Friday, 5 pm. An employee hands back their badge, there’s a card, a few drinks, good luck with everything. Monday, 9 am, nothing is broken. And yet the question comes, usually from whoever is picking up their work: what exactly did they have access to?
On LinkedIn I told the extreme version of that scene: the “IT guy” who leaves with the passwords. Here I take the time to walk through what happens at every employee departure, even the most ordinary one, and how I make sure that Monday is just another Monday.
IN ONE SENTENCE
Offboarding starts on an employee’s first day: you can only close cleanly the doors you wrote down when you opened them.
A departure isn’t just an email account to switch off
In a company of 10 to 80 people, an employee builds up access over the years. Email, of course. But also shared folders, the accounting software, the CRM, online banking, three supplier portals, the Wi-Fi code, the alarm code, and that account opened “just for now” in their first week, because they needed to get working.
Most of those accesses were opened quickly, by someone in a hurry, and almost never written down. When the person leaves, the mailbox gets disabled and everyone assumes that’s that. What’s left are the accesses nobody remembers.
There are two risks, and they are not the same kind:
- The access that stays open: the former employee, or someone who got hold of their credentials, can still get in. That’s the risk everyone talks about.
- The access the company loses: a file that only existed in their personal space, a subscription paid with their card, a supplier account tied to their address. That’s the risk nobody talks about, and it’s often the more expensive one.
The twelve accesses to close when an employee leaves
This is the offboarding checklist I run through at every departure, grouped into four families. It applies to an employee, an intern, a contractor or a partner who is moving on.
1. Their digital identity
- The main account (Microsoft 365 or Google Workspace): block sign-in, reset the password, revoke open sessions on every device.
- Multi-factor authentication: remove their phone from the approval methods. Otherwise it’s their personal smartphone that keeps approving sign-ins.
- The mailbox: an automatic reply pointing to the new contact, then forwarding to a colleague or conversion to a shared mailbox, for a limited period.
2. Their data
- Their personal cloud space (OneDrive, Google Drive): move whatever the business needs before closing anything.
- Shared folders they created: on Google Drive especially, a folder belongs to whoever created it. Ownership has to be transferred.
- What never got synced: their desktop, the Downloads folder, the USB stick. Anything that was neither on the server nor in the cloud.
3. Their devices and remote access
- Equipment: laptop, phone, monitor, headset, badge, keys. Returned, and checked against the inventory, not against someone’s memory.
- Their personal smartphone: wipe the work side (email, Teams, files) without touching the rest of their phone.
- Remote access: VPN, remote desktop, external access to the NAS. These don’t always depend on the main account.
4. What went beyond the person
- Business and online apps: accounting, CRM, banking, supplier portals, the company’s social media. Each one has its own credentials.
- Shared passwords they knew: Wi-Fi, alarm, a generic info@ address, the password vault. Those get changed.
- Licences and subscriptions: free up their licence, or you’ll keep paying for a ghost, and check no subscription is paid with their card or tied to their address.
IMPORTANT: ORDER MATTERS
Block on the day, recover straight after, delete later. Deleting an account on day one often means deleting their files with it. Never deleting it means a ghost account left open for years, and a licence that keeps landing on the invoice. In between, you need a date, set on the day they leave.
And when the person leaving is the one who held the keys?
The list above assumes one thing: that someone knows where the doors are. When the person leaving is precisely the one who looked after IT, the problem flips. You can’t close what you don’t know exists.
Office all-rounder, long-standing contractor, the tech-savvy nephew, whatever the status. For ten years, they were the one who knew. The server admin password was in their head. The domain name was registered with their personal email. The account that manages the email tenant was theirs. They did nothing wrong: they did their job without anyone asking them to leave the key behind.
This isn’t a security problem. It’s a dependency problem. Security is someone trying to get in. Dependency is you being unable to get in. And it has one unpleasant feature: you only see it once the person has gone, which is too late to ask them.
FOUR QUESTIONS TO ASK TODAY, WHILE THEY’RE STILL HERE
- Who is the administrator of our email, and with which address?
- Which account is our domain name registered to, and who receives the renewal emails?
- Where are the admin passwords for the server, the NAS, the firewall and the Wi-Fi written down?
- If they don’t come back on Monday, who can get in?
If the answer to any of these is “them”, that’s not a fault. It’s a job to do, and it goes far better with them than without them.
The real fix happens on their first day
A clean departure isn’t built on Friday at 5 pm. It’s built on day one, when access is opened. Every account created at onboarding is a line: email, file group, business software, badge, laptop and its serial number. On the day they leave, you don’t invent anything: you read the same list backwards and tick it off.
The second rule fits in one sentence: whatever belongs to the company is in the company’s name. The domain name, the admin accounts, the subscriptions, the documentation. An address like [email protected] rather than someone’s Gmail. That’s what I call digital ownership: you can only take back control of what you own.
FROM THE FIELD
I supported an SME that grew from 40 to 400 users in four years. When it hired its own in-house IT manager, the handover took fifteen days. Not because I was especially brilliant: because everything was already in the company’s name, written down, and they held the keys. The same test applies to me. The day a client stops working with me, they should walk away with everything.
How I handle it as a fractional IT manager
When I take on a company’s IT as a fractional IT manager, in Dublin or in Lyon, the first thing I put in place isn’t the most impressive. It’s the access list: written down, up to date, in the company’s name, and held by the business owner. It’s far more useful on a Monday morning than a nice network diagram.
After that, joiners and leavers go through Foundation, the platform included in the Fractional IT Manager package. The owner or HR lead declares a new joiner from their space. That produces an onboarding sheet: accounts, access, permissions, equipment, licences. On the day they leave, the offboarding sheet takes exactly those lines, and each one is closed, dated, verifiable. No treasure hunt, no “I think they also had access to…”.
And when it’s the “IT guy” who’s leaving, I run the handover while they’re still here. There’s almost never any ill will, just ten years of things nobody ever needed to write down. We write them down together, and put them back in the company’s name.
Frequently asked questions about employee offboarding
How long should you keep a departing employee’s mailbox?
There’s no single period set in law. GDPR principles (transparency, storage limitation) point the same way as good practice: tell the employee, give them the chance to retrieve personal messages before they go, set up an automatic reply that points to the right contact, and don’t keep a named mailbox live indefinitely. In practice, a period of a few weeks to a few months, decided and written down on the day they leave, covers business continuity. After that, you close it.
Should you delete the Microsoft 365 account on their last day?
No. On the day, you block sign-in and revoke sessions. You only delete once files have been recovered and the mailbox has been dealt with. A deleted user is only kept by Microsoft for 30 days before being erased, along with their OneDrive, unless settings say otherwise. Deleting too early means risking the loss of whatever you hadn’t moved yet. The same principle applies to Google Workspace.
What if the former IT person or contractor won’t hand back access?
Start by asking in writing, simply: in the vast majority of cases it isn’t ill will, it’s oversight. If that isn’t enough, most providers (your domain registrar, Microsoft, Google, software vendors) have a recovery procedure based on proof of ownership, typically company registration details from the CRO and an invoice. It takes longer, but it works, and it’s exactly the kind of process a fractional IT manager handles for you.
Where do you start if you’ve never done this exercise?
With the accesses that unlock all the others. In order: email administration (Microsoft 365 or Google Workspace), the account that manages your domain name, then access to your backups. If those three are in the company’s name and known to at least two people, you can take back control of almost everything else. A stolen laptop raises the same question from another angle, which I covered in the article on laptop theft in business.
What does a fractional IT manager change about departures?
They change when it gets done. Without one, a departure is discovered on Monday and sorted out by rummaging. With one, the list exists beforehand, every joiner adds to it, and every leaver closes it. It’s also someone whose job is precisely to make sure your IT belongs to the company, not to a person, including not to them. The package comes with no lock-in, and that’s consistent: you stay because you’re satisfied, not because you don’t have the keys.
Let’s discuss your situation.
30 minutes, no obligation.
Let’s take a look together at what it would take to ease your IT workload. No sales pitch. Just an honest assessment of the situation.
Your IT architect. Your trusted partner.
