The Offboarding Checklist Small Teams Skip (And Regret)
Why Offboarding Is the Weak Link in Small Team Security
Most small teams have a rough process for bringing someone on. They set up an email, add them to Slack, maybe hand over a laptop. Far fewer teams have a real process for taking all of that away when someone leaves.
That gap matters more than it seems. A departing employee, whether they left on good terms or bad ones, often still has working logins to email, cloud storage, banking tools, CRM software, and shared drives. Every one of those accounts is a door left unlocked. It doesn’t take malice for that to become a problem. A former contractor’s laptop gets stolen. An old login gets caught in a data breach at some unrelated service and reused by an attacker. A departed employee’s personal email, still linked as account recovery, gets compromised years later.
The fix isn’t complicated, but it does require a checklist you actually follow every time, not just when you remember.
Build a Master List of Every Access Point First
You can’t revoke what you don’t know exists. Before you can build a real offboarding process, you need an inventory of everywhere your team has accounts. Most small businesses have never written this down.
Start with these categories
- Email and calendar
- Cloud storage (Google Drive, Dropbox, OneDrive, shared servers)
- Communication tools (Slack, Teams, Discord)
- Financial tools (banking portals, accounting software, payment processors, expense cards)
- Customer-facing systems (CRM, help desk, website admin, social media accounts)
- Development and infrastructure (code repositories, hosting accounts, VPN, admin panels)
- Physical access (building keys, badges, alarm codes, shared equipment)
For each item, note who has access, whether it’s a shared login or an individual one, and who owns the account (meaning who can revoke access without needing a password reset from IT support). This inventory takes an afternoon to build the first time and about ten minutes to update each time someone joins or leaves after that.
The Core Offboarding Sequence
When someone is leaving, whether the departure is planned or sudden, work through the same sequence every time. Order matters here, because some steps depend on others.
1. Revoke email access first
Email is usually the recovery method for every other account. If you cut it off first, you also cut off the easiest way for someone to reset passwords on other systems later. Disable the account rather than deleting it immediately, so you can still review sent and received messages if needed for a transition period.
2. Pull financial and payment access next
Remove the person from banking portals, accounting software, expense management tools, and any payment processor dashboards. Cancel any company cards issued to them. This is the category with the most direct financial exposure, so it should never wait until “later this week.”
3. Rotate shared credentials
If the departing person had access to any shared login, and small teams almost always have a few, that password needs to change immediately. A shared login can’t be selectively revoked for one person, so the only real fix is a full reset, followed by re-sharing the new credential only with people who still need it.
4. Remove them from cloud storage and communication tools
Check what folders or shared drives they had access to individually, not just through group membership. Group removal doesn’t always clear individual sharing permissions someone set up manually months earlier.
5. Disable developer and infrastructure access
If the person had access to code repositories, hosting accounts, servers, or a VPN, revoke those credentials and rotate any API keys or tokens they could have seen or used. This step gets missed constantly because it often sits with a different person than the one handling HR-related offboarding.
6. Collect and wipe physical devices
Company laptops, phones, and any hardware security keys should be collected before or on the last day whenever possible. If a device can’t be physically retrieved right away, remotely lock or wipe it if your setup allows that, and change any credentials that were stored on it.
7. Update recovery information everywhere
Check whether the departing employee’s personal phone number or email was set as a backup recovery method for any shared business account. This is easy to forget and easy to exploit later.
Handling Different Types of Departures
Planned departures
When someone gives notice, you have time to plan the transition. Use it. Schedule the access revocation for their actual last day, not “sometime that week,” and assign one person to own the checklist so nothing falls through because everyone assumed someone else handled it.
Sudden or contentious departures
If someone is terminated or leaves under difficult circumstances, move up the timeline. Revoke access before or at the moment they’re notified, not after. This isn’t about assuming bad intent, it’s about removing the possibility of a bad decision made in a stressful moment. Have the checklist ready to execute within minutes, not hours.
Contractors and temporary staff
Contractor access is often the most poorly tracked because it doesn’t go through the same HR process as a full-time hire. Set an expiration date on contractor accounts when you first create them, so access disappears automatically even if nobody remembers to remove it manually.
Make It a Repeatable Process, Not a One-Time Fix
A checklist only works if it’s used consistently. Write yours down somewhere the whole team can find it, assign clear ownership for each category (who handles financial tools, who handles infrastructure, who handles physical equipment), and review it every few months to make sure it still matches your current tool stack.
Also do a periodic access audit, separate from any individual offboarding, where you review who currently has access to what and confirm every name on the list still belongs there. Teams change tools and add contractors faster than they update their access records, and an audit twice a year catches accounts that should have been closed months earlier.
The Bottom Line
Offboarding security isn’t about distrust. It’s about closing doors that no longer need to stay open. A short, written checklist that gets followed every single time someone leaves, whether they were there for two weeks or five years, closes the biggest and most preventable security gap most small teams have.
For the complete, structured playbook on this topic, see Blog in our library. New here? Start with our free guide.