Digital security

When an Employee Leaves: The Digital Offboarding Checklist

Offboarding is not only closing an email account. It is revoking sessions, recovering devices, transferring work and confirming that access is gone.

An employee can leave the office while their digital access remains.

Email sessions stay active on a personal phone. Shared passwords are unchanged. Cloud files remain synchronised. A social account still recognises the old device. Supplier portals continue to work. Customer information stays inside a personal WhatsApp history.

Offboarding should close the relationship cleanly without losing the business knowledge required to continue.

Shoppers and roadside businesses in Serekunda
Access should follow a person’s role and end cleanly when that role changes. Photo: tjabeljan, Wikimedia Commons, CC BY 2.0.

Prepare before the final day

Where the departure is planned, identify:

  • role and manager
  • final working time
  • company and personal devices used
  • accounts and applications
  • administrator privileges
  • shared credentials known
  • files and records owned
  • customers, suppliers and projects in progress
  • physical keys, cards and tokens
  • required handover

The list should come from both central records and the employee’s manager. Technology teams may know the email account but not the informal tools adopted by a department.

Decide the timing based on risk

Not every departure follows the same sequence.

A routine planned departure may allow a structured handover before access is closed. An involuntary or high-risk departure may require immediate, coordinated revocation.

Human resources, management and the technical owner should agree on timing. The employee should not receive access beyond the authorised moment, but premature removal should not destroy records or prevent a controlled transition.

Disable the identity and revoke sessions

Changing a password may not close every active session.

The process should address:

  • primary email or identity account
  • active sessions and trusted devices
  • multifactor authentication methods
  • application passwords and tokens
  • remote access and VPN
  • single sign-on connections
  • administrator roles
  • recovery details
  • delegated mailbox or calendar access

Where supported, block sign-in and explicitly revoke sessions.

Remove access from every business platform

Review systems such as:

  • cloud files and collaboration
  • CRM
  • accounting and finance
  • booking or property systems
  • ecommerce and payment tools
  • social media
  • advertising and analytics
  • website and hosting
  • code repositories
  • support and ticketing
  • supplier portals
  • network, cameras and access control
  • password manager
  • automation and AI tools

Do not assume removing email access automatically removes every external application.

Handle shared passwords deliberately

If the employee knew shared credentials, changing them may be necessary.

This can include:

  • Wi-Fi
  • network administration
  • social or shared service accounts
  • door and alarm codes
  • device PINs
  • supplier portals
  • recovery secrets
  • emergency accounts

The better long-term solution is to replace shared access with individual accounts wherever practical. Offboarding becomes faster and safer when permissions belong to identities rather than memories.

Recover and assess devices

Collect company laptops, phones, tablets, keys, security tokens, storage devices and SIMs.

Record condition and confirm:

  • device ownership
  • encryption status
  • current user
  • management status
  • locally stored business data
  • required backup
  • remote wipe capability
  • repair or reset needs
  • reassignment or disposal plan

If business information was used on a personal device, follow the company’s policy and applicable obligations. The aim is to remove corporate access and data without taking personal information that does not belong to the company.

Transfer work before deleting anything

Email, files, customer relationships and active tasks may need a new owner.

Transfer:

  • mailbox responsibility where appropriate
  • important documents
  • calendars and scheduled meetings
  • CRM records and follow-ups
  • open quotations, bookings or support cases
  • supplier communication
  • administrative documentation
  • project ownership

Avoid simply forwarding everything indefinitely. Define what the new owner needs, how long any automatic response remains and when old access or routing will be removed.

Protect customer communication

If the employee used WhatsApp or another messaging channel for customers, identify:

  • account ownership
  • device and number ownership
  • active conversations
  • outstanding promises
  • data that belongs in the approved business system
  • the customer communication required

Customers should receive continuity without private conversations being copied indiscriminately.

This is one reason customer relationships should not depend entirely on personal phones.

Confirm the result

After revocation, verify:

  • sign-in is blocked
  • sessions are closed
  • administrator roles are removed
  • devices are recovered or managed
  • shared secrets are changed where required
  • work is transferred
  • automatic responses are correct
  • physical access is closed
  • the event is documented

Review logs or sign-in activity if the risk warrants it.

Learn from every departure

Offboarding often reveals weaknesses in onboarding.

If the business cannot identify an employee’s access, the original access-granting process was incomplete. Update the role template, system inventory and manager checklist so the next employee begins with clearer control.

Good offboarding starts with good onboarding.

Close access without losing the work

People change. Business access should change with them.

Palmward helps organisations map identities, devices, information and supplier access into a repeatable process for joiners, movers and leavers.

Good offboarding closes the accounts, protects the business, preserves the work and leaves responsibility clear on both sides.

The wider business account ownership checklist helps identify the systems that offboarding must cover. If the company cannot produce that list, start with a business technology audit.


Contact