Articles · Security

2027-01-27 11 min EN / FR

Offboarding checklist: removing access when someone leaves

When an employee, freelancer or agency leaves, most companies disable the email account and consider it done. Weeks later they discover that the person still had admin access to the hosting dashboard, the shared password to the payment provider, a personal token on the code repository, and the only recovery phone number for a critical account.

Offboarding is a security task, a continuity task and, with personal data involved, a compliance task. It works best as a checklist you run every time.

Principles

  • Do it on the day, or before, depending on the situation. Access that lingers is a risk even with good intentions.
  • Plan for two scenarios: a friendly departure (more time, knowledge transfer) and an urgent one (immediate cut-off).
  • Know what each person has access to. If you cannot list it, that is the first problem to fix. Start with a 30-minute account ownership audit.
  • Transfer before you remove. Ownership and knowledge first, then access.

Step 1: Before the departure

When you know in advance:

  • Knowledge transfer: document what the person does, which systems they operate, recurring tasks and known issues
  • Ownership transfer: accounts, subscriptions, domains, repositories and automations that are in their name or tied to their login
  • Recovery paths: replace their phone number and email wherever they serve as the 2FA or recovery method
  • Shared credentials: list the ones they know, for rotation later
  • Open work: hand over tickets, branches, pending deployments and scheduled jobs
  • Customer and partner contacts: introduce the replacement

Step 2: On the day, access removal

Go through each category. Prefer suspending accounts first, deleting later, so that you do not lose data or break things that depend on them.

Identity and communication

  • Company email: suspend, set up forwarding or an auto-reply for a transition period, and delegate the mailbox contents to the manager
  • Single sign-on and identity provider: disable the account, which cascades to connected tools
  • Chat, video and collaboration tools
  • Calendar and shared resources: transfer meeting ownership and recurring events

Infrastructure and code

  • Cloud and hosting consoles (roles, access keys, SSH keys)
  • Servers: remove SSH keys and local accounts, check for personal tokens or scripts
  • Code repositories: remove from organisations and teams, review personal access tokens and deploy keys
  • CI/CD systems and secrets: revoke what they could use
  • VPN and firewall allowlists tied to their device or address
  • Databases and admin panels

Business tools

  • CRM, helpdesk, accounting, invoicing, HR tools
  • Payment providers and bank access
  • Marketing and analytics accounts, ad platforms, social media
  • App store and developer accounts
  • Domain registrar and DNS

Devices and physical access

  • Laptop, phone and other equipment: return, wipe or re-image according to your policy
  • Remote management and device policies
  • Badges, keys and office access
  • Personal devices that held company data: have the person remove it, and, where you use device management, remove the work profile

Need a clean access map before someone leaves?

We help inventory accounts, transfer ownership and put revocable access in place so offboarding is a checklist, not a scramble.

Step 3: Rotate shared secrets

Disabling the person's account does not protect you from credentials they know. Rotate:

  • Shared passwords (the "team" login to a tool, a Wi-Fi password, a shared admin account)
  • API keys and tokens they created or could view
  • Database passwords and application secrets they had access to
  • Webhook secrets and signing keys
  • Recovery codes and backup 2FA methods

Rotation is easier if secrets live in a vault and applications read them from there, so one change updates everything. If your secrets are scattered in config files and chat messages, a departure shows how costly that is.

For a freelancer or agency who was granted limited, revocable access from the start, the process is much lighter: remove the access and confirm that nothing important lived in their accounts.

Step 4: Handle the data

  • Email and files: decide what happens to the mailbox and documents. Retain what you need for business or legal reasons, then delete according to your retention rules. Giving a manager access to a mailbox is a privacy-sensitive decision, so follow your internal policy and keep it proportionate.
  • Personal data in their custody: local exports, downloaded reports and test databases must be located and deleted. For test copies of production, see GDPR and test environments.
  • Work on personal accounts or devices: ask for written confirmation of deletion and, for external providers, check the clauses in your agreement.
  • Logs: keep the audit trail of what happened and when.

Step 5: Verify

Do not assume it worked.

  • Try logging in as the person (or check the status of the account) in the main systems
  • Review access lists of your critical tools for their name, and for generic accounts they might have used
  • Check active sessions and tokens: many tools let you list and revoke them
  • Search the audit logs for activity after departure
  • Update your inventory of accounts and owners
  • Record the date, the person who performed it and the exceptions

Step 6: Communicate

  • Tell the team who takes over what
  • Inform customers and partners where relevant
  • Update the auto-reply and public contact points
  • Remove the person from mailing lists, on-call rotations and documentation as the owner
  • Keep a cordial tone. Offboarding is routine, not an accusation

The urgent version

When someone leaves abruptly or under dispute, work in this order:

  1. Identity provider and email: suspend immediately
  2. Production access: cloud, servers, repositories, deployment keys
  3. Money: payment providers, banking, ad accounts
  4. Domain and DNS
  5. Shared secrets: rotate the most sensitive first
  6. Review logs for recent unusual activity
  7. Everything else, following the full checklist

For freelancers and agencies

External providers deserve a specific process:

  • Accounts and access were granted by you, under your ownership, and are limited and time-bound
  • At the end of the engagement, remove access, rotate any secrets they were given, and receive the handover documentation
  • Obtain written confirmation of deletion of any personal data and credentials held, as your agreement requires
  • Check licences and subscriptions purchased in their name
  • Review what they deployed to make sure there are no remote access tools or hidden accounts left behind

Build this into the relationship from day one with the exit plan every client should require from a tech provider.

Common pitfalls

  • Disabling email only
  • Forgetting personal access tokens, SSH keys and deploy keys, which keep working after the account is disabled in some systems
  • Shared passwords never rotated
  • Recovery email and phone still pointing to the departed person
  • Automations and scheduled jobs running under their account, which stop working when it is suspended (hence the need to transfer first)
  • Deleting an account and losing the data or the ownership of the records
  • No record of who did what
  • Treating freelancers differently from employees, in the wrong direction (fewer checks instead of clearer, revocable access)

Checklist

Before

  • Knowledge transfer and documentation
  • Ownership of accounts, subscriptions, repositories and automations transferred
  • Recovery methods replaced

On the day

  • Identity provider and email suspended
  • Cloud, servers, code and CI/CD access removed
  • Business tools, payments, domain and DNS access removed
  • Devices returned or wiped

After

  • Shared secrets, API keys and tokens rotated
  • Data and mailbox handled according to policy
  • Logs reviewed, access verified
  • Inventory updated and the offboarding recorded

Related

From a scramble to a repeatable checklist

If access is scattered across people and tools, we can help you inventory, transfer and harden it before the next departure.