Digital security
When an Employee Leaves: The Digital Offboarding Checklist
Offboarding is not only closing an email account. It is revoking sessions, recovering devices, transferring work and confirming that access is gone.

An employee can leave the office while their digital access remains.
Email sessions stay active on a personal phone. Shared passwords are unchanged. Cloud files remain synchronised. A social account still recognises the old device. Supplier portals continue to work. Customer information stays inside a personal WhatsApp history.
Offboarding should close the relationship cleanly without losing the business knowledge required to continue.
Prepare before the final day
Where the departure is planned, identify:
- role and manager
- final working time
- company and personal devices used
- accounts and applications
- administrator privileges
- shared credentials known
- files and records owned
- customers, suppliers and projects in progress
- physical keys, cards and tokens
- required handover
The list should come from both central records and the employee’s manager. Technology teams may know the email account but not the informal tools adopted by a department.
Decide the timing based on risk
Not every departure follows the same sequence.
A routine planned departure may allow a structured handover before access is closed. An involuntary or high-risk departure may require immediate, coordinated revocation.
Human resources, management and the technical owner should agree on timing. The employee should not receive access beyond the authorised moment, but premature removal should not destroy records or prevent a controlled transition.
Disable the identity and revoke sessions
Changing a password may not close every active session.
The process should address:
- primary email or identity account
- active sessions and trusted devices
- multifactor authentication methods
- application passwords and tokens
- remote access and VPN
- single sign-on connections
- administrator roles
- recovery details
- delegated mailbox or calendar access
Where supported, block sign-in and explicitly revoke sessions.
Remove access from every business platform
Review systems such as:
- cloud files and collaboration
- CRM
- accounting and finance
- booking or property systems
- ecommerce and payment tools
- social media
- advertising and analytics
- website and hosting
- code repositories
- support and ticketing
- supplier portals
- network, cameras and access control
- password manager
- automation and AI tools
Do not assume removing email access automatically removes every external application.
Handle shared passwords deliberately
If the employee knew shared credentials, changing them may be necessary.
This can include:
- Wi-Fi
- network administration
- social or shared service accounts
- door and alarm codes
- device PINs
- supplier portals
- recovery secrets
- emergency accounts
The better long-term solution is to replace shared access with individual accounts wherever practical. Offboarding becomes faster and safer when permissions belong to identities rather than memories.
Recover and assess devices
Collect company laptops, phones, tablets, keys, security tokens, storage devices and SIMs.
Record condition and confirm:
- device ownership
- encryption status
- current user
- management status
- locally stored business data
- required backup
- remote wipe capability
- repair or reset needs
- reassignment or disposal plan
If business information was used on a personal device, follow the company’s policy and applicable obligations. The aim is to remove corporate access and data without taking personal information that does not belong to the company.
Transfer work before deleting anything
Email, files, customer relationships and active tasks may need a new owner.
Transfer:
- mailbox responsibility where appropriate
- important documents
- calendars and scheduled meetings
- CRM records and follow-ups
- open quotations, bookings or support cases
- supplier communication
- administrative documentation
- project ownership
Avoid simply forwarding everything indefinitely. Define what the new owner needs, how long any automatic response remains and when old access or routing will be removed.
Protect customer communication
If the employee used WhatsApp or another messaging channel for customers, identify:
- account ownership
- device and number ownership
- active conversations
- outstanding promises
- data that belongs in the approved business system
- the customer communication required
Customers should receive continuity without private conversations being copied indiscriminately.
This is one reason customer relationships should not depend entirely on personal phones.
Confirm the result
After revocation, verify:
- sign-in is blocked
- sessions are closed
- administrator roles are removed
- devices are recovered or managed
- shared secrets are changed where required
- work is transferred
- automatic responses are correct
- physical access is closed
- the event is documented
Review logs or sign-in activity if the risk warrants it.
Learn from every departure
Offboarding often reveals weaknesses in onboarding.
If the business cannot identify an employee’s access, the original access-granting process was incomplete. Update the role template, system inventory and manager checklist so the next employee begins with clearer control.
Good offboarding starts with good onboarding.
Close access without losing the work
People change. Business access should change with them.
Palmward helps organisations map identities, devices, information and supplier access into a repeatable process for joiners, movers and leavers.
Good offboarding closes the accounts, protects the business, preserves the work and leaves responsibility clear on both sides.
The wider business account ownership checklist helps identify the systems that offboarding must cover. If the company cannot produce that list, start with a business technology audit.
Contact