When someone leaves a small business, the work they were doing usually gets redistributed the same day. Their access to company systems often does not.
Email stays active. Shared drives remain reachable. The password manager, project tools, vendor portals, and sometimes even banking or domain accounts continue to work. Weeks later someone notices the former employee still appears in a user list—or worse, an incident traces back to credentials that should have been disabled.
This is one of the most common and most preventable security gaps in small teams. The fix is not complicated technology. It is a short, repeatable checklist executed with the same urgency as collecting the laptop.

Why Offboarding Fails in Small Companies
In organizations without a dedicated IT or HR security function, offboarding is usually handled by whoever is least busy that day. The focus stays on work continuity: transferring files, updating customers, reassigning tasks. Access removal becomes a secondary task that slips.
Shared logins make the problem worse. If three people used the same password for a critical tool, simply “removing the departing employee” has no clear technical meaning.
A written checklist turns an ad-hoc scramble into a reliable process.
The Same-Day Offboarding Checklist
Complete these steps on the employee’s last day (or the day you learn they are gone). Do not wait for the final paycheck cycle or a quieter week.
1. Collect all company devices
Laptops, phones, tablets, security keys, access cards, and any adapters or external drives. Record serial numbers if you track assets. If the employee works remotely, arrange prompt return and disable access while the device is still in transit.
2. Disable or delete the primary identity account
This is usually the Microsoft 365 or Google Workspace account. Disabling it immediately cuts off email, calendar, and most connected cloud services. Deleting can wait until you have transferred any needed files.
3. Remove the user from the company password manager
Revoke their vault access the same day. If they had stored personal passwords there, give them a short window to export those only—company credentials stay.
4. Rotate credentials for any shared or role-based accounts they could access
Even if individual accounts are the rule, exceptions exist. Change passwords on shared vendor portals, social media accounts, domain registrar logins, emergency admin accounts, and any other system that did not use unique credentials.
5. Review admin and privileged roles
Check Microsoft 365 / Google admin centers, cloud consoles, banking portals, payroll systems, and domain hosts. Remove the departing employee from any elevated roles.
6. Transfer or secure shared data
Move ownership of shared drives, important documents, customer folders, and project boards to a remaining team member or a generic company account. Confirm that external sharing links they created are still appropriate.
7. Check email forwarding, inbox rules, and app passwords
Look for forwarding rules that send mail outside the company and for app-specific passwords that might still grant access. Remove anything unexpected.
8. Revoke access to third-party tools
Project management, CRM, design tools, marketing platforms, accounting add-ons, and industry software often maintain separate user lists. Go through the short list of tools the person actually used and deactivate their accounts.
9. Update internal records
Note the departure date, devices collected, accounts disabled, and credentials rotated in a simple shared log. This record is useful if questions arise later.

10. Confirm MFA and recovery methods are cleared
Ensure no personal phone numbers or authenticator apps belonging to the former employee remain as recovery options on company accounts.
Handling Common Complications
Remote employees
Disable accounts first, then arrange device return. Consider remote wipe capability if the device is company-owned and enrolled in basic management.
Sudden or contentious departures
Prioritize identity account disablement and password rotation on critical systems within the first hour. Device collection and thorough review can follow immediately after.
Shared devices or shared logins that still exist
Treat the departure as the trigger to eliminate the shared login. Create individual accounts for remaining staff and store credentials properly in the password manager.
Former employees who still “need temporary access”
Avoid this whenever possible. If genuinely required, create a time-limited account with minimal permissions and a firm end date. Do not simply leave the original account active.
Making the Process Sustainable
Keep the checklist to one page.
Store it where the people who handle departures can find it immediately.
Assign primary responsibility (operations lead, office manager, or owner).
Run through it the same day, every time—no exceptions for “trusted” departures.
Review the checklist twice a year to add or remove tools as the company stack changes.
The Link to Broader Access Hygiene
Clean offboarding is much easier when the company already follows basic access rules: individual accounts on important systems, a password manager as the standard, MFA on critical tools, and a consistent new-employee setup process. When those foundations are in place, removing someone becomes a short sequence rather than an archaeological dig.
Final Note
Leaving access behind is rarely malicious. It is almost always the result of competing priorities and the absence of a simple process. A same-day checklist protects the business without requiring specialized security knowledge or expensive tools.
The best time to remove access is before it becomes a problem. The second-best time is the day the person leaves.
Secure enough includes knowing that when someone walks out, their access walks out with them.
No feedback yet — submit the first.