An employee is leaving. Secure offboarding without chaos or burned bridges
An employee departure requires more than disabling email. This practical checklist transfers work, removes access and treats the person with respect.
- AUTHOR
- Karol Rapacz / CEO Breachroad · OSCP · PNPT
- PUBLISHED
- 23 September 2026
- READING TIME
- 16 min read
- TOPIC
- Human Security
An employee resigns. Their team thinks about project handover, HR prepares documents, the manager considers recruitment, and IT gets a short message: “Disable the account on their last day.” That is not enough. The person may approve invoices, manage advertising, own customer files, administer the website, use a company card or be the sole owner of an automation.
Good offboarding does not assume malicious intent. It removes the company’s dependence on one identity and closes access that is no longer needed after employment. The process should be predictable, proportionate and dignified—security does not require humiliating a person.
Start with the date, role and risk level
HR or the manager should give the coordinator three reliable facts: when access ends, the last active working period, and whether the departure is standard or requires immediate action. A month-long handover is different from termination with immediate effect.
Do not distribute sensitive details in a broad email. The technical team needs timing and scope, not a judgement about the employee’s character. Where risk is elevated, HR, the manager, IT, security and legal counsel should agree the plan within a small group.
The access list must extend beyond company email
Begin with the central identity directory, but do not stop there. Review access to:
- email, messaging, drives and calendars;
- CRM, accounting, banking, payments and company cards;
- customer and partner systems;
- social media, advertising, marketing and webinar tools;
- domains, hosting, websites and online shops;
- code repositories, cloud services, backups and admin panels;
- HR platforms, electronic signatures and document workflows;
- applications purchased directly by a team;
- access cards, keys, tokens, phones, laptops and storage media;
- shared accounts, secrets and recovery codes.
A conversation with the employee is often the most effective way to find invisible tools. Do not ask only “Which accounts do you have?” Ask: “Which processes do you own, and what will stop working if you are unavailable tomorrow?”
Transfer ownership, not passwords
Files, calendars, forms, scheduled reports, advertising campaigns and integrations need a new owner. Sharing a folder is insufficient if the departing employee remains the owner of the document or billing account.
Do not ask them to write passwords in a spreadsheet or send them in chat. Reassign named accounts through administrative controls. Put legitimate shared accounts in the company password manager, then rotate the password and recovery codes after departure. If a service cannot transfer ownership, contact its provider before the last day.
Decide who takes over:
- open tasks and customer relationships;
- recurring payments and subscriptions;
- scheduled publications and campaigns;
- automations running under the employee’s identity;
- shared mailboxes and support queues;
- keys to safes, cabinets and rooms;
- knowledge of exceptions, workarounds and manual steps.
What should happen on the last day
For a standard departure, agree a precise time. Access should remain available for the handover as long as necessary, but not beyond employment. At the agreed point:
- disable the primary account and remote access;
- revoke active sessions, tokens and keys assigned to the person;
- remove administrative roles and customer-system access;
- disable access cards, payment cards and a company SIM where applicable;
- receive devices and record their condition;
- confirm that ownership of files and services has moved;
- configure an approved reply or contact route for business correspondence;
- record completion and the responsible person.
Disabling one directory account may not terminate already issued sessions in every application. Check the highest-value services separately and use central identity lifecycle management wherever practical.
Prefer a clear reply to silent mailbox surveillance
A departing employee’s mailbox may contain private employment discussions, candidate data and information a manager should not receive without limitation. Do not automatically forward all email “just in case.”
A better starting point is an automatic response stating that the person has left and providing a replacement contact. If local law and a legitimate need require access to specific correspondence, use an approved, limited process with an end date and an audit trail. HR and legal counsel should define the rules for the organisation and jurisdiction.
Personal devices and company data
If the employee used a personal phone or computer, the business must understand which company applications and data were available there. That does not create a right to erase private photos or the whole device. A managed work profile should allow company data to be removed without touching the private area.
Without such a control, agree a supervised process: sign out of accounts, remove company applications and local copies, return or transfer documents, and confirm completion. The policy should exist before departure—ideally when employment begins.
Immediate departures require synchronisation
When access must end without notice, IT should not disable the account too early or too late. HR conducts the conversation while an authorised person triggers restrictions at the agreed moment. Equipment and the access badge should be collected calmly and with regard for dignity and safety.
An urgent departure does not automatically justify reading the employee’s entire history. Monitoring and preservation actions need a basis, defined scope and proper approval. Emotion around a departure is not a substitute for risk assessment.
Check again the next day and after a month
Offboarding does not end when the laptop is returned. The next day, confirm that:
- the account did not sign in after the deadline;
- critical tasks and automations still run;
- customers have a current contact;
- no unnecessary external sharing remains;
- returned hardware is recorded and queued for secure preparation;
- every exception has an owner and closure date.
After several weeks, review subscriptions, mailing lists, guest accounts and partner systems. Those are common places for access missed on the final day.
Treat the person as you want future reporters to be treated
An employee who feels respected is more likely to disclose an informal account, forgotten automation or customer-side file. A clear checklist, time to transfer knowledge and one named coordinator work better than suspicion.
At the end, ask what was unclear and where the business depended on the person’s private knowledge. That feedback improves onboarding for their successor and the next version of the process.
Source facts and Breachroad recommendations
The NCSC recommends a joiners, movers and leavers process and automatic access removal when a person leaves a role or organisation. Its guidance also says accounts—especially administrative ones—should be revoked promptly when no longer required.
The business-process inventory, transfer of ownership instead of passwords, constrained access to the former mailbox and post-departure checks are Breachroad recommendations. They must account for employment law, privacy and organisational policy. Our guide to business password managers covers safe access sharing. Managers, HR and IT can rehearse the process together in organisational cybersecurity training.

