Offboarding staff without leaving security gaps
When someone leaves your firm, a clear offboarding routine ensures access is removed promptly and nothing sensitive walks out the door.
Onboarding usually gets careful attention because a new starter cannot work without access. Offboarding often gets less, yet it carries more risk. A departed employee whose access lingers is a quiet vulnerability: they may retain entry to client data long after their last day, whether through an active account, a saved password or a synced device. A simple, repeatable offboarding routine closes those gaps.
Why offboarding is a security issue
People leave for all sorts of reasons, and most departures are entirely amicable. But security planning is not about assuming bad intent; it is about removing the opportunity for harm, accidental or otherwise. Lingering access also complicates your audit trail, because actions taken on a former employee's account are hard to attribute and explain.
A practical offboarding checklist
Treat offboarding as a defined process that runs the same way every time, ideally owned by one person so nothing is missed.
Revoke access promptly
- Disable the identity provider account first. If you use single sign-on through Google or Microsoft, disabling the central account removes access to connected tools at once. This is the single most effective step.
- Check for separate logins. Any tool with its own password outside SSO needs to be handled individually.
- Reassign rather than delete immediately. Transfer the person's clients, jobs and to-dos to a colleague before deactivating, so work continues and records stay intact.
Recover and secure assets
- Collect or remotely wipe firm devices, including phones with email or app access.
- Rotate any shared credentials the person knew. Shared passwords are a weak practice, but where they exist, change them.
- Review documents they may have downloaded locally during their time with you.
Preserve the record
Keep the audit trail of the departed user's activity rather than erasing it. You may need it later to answer a question or investigate an issue. Platforms with role-based access and a retained audit trail, such as Finye, make reassignment and access removal straightforward while keeping the history intact.
Make it routine, not reactive
The biggest risk is an ad hoc offboarding done in a hurry on someone's last afternoon. Write the steps down, assign an owner, and run the same checklist every time. Tie the trigger to your HR process so IT and access removal start the moment a departure is confirmed, not days later.
Takeaway: write a standard offboarding checklist that disables central access first, reassigns work, recovers devices and preserves the audit trail, then run it the same way for every departure so no access is left behind.