You discover that a former employee still has access to email, a cloud drive, a project tool, the password manager, or another company system. Sometimes the discovery is routine—an audit or a login notification. Sometimes it comes after odd activity appears.
In either case the priority is the same: remove the access cleanly and determine whether anything needs further attention. This playbook is written for small teams that do not have a formal security or IT department.

Step 1: Confirm the Scope Quickly
Determine exactly what the former employee can still reach:
Company email or Microsoft 365 / Google Workspace account
Shared drives or cloud storage
Password manager
Project management, CRM, or industry tools
Banking, payroll, domain registrar, or other high-value systems
Admin or elevated roles in any of the above
Check both the primary identity account and any separate logins that may have been created. Note whether the access appears to have been used recently.
Step 2: Disable Access Immediately
Do not wait for a full investigation.
Disable or delete the former employee’s primary company account (email / Microsoft 365 / Google Workspace).
Remove them from the company password manager.
Deactivate accounts in every third-party tool they used.
Revoke any remaining admin or privileged roles.
Sign out active sessions where the platform allows it.
If shared credentials were used, change those passwords at once and update the remaining people who need them.
Speed matters more than perfect documentation at this stage.
Step 3: Rotate Sensitive Credentials
Even after accounts are disabled, assume that any passwords the person once knew may still be usable until they are changed.
Priority targets:
Shared or role-based logins they could access
Emergency or break-glass admin accounts
Domain registrar, DNS, and hosting panels
Banking and payment systems
Any system that does not support individual accounts cleanly
Store the new credentials in the company password manager and limit visibility to current staff who need them.
Step 4: Review for Signs of Misuse
Once access is removed, check for evidence that the access was used after the departure date:
Login history or sign-in logs for unfamiliar times, locations, or devices
Email forwarding rules or inbox rules created after the person left
Unexpected file downloads, deletions, or sharing changes
New users, API keys, or admin accounts created in relevant tools
Changes to billing, domain, or security settings
If nothing unusual appears, document that finding. If activity is present, preserve the logs and expand the review.
Step 5: Assess Business Impact and Next Actions
Ask two practical questions:
Was any sensitive data or system likely accessed after the employee left?
Does the nature of the departure or the activity observed raise concern about intentional misuse?
Most cases turn out to be simple operational oversights with no further activity. In those situations, closing the access and tightening the offboarding process is sufficient.
If there is evidence of misuse, or if the data involved is highly sensitive, consider additional steps: legal advice, customer notification (if required), or professional forensic help. Do not escalate automatically—match the response to what the evidence actually shows.
Step 6: Document and Fix the Process Gap

Write a short internal note covering:
When the lingering access was discovered
What systems were still reachable
What was disabled or rotated
Whether any post-departure activity was observed
What changes will prevent a repeat
Then update the offboarding checklist so the same gap is less likely next time. Common root causes are missing steps on the checklist, shared logins that were never migrated, or unclear ownership of the offboarding process itself.
Preventing the Problem Going Forward
Lingering access is almost always an operational failure rather than a technical one. The highest-leverage prevention measures are:
A written, same-day offboarding checklist that is actually used
Individual accounts on important systems instead of shared logins
A company password manager that makes removal straightforward
Clear ownership of the offboarding process
Periodic light reviews of user lists on critical tools
These steps turn a recurring risk into a manageable routine.
Final Note
Finding that a former employee still has access is uncomfortable but usually fixable. The correct response is decisive removal of access, a focused check for misuse, credential rotation where needed, and a process improvement so it happens less often.
Most cases are the result of incomplete offboarding rather than malicious intent. Treat them as operational feedback.
Secure enough includes the ability to confirm that when someone leaves, their access leaves with them—and to act quickly when that does not happen.
No feedback yet — submit the first.