Securing Accounts When an Employee Leaves: An Offboarding Checklist

Six months after a marketing contractor wrapped up, a small agency noticed something odd: emails to the company's old campaigns@ address were still being forwarded to a personal Gmail nobody recognized. The contractor had set up the forward in their last week, and no one had ever turned it off. For half a year, a stranger had a quiet copy of client conversations.

Nothing dramatic happened. That is the point. Offboarding usually gets treated as an HR and payroll task: hand back the laptop, cancel the badge, move on. But the security half, the logins, the sessions, the shared passwords, tends to get skipped, and a former employee's forgotten access is one of the most common quiet doors into a small business. Here is a plain-English checklist to close it properly.

Why offboarding is a security problem, not just an HR one

When someone leaves, the goal is not only to stop paying them. It is to make sure they, or anyone who later gets hold of their old credentials, cannot reach anything. That is harder than it sounds, because access sprawls:

  • People accumulate logins to a dozen tools over their time with you, and no one keeps a full list.
  • Passwords get shared and reused, so "their" account often is not only theirs.
  • Logins live on personal phones and home laptops you do not control.
  • Some access hides behind third-party tools your main system does not touch.

Miss any one of those and you have left a door open, sometimes for months, exactly like that campaigns@ forward.

The offboarding security checklist

Work through these in order. The order matters: cut the master keys first, then chase down the rest.

1. Disable the primary identity first

Start with email and any single sign-on account, because those are the master key that resets everything else. Disable the account rather than deleting it outright, so you do not lose data or break shared calendars, but cut the login immediately.

2. Revoke active sessions, not just the password

This is the step people skip, and it is the campaigns@ lesson in a nutshell. Changing a password does not always kick out someone who is currently logged in. In each important account, use "sign out of all devices" or "revoke active sessions" so any live session, and any stolen session cookie, stops working right now.

3. Rotate any shared or reused passwords they knew

If the departing person used a shared login (a social account, a vendor portal, a service account), change it. Assume any password they had access to is now compromised, and update it everywhere it was used. A password manager makes this far less painful, and is the reason to stop sharing raw passwords in the first place.

4. Transfer their data, then remove access

Before you fully close things out, reassign or export what you need: email, files, documents in progress. Set up a mail forward or auto-reply to a current employee if clients might still write to them. Then remove their access to shared drives and folders.

5. Revoke third-party and app access

This is the sprawl people forget. Single sign-on does not cover everything. Check the tools that have their own separate logins: accounting software, the CRM, design tools, social schedulers, cloud storage, vendor portals. Each one may have a standalone account that survives after email is gone.

6. Remove them from MFA and recovery methods

Make sure their phone or authenticator is not still a two-factor or account-recovery method on shared or company accounts. A recovery method left in place can quietly undo everything else you just did.

7. Reclaim devices and clear work data from personal ones

Collect company hardware. For anyone who used a personal phone or laptop for work, remove the work accounts and any saved company passwords from that device. A saved login on a home laptop is a leak waiting to happen if that machine is ever infected.

8. Check whether their credentials have already leaked

Their old logins may already be circulating from a past breach or infostealer log. It is worth checking their work addresses for exposure, and, more importantly, keeping an eye on the domain going forward, so a dormant-but-leaked account does not resurface as a problem later. (Here is how to check business email exposure.)

9. Write down what you did

Keep a short record of the accounts you disabled and when. It takes two minutes and it is invaluable if a question ever comes up, or if you need to prove access was cut on a specific date.

When the departure is not friendly

Everything above matters more when someone leaves on bad terms. In those cases, compress the timeline: cut the primary identity and revoke sessions before or at the moment of the conversation, not the next day. A disgruntled ex-employee with still-active access, or one who quietly set up a forward or an extra recovery method on the way out, is a genuinely serious risk. Treat contentious departures as time-sensitive.

Don't forget contractors and freelancers

Offboarding is not just for full-time staff. Contractors, freelancers, seasonal help, and agencies you stop working with often accumulate more access than you would expect: a login to your CRM, editor access to your website, a seat in a shared design tool, or a folder in your cloud storage. Because they were never "employees," their access rarely goes through any formal exit process at all, so it just lingers. When a project wraps, run the same checklist for them: cut the login, revoke sessions, rotate anything shared, and remove app access. The campaigns@ forward at the start of this article came from exactly this gap, a contractor whose access nobody owned.

Make offboarding repeatable

The reason offboarding gets skipped is that it is ad hoc: it depends on someone remembering, under pressure, on a person's last day. Take the pressure off by making it routine. Keep a simple, living list of every tool and account the business uses, so when someone leaves you are working from a map instead of your memory. Turn this checklist into a one-page template you run every time, friendly departure or not. And build the security steps into your standard exit process alongside the HR ones, so cutting access is as automatic as collecting the laptop. A repeatable process is what turns "we think we got everything" into "we know we did."

How GuardPilot helps

A checklist handles the accounts you remember. The danger is the one you forget: the tool nobody logged into in a year, the shared inbox, the login that quietly leaked long ago. GuardPilot is the AI Incident Response Platform for Credential Exposure, and it watches your whole domain, including the accounts tied to people who have left, for any credential that shows up in a data breach or infostealer log. When one surfaces, its AI explains what leaked and how serious it is, and walks you through shutting it down, then keeps watching so a dormant account cannot quietly become an open door. It is the safety net under your offboarding process. You can start free and see what is already exposed in a couple of minutes, and while you are tightening things up, our guide on protecting your business from credential theft covers the prevention side.

Frequently asked questions

Should I delete the departing employee's account or just disable it?

Usually disable first, then delete later once you have transferred their data and confirmed nothing depends on it. Disabling cuts the login immediately without the risk of losing files or breaking shared resources.

Why revoke sessions if I already changed the password?

Because a password change does not always end an active session, and it will not stop someone using a stolen session cookie. Revoking sessions forces a fresh login everywhere, which the old credential can no longer provide.

We are tiny and everyone trusts each other. Is this overkill?

The risk usually is not the person, it is the forgotten access left behind after they are gone, which anyone who later gets those credentials can use. The checklist protects you from the leftover door, not from your former colleague.

How do I handle logins on someone's personal phone?

Remove the work accounts and any saved company passwords from the device, and revoke that device's sessions on your accounts. If it held sensitive access, rotate those passwords too.

What is the single most important step if I am short on time?

Disable the primary identity (email or single sign-on) and revoke its active sessions. That is the master key that can reset most other accounts, so cutting it, and any live session behind it, closes the biggest door fastest. Then work through the rest of the list when you can.

The takeaway

Offboarding is not done when the laptop comes back. It is done when every login is cut, every session revoked, every shared password rotated, and someone has checked that no quiet forward or leaked credential got left behind. Work the checklist in order, move fast when a departure is tense, and back it up by watching your domain for exposure. Do that, and a former employee's access stops being a risk the moment they walk out the door.

See what’s already exposed.

Run a free scan of your business email and domain. It takes about two minutes.

Start your free scan →