The "Digital Offboarding" Checklist: Securing Business Data When an Employee Leaves

Article summary: When an employee leaves, most businesses collect a laptop and a badge while the digital footprint stays active. A documented employee offboarding checklist closes every account, login, and integration they touched. Doing this in the first hours after departure is one of the cheapest security upgrades a small business can make. 

An employee’s last day has arrived. They return their company laptop, say goodbye to the team, and walk out the door. From an HR perspective, the departure may be complete.

From a security perspective, the work is just beginning.

The former employee may still have access to email, shared files, business applications, or accounts no one remembers approving. If those connections remain active, they can create security risks long after the employee leaves.

A complete offboarding process closes every point of access, not just the ones that are easy to see.

Why Offboarding Is a Security Event, Not an HR Formality

Many businesses approach offboarding primarily as an HR process: issuing the final paycheck, updating benefits, and conducting an exit interview. Removing access is often treated as a separate IT task rather than a critical part of the employee’s departure.

That gap may be larger than many business owners realize.

In a Beyond Identity survey, 83% of respondents said they continued accessing at least one account from a previous employer after leaving, while nearly one in four admitted to intentionally keeping a workplace password.

Those findings highlight why access removal cannot wait until IT gets around to it. Every account, application, and credential should be identified and addressed as part of the employee’s departure.

Most former employees may never use that access maliciously. But that is not the only risk.

An active account that no one is monitoring can also provide an attacker with a legitimate path into the business. Because the login uses valid credentials, the activity may appear normal and be harder to detect.

The Digital Offboarding Checklist

A complete employee offboarding checklist should address four key areas. Overlooking any one of them can leave unnecessary access in place.

Identity and email

Disable the departing employee’s primary account first, ideally through your identity provider (Microsoft Entra ID, Google Workspace, or similar) so the change cascades across every connected app at once.

Force sign-out on all active sessions. Disabling a password doesn’t automatically end a session that’s already open on a phone or home computer.

Decide how the former employee’s email will be handled, whether that means forwarding messages to a manager, converting the account to a shared mailbox, or setting up an automatic reply. Whatever approach you choose, disable the former employee’s ability to sign in.

Shared accounts and passwords

Change the password for any account the departing employee accessed through shared credentials. This may include social media accounts, accounting software, shared email inboxes, or other business applications without individual user logins.

Review where those credentials are stored as well. If shared passwords are kept in spreadsheets, documents, or other informal locations, it may be difficult to know who still has access. A business password manager provides better control over how credentials are stored, shared, and updated.

Devices and physical access

Collect laptops, phones, and any security keys or tokens. Deactivate keycards, change alarm codes if they were shared, and remove the person from any physical access lists.

Wipe or reimage returned devices before assigning them to another employee. Local files, saved passwords, and cached login credentials may remain on the device after the employee leaves.

Third-party apps and integrations

Third-party applications are easy to overlook during offboarding. Over time, employees may connect business accounts to outside tools using options such as “Sign in with Google” or “Connect to Microsoft 365.” Some of those authorizations may remain active until they are specifically reviewed or revoked.

As part of the offboarding process, review the applications connected to the employee’s account and remove any access that is no longer needed. Our guide to auditing and revoking third-party app access explains how to identify these connections and determine which ones should be removed.

Where the Gaps Usually Hide

The employee’s primary account is usually disabled. The less obvious connections are where gaps remain.

That may include a salesperson’s personal Dropbox account containing company proposal templates, an AI writing tool paid for by the business but tied to a personal login, or a contractor’s remote access tool that was never connected to the company’s identity system.

According to IBM’s 2025 Cost of a Data Breach Report, breaches involving compromised credentials took an average of 186 days to identify and another 60 days to contain.

Because attackers are using valid login information, their activity may initially appear legitimate, making unauthorized access more difficult to detect.

Federal guidance treats employee separation as a coordination issue as much as a technical one. CISA recommends promptly revoking physical and system access when an employee leaves.

Access removal should be part of the departure process, not a task left for days later.

Building a Process You’ll Actually Follow

A successful offboarding process requires clear ownership and consistent follow-through. A few practical steps can help make that happen:

  • Establish a process for notifying IT as soon as an employee’s departure date is confirmed.

  • Keep an up-to-date record of the systems, applications, and shared accounts each employee can access.

  • Make access removal a core part of the departure process, not a task completed days later.

  • Document which accounts and permissions were removed, when the changes were made, and who completed them.

NIST personnel security guidance emphasizes the importance of a defined termination process, including clear responsibilities and established timeframes for disabling system access.

Ready to Close the Gap on Employee Departures?

Effective employee offboarding does not have to be complicated. It requires a complete, repeatable process that removes access consistently every time someone leaves.

If you are not sure whether every account, shared login, and connected application is included in your current process, BrainStomp can help. We can identify gaps, document your full technology environment, and build an offboarding process that covers everything from email and user accounts to overlooked third-party applications.

To get started, reach out at brainstomp.com/contact or call 260-918-3548.

Article FAQs

What should be included in an employee offboarding checklist?

A complete checklist should include disabling the employee’s primary account, ending active sessions, removing access to business applications, changing shared passwords, collecting company devices and physical access items, and reviewing third-party applications connected to company accounts.

How quickly should access be removed after an employee leaves?

Access should be removed as close to the employee’s departure as possible. For planned departures, IT should coordinate with HR and management so accounts are disabled at the appropriate time. Delays can leave unused accounts available to former employees or attackers.

Why is third-party application access often missed during offboarding?

Employees can connect third-party applications to business accounts with only a few clicks, often without a formal approval or tracking process. Regular audits can help identify these connections so unnecessary access can be removed when an employee leaves.