT checklist accounting firms should finish before tax seasonThe work to finish in the quiet months, so nothing breaks between February and April 30.
- Payment redirection fraud, and why construction gets hit firstHow the scam works on a progress draw, the controls that stop it, and the first hour if it lands.
- Windows 10, a year after support ended: the October decisionWhat year two of Extended Security Updates costs, and how to decide machine by machine.