A gap that’s easy to create and easy to miss
Most small businesses have a reasonably solid process for onboarding a new employee: setting up email, granting access to the tools they’ll need, getting them a login. Offboarding, revoking that same access when someone leaves, gets far less consistent attention, and that gap is one of the more common ways small businesses end up exposed.
Why offboarding gets skipped or delayed
Onboarding happens on a clear schedule, usually a start date everyone knows in advance. Offboarding is often less predictable: a sudden resignation, a layoff, or a departure on bad terms, all of which can mean access revocation happens as an afterthought rather than a planned step, if it happens promptly at all.
What’s actually at risk
A former employee with lingering access can, intentionally or not, still reach company email, shared files, customer data, or financial systems. Even without any bad intent, an old account is simply one more entry point an attacker could compromise, especially if that former employee reused a password that’s since been exposed in an unrelated breach.
A realistic offboarding checklist
| Step | Why it matters |
|---|---|
| Revoke email and file access immediately | Closes the most commonly used entry point first |
| Remove access from shared and third-party tools | Covers the accounts that are easy to forget, like a CRM or a social media login |
| Change any shared passwords they knew | Closes access even if a specific account can’t be individually revoked |
| Collect company devices and check for personal cloud sync | Prevents company data from leaving on a personal account |
| Confirm removal with a documented checklist | Avoids relying on memory for a process that needs to be consistent |
The gap that’s easiest to miss: third-party tools
It’s common for a business to promptly remove someone from email and the main file system while forgetting about accounts in tools that live outside core IT oversight, a social media scheduler, a project management tool, or a vendor portal someone set up individually. These often stay live far longer than anyone realizes, simply because nobody owns the job of tracking every tool a given employee had access to.
Timing matters more than most businesses treat it
The safest approach is revoking access at the same time an employee is notified of their departure, not at the end of the day or the following week. This applies even to departures on good terms. It isn’t a statement about trust, it’s a consistent process applied the same way every time, which is what makes it reliable.
Make it a documented process, not a memory exercise
A written offboarding checklist, reviewed and updated as new tools get adopted, closes this gap far more reliably than trusting whoever handles it to remember every system on their own. This is a small amount of upfront structure that prevents a gap that’s genuinely hard to notice until something goes wrong.
Not sure whether your current offboarding process actually covers everything it should? Reach out and we’ll help you build a checklist that holds up.
