Most offboarding goes fine. Someone gives notice, works out two weeks, hands back a laptop, and everybody signs a card. The account gets disabled a few days later when somebody remembers, and nothing bad happens. That is the normal case, and it is why offboarding rarely gets fixed.
The problem is that the process you use for the friendly departure is the same one you will have on the day of the unfriendly one. Terminations are not scheduled. When one happens at 9:15 on a Tuesday, you do not want to be inventing a checklist while the person is still sitting at a desk with an open laptop. Here is what a good offboarding process covers, why timing matters most, and the accounts almost every business forgets.
Timing Beats Everything Else
The single most common offboarding mistake is not a missed account. It is a delay. Access gets removed the following week, or after the final paycheck clears, or whenever IT gets around to the ticket. That window is the entire risk.
The rule we recommend is simple. Access ends at the moment of notification, not at the end of the day and not at the end of the week. For a voluntary resignation with a two week notice, that means access to sensitive systems gets reviewed and narrowed immediately, and full removal happens the moment the last day ends. For an involuntary termination, disabling accounts should happen while the conversation is happening, not after.
This is not about assuming the worst of people. It is about sequencing. A manager telling someone their role is eliminated is having a hard human conversation. Nobody in that room should also be responsible for remembering to call IT. Build the timing into the process so neither person has to think about it.
Lingering credentials are the workhorse of modern attacks. The Verizon 2025 Data Breach Investigations Report found credential abuse to be the most common way attackers get in, and that the human element was involved in roughly 60 percent of breaches. An account that still works after someone leaves is a credential with no owner watching it.
The Accounts Everyone Forgets
Everybody remembers email. Almost nobody gets the rest of the list on the first try. These are the ones we find left open when we audit a new client:
- SaaS tools bought on a personal card. The design tool, the scheduling app, the transcription service, the AI assistant. Nobody in IT knows it exists because it was expensed, not procured. This is exactly the problem we described in our piece on shadow IT, and offboarding is where it comes due.
- Shared logins. The front desk account, the shipping portal, the utility company website, the social media password everyone knows. Disabling the departing person’s own account does nothing here. The shared password has to be changed.
- MFA devices and authenticator apps. If their phone still holds a working authenticator token or a hardware key is still registered, the second factor is walking out with them. Remove registered devices, do not just reset the password. Our overview of what a YubiKey is explains why the physical key needs its own line on the checklist.
- VPN and remote access. Often configured separately from the main directory, sometimes years ago, sometimes by a vendor who is no longer involved.
- Door codes, alarm codes, and keys. A shared keypad code is a shared password with a physical lock attached. If the code was never personal, it needs to change.
- Phone forwarding and voicemail. Direct dial numbers that forward to a personal cell will keep forwarding after the person is gone, and customers will keep calling that number for months.
- Cloud drives and personal sync. A folder synced to a personal laptop keeps syncing until the account is disabled. Check for sharing links the person created, which can survive the account itself.
- Personal devices with company mail. A phone that was never company property but has your mailbox on it. You need the ability to remove company data from it, which is a thing you have to set up before you need it.
- Vendor and bank portals. Payroll, merchant services, the domain registrar. These usually sit outside your identity system entirely.
How common is this? A Beyond Identity survey of 1,121 employees and business leaders, published in 2022, found 83 percent of respondents said they continued accessing accounts from a previous employer after leaving, and 24 percent admitted to intentionally keeping a password. That survey is a few years old, and nothing about how businesses buy software since then has made the problem smaller.
The Data Question
There are two halves to this, and they pull in opposite directions. You want the departing person to stop having your data. You also want to keep their data, because you may need it.
On the keeping side, decide before the last day what happens to the mailbox and the files. A mailbox deleted on day one takes years of customer history with it. The usual answer is to convert it to a shared or archived state, forward it to the manager for a defined period, and preserve the contents according to whatever your industry requires. Files in personal cloud drives should move to a manager or a team location, not sit orphaned.
On the removing side, be honest about what is realistic. You cannot un-know a client list from someone’s memory. You can make sure copies are not sitting on a personal device, revoke shared links, and get any confidentiality obligation acknowledged in writing at the exit conversation. If a departure is contentious, tell your attorney before you delete anything. Preserving evidence and removing access are different jobs.
The Reusable Checklist
Write this down once and use it every time. The value is not the cleverness of any single item, it is that nobody has to remember anything under pressure.
- Before the conversation. HR notifies IT with a date and time. IT prepares but does not act. Manager confirms what data needs preserving.
- At the moment of notification. Disable the primary account, revoke active sessions, and remove registered MFA devices. Sessions matter, because a disabled account with a live session can keep working.
- Within the hour. Disable VPN and remote access. Change shared passwords the person knew. Change door and alarm codes.
- Same day. Remove phone forwarding, reassign the direct dial, and update voicemail. Remove company mail and data from personal devices.
- Same day. Collect laptop, phone, hardware keys, badges, and physical keys. Write down what came back and what did not.
- Within one business day. Convert the mailbox, transfer file ownership, and revoke sharing links the person created.
- Within one week. Walk the software list. Every SaaS tool, vendor portal, and bank site. Remove the user and cancel subscriptions that were only ever theirs. Reassign anything they owned, including domain renewals and alert emails sent to their address.
- Within 30 days. Review the account list and confirm it is actually gone, not just disabled and forgotten. Delete or archive per your retention policy.
The Bottom Line
Offboarding is not a security project. It is an operations habit with security consequences. The businesses that do it well are not the ones with the best tools. They are the ones where HR and IT agree in advance on who does what, and where the checklist lives somewhere both can find it.
Build it while nothing is happening. The day you need it is a bad day to write it.
If you want help building an offboarding checklist that matches the systems you actually use, or an audit of accounts still open from people who left months ago, we do this work for small and mid sized businesses across Denton County. Contact us today.
Sources:

Comments are closed