Access accumulates across more systems than anyone remembers, and it is rarely removed on departure. A written list maintained in advance turns an awkward improvised task into fifteen minutes, and it is the only version that gets done properly under pressure.

Why this goes wrong

Not through negligence. Through the list not existing.

Access was granted over months, by different people, for different reasons. On the day somebody leaves, nobody can reconstruct what they had, so what gets removed is whatever is remembered, which is the email and the obvious ones.

The rest stays open indefinitely, and it is usually discovered years later during an unrelated audit, if at all.

The list, which has to exist first

Maintaining a record of who has access to what is the entire preparation, and it turns the departure into a procedure rather than a memory exercise.

Most small businesses reading that list will identify three or four they had not thought of, which is the point of writing it down before it is needed.

The order on the day

Email first

Because it is the recovery route for everything else. A former employee with mailbox access can reset passwords on systems you already secured.

The sequence matters: change the mailbox password or disable the account before working through the rest, or you are securing things that can be reopened behind you.

Anything financial

Banking, payment systems, invoicing, and anything that can move money or issue credit.

Anything public-facing

Social accounts, the business listing, and the website. These carry reputational exposure rather than financial, and a public post from a business account is difficult to undo.

Everything else

Working down the list, marking each as done.

The shared password problem

The reason offboarding is frequently impossible to do properly.

Where several people use one login, removing access means changing the password, which means telling everyone else the new one, which is disruptive enough that it gets postponed.

The structural fix is named accounts wherever a system supports them, so removing one person affects nobody else. That is a decision to make before the departure rather than during it, and it is the single change that makes this whole process workable.

Where a shared login genuinely cannot be avoided, a password manager with per-person access achieves something similar, since access can be revoked without redistributing anything.

What gets missed

The recovery address one is worth checking specifically, since an account secured today can be recovered tomorrow by whoever controls the recovery route.

Handling the mailbox

Not simply deleting it, which loses history and bounces mail from customers.

The usual approach is to disable the login, keep the mailbox, and forward it to whoever is taking over. That preserves the correspondence, catches customers who still have the old address, and prevents access.

An automatic reply saying who to contact instead is worth setting for a period, since customers will keep writing to a name they know for a long time.

Contractors are the same and worse

A developer, a bookkeeper, a marketing supplier, or a photographer who had access to something.

Worse because the relationship ends informally. There is no last day, just a project that finished, and nobody revokes anything. Access granted for a two-week project is frequently still active four years later.

The practical habit is to remove access when a project ends rather than when the relationship formally does, and to note the date access was granted so it can be reviewed.

The difficult departures

Where the person is unhappy or the exit is abrupt, the same list applies with the sequencing compressed.

Email first, financial second, public-facing third, all on the same day rather than over a week. That is not a statement about the individual, it is standard practice, and having it written down in advance makes it possible to do calmly rather than as a reaction.

It also protects the person leaving, since a documented process removes any suggestion that anything happening on those accounts afterwards was theirs.

The version that works

Write the list now, while nobody is leaving. Add to it whenever access is granted. Use named accounts wherever possible so removal is clean.

Then the departure is a fifteen-minute task with a checklist rather than an anxious afternoon of trying to remember, which is what the inventory in who has access to what is actually for.


Frequently asked questions

Why does removing access go wrong?

Because the list does not exist. Access was granted over months by different people, so on the day someone leaves only the obvious accounts get remembered.

What should be removed first?

Email, because it is the recovery route for everything else. Securing other systems first means a former employee with mailbox access can reset them behind you.

What is usually missed?

Mail forwarding rules, recovery addresses pointing at the person, two-factor registered to their device, administrator status on social pages, and third-party app access they granted.

Should I delete the departing person's mailbox?

No. Disable the login, keep the mailbox, and forward it to whoever is taking over. That preserves correspondence and catches customers still using the old address.

Why are shared passwords a problem here?

Removing access means changing the password and telling everyone else, which is disruptive enough that it gets postponed. Named accounts make removal clean.

Do contractors need the same process?

Yes, and they are more often missed because the relationship ends informally. Access granted for a two-week project is frequently still active years later.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

No idea what a former employee or contractor still has access to?

We build the inventory, move you onto named accounts, and make the next departure a checklist rather than a scramble.

Start a Conversation