The Offboarding Gap: What Happens to Access When People Leave
Accounts that outlive employment are a quiet but serious risk. Here is a same-day offboarding checklist that closes every door when someone leaves.
When someone leaves your business, the goodbye email goes out, the desk gets cleared, and everyone moves on. What often lingers is their access. Active accounts, live sessions, and shared passwords that outlive employment are one of the quietest and most common security risks a small business carries, and almost no one notices until something goes wrong.
The fix is not complicated. It is a disciplined, same-day process that leaves nothing open.
Why lingering access is so dangerous
A former employee's account is a door you have stopped watching. It may belong to someone who left on good terms, or it may be a credential that ends up for sale after a breach somewhere else. Either way, it is access that no longer maps to anyone in your building, which means no one is accountable for how it gets used.
The longer these accounts persist, the more they accumulate, until your real attack surface is much larger than your active headcount.
There is a compliance dimension too. In a regulated business, being able to show that access is granted and removed in a controlled way is part of demonstrating a mature program. An examiner who finds active logins tied to people who left months ago will reasonably wonder what else is not being tracked. Clean offboarding is not only good security. It is evidence that you take control of your environment seriously.
The same-day checklist
The goal on a departure day is simple: cut off every path in, not just the obvious one. Disabling the primary login is a start, but it is only a start.
- Disable the identity account and revoke active sessions so open logins do not keep working.
- Remove registered MFA devices so a personal phone cannot approve future sign-ins.
- Rotate any shared passwords the person knew.
- Check email for forwarding rules that could quietly send mail elsewhere.
- Include third-party SaaS apps and vendor portals, not just your core systems.
That last point is where most gaps hide. People accumulate logins to dozens of outside services over the years, and those are easy to forget on the way out.
Sessions and MFA outlive passwords
Disabling an account does not always end sessions that are already open, and it does not remove a phone that is still registered for multi-factor authentication. If you only reset the password, a former employee's already-authenticated session or registered device may keep working. Revoking sessions and removing MFA devices closes those gaps.
Do not forget forwarding rules
Email forwarding rules deserve special attention. A rule quietly set to copy messages to an outside address can keep leaking information long after an account is disabled, because the rule lives in the mail system rather than the person's device. Reviewing rules on departure, and periodically for active staff, closes a channel that is easy to miss.
Make the handoff automatic
The most reliable improvement you can make is to stop relying on memory. When HR knows someone is leaving, IT needs to know the same day, ideally through a defined trigger rather than a hallway conversation. Build a simple notification so that a departure automatically kicks off the offboarding checklist.
When the process starts by itself, access gets closed on time even on busy days.
Where to start
Write the checklist down and keep it with your offboarding records so it is followed the same way every time. Then connect HR and IT so a departure automatically starts the process. Finally, run a one-time review of existing accounts to find any that already belong to people who are gone. A managed services partner can help you build and automate this so nothing depends on someone remembering.