Safeguard Desk
Response Playbooks

What to Do If a Former Employee Still Has Access to Company Tools

What to Do If a Former Employee Still Has Access to Company Tools
A former employee retains access to company systems like email, cloud storage, or password managers—this playbook guides small teams through immediate account disabling, credential rotation, activity log review, and impact assessment to close the gap without a dedicated IT department.

You discover that a former employee still has access to email, a cloud drive, a project tool, the password manager, or another company system. Sometimes the discovery is routine—an audit or a login notification. Sometimes it comes after odd activity appears.

In either case the priority is the same: remove the access cleanly and determine whether anything needs further attention. This playbook is written for small teams that do not have a formal security or IT department.

Documentary style photo of a small business manager reviewing active user lists and accounts at an office desk.

Step 1: Confirm the Scope Quickly

Determine exactly what the former employee can still reach:

  • Company email or Microsoft 365 / Google Workspace account

  • Shared drives or cloud storage

  • Password manager

  • Project management, CRM, or industry tools

  • Banking, payroll, domain registrar, or other high-value systems

  • Admin or elevated roles in any of the above

Check both the primary identity account and any separate logins that may have been created. Note whether the access appears to have been used recently.

Step 2: Disable Access Immediately

Do not wait for a full investigation.

  • Disable or delete the former employee’s primary company account (email / Microsoft 365 / Google Workspace).

  • Remove them from the company password manager.

  • Deactivate accounts in every third-party tool they used.

  • Revoke any remaining admin or privileged roles.

  • Sign out active sessions where the platform allows it.

If shared credentials were used, change those passwords at once and update the remaining people who need them.

Speed matters more than perfect documentation at this stage.

Step 3: Rotate Sensitive Credentials

Even after accounts are disabled, assume that any passwords the person once knew may still be usable until they are changed.

Priority targets:

  • Shared or role-based logins they could access

  • Emergency or break-glass admin accounts

  • Domain registrar, DNS, and hosting panels

  • Banking and payment systems

  • Any system that does not support individual accounts cleanly

Store the new credentials in the company password manager and limit visibility to current staff who need them.

Step 4: Review for Signs of Misuse

Once access is removed, check for evidence that the access was used after the departure date:

  • Login history or sign-in logs for unfamiliar times, locations, or devices

  • Email forwarding rules or inbox rules created after the person left

  • Unexpected file downloads, deletions, or sharing changes

  • New users, API keys, or admin accounts created in relevant tools

  • Changes to billing, domain, or security settings

If nothing unusual appears, document that finding. If activity is present, preserve the logs and expand the review.

Step 5: Assess Business Impact and Next Actions

Ask two practical questions:

  1. Was any sensitive data or system likely accessed after the employee left?

  2. Does the nature of the departure or the activity observed raise concern about intentional misuse?

Most cases turn out to be simple operational oversights with no further activity. In those situations, closing the access and tightening the offboarding process is sufficient.

If there is evidence of misuse, or if the data involved is highly sensitive, consider additional steps: legal advice, customer notification (if required), or professional forensic help. Do not escalate automatically—match the response to what the evidence actually shows.

Step 6: Document and Fix the Process Gap

Documentary style close-up of a person updating an offboarding checklist and documenting incident review notes on paper.

Write a short internal note covering:

  • When the lingering access was discovered

  • What systems were still reachable

  • What was disabled or rotated

  • Whether any post-departure activity was observed

  • What changes will prevent a repeat

Then update the offboarding checklist so the same gap is less likely next time. Common root causes are missing steps on the checklist, shared logins that were never migrated, or unclear ownership of the offboarding process itself.

Preventing the Problem Going Forward

Lingering access is almost always an operational failure rather than a technical one. The highest-leverage prevention measures are:

  • A written, same-day offboarding checklist that is actually used

  • Individual accounts on important systems instead of shared logins

  • A company password manager that makes removal straightforward

  • Clear ownership of the offboarding process

  • Periodic light reviews of user lists on critical tools

These steps turn a recurring risk into a manageable routine.

Final Note

Finding that a former employee still has access is uncomfortable but usually fixable. The correct response is decisive removal of access, a focused check for misuse, credential rotation where needed, and a process improvement so it happens less often.

Most cases are the result of incomplete offboarding rather than malicious intent. Treat them as operational feedback.

Secure enough includes the ability to confirm that when someone leaves, their access leaves with them—and to act quickly when that does not happen.

Updated · 2026-09-07 10:11
Feedback

No feedback yet — submit the first.

Submit feedback
© 2026 Safeguard Desk. All rights reserved. data-driven, published weekly