Almost every business has a process for someone joining. Far fewer have one for someone leaving, and the gap tends to show up much later — an invoice paid to a changed bank account, a file share nobody could get into, a subscription still billing two years on.

None of it is complicated, but it needs to be written down rather than remembered.

Do these on the last day

Order matters here, because a couple of these steps destroy data if you take them too early.

  • Reset the password and revoke active sessions. A password change alone doesn’t kick someone out of a session already signed in on a phone.
  • Disable the account. Do not delete it. Deleting can take the mailbox and files with it.
  • Remove MFA methods tied to their personal phone, so a recovery route doesn’t survive them.
  • Collect the hardware — laptop, phone, any security keys, and the office alarm code if they had one.
  • Remove building and remote access, including VPN and remote-support tools.

Deleting instead of disabling is the mistake we see most. Disable the account straight away, and only delete it much later, once you’re sure nothing is still needed.

Then deal with the data

Don’t rush this part.

Convert the mailbox to a shared mailbox so colleagues can search it and clients emailing the old address still reach someone. Reassign ownership of their files before anything gets deleted.

This is another reason to disable rather than delete. In Microsoft 365 the retention clock on someone’s OneDrive starts when the account is deleted — 30 days by default — and disabling the account or removing the licence doesn’t start it at all. If you disable the account, you have as long as you need to sort out the files. If you delete it, you have a month.

Check what they personally owned that the business depends on: recurring reports, scheduled tasks, automations, a spreadsheet everyone relies on that lived only in their own drive.

The accounts you’ll forget

Company logins are the easy part. The ones that linger are the ones that were never on a list:

  • Their personal profile on business systems — accounting, CRM, the booking tool
  • Domain name and hosting accounts registered in their own name
  • Social media and Google Business Profile access
  • Anything paid on their personal card and expensed
  • Shared passwords they knew, which now need changing

Check the domain and hosting in particular. If the person leaving registered your domain under their personal email, get it transferred to a business account before they go, not when it comes up for renewal.

Shared passwords

If a departing person knew a shared password, that password is now outside the business, whatever the circumstances of their leaving. It needs changing.

The practical fix is to stop having shared passwords. A password manager with per-person access means offboarding is a single revoke, rather than a scramble to work out what they knew.

Keep a record

Write down what you disabled, what you transferred, and when. It takes five minutes and helps in two ways. If something breaks a fortnight later, you know what changed. And if you’re ever asked to show your process — by an insurer, an auditor, or a client’s security questionnaire — you have an answer.

The same note tells you when it’s safe to finally delete the account and stop paying for the licence.

Do it before you need it

Write this list for your business while nobody is leaving. When offboarding is done in a hurry on someone’s last afternoon, steps get missed, and they tend to be the important ones. It takes an afternoon, and you can reuse it every time.