Keep a list of what each person can reach, and work through it the week somebody leaves. Access that is never removed accumulates, and it is a risk that grows quietly for years.

Why this accumulates

Access is granted one account at a time, over years, by different people, for good reasons.

Removing it requires somebody to remember every one of those grants, at a moment when the business is dealing with a departure and probably short-handed.

So the obvious ones are removed and the rest are not, and nothing ever prompts a review.

Five years later a business has former employees and contractors holding live credentials to systems nobody has thought about.

What is usually missed

The sixth is the one with immediate financial consequences and the one least often checked.

A worked example

A small firm that discovered a former employee had been reading the shared enquiries inbox for two years after leaving.

It was not malicious. His phone had the account configured and nobody had told him to remove it, so it kept syncing.

He mentioned it himself, awkwardly, when he ran into the owner and referred to something he should not have known about.

The account had been left because closing it seemed likely to lose the mail history, which nobody had time to sort out.

What made it worse was the audit that followed: three other former people still had access to something, including a contractor with an administrator login to the website from a project in 2016.

None of them had done anything with it. That was luck rather than a system.

The list that prevents this

The only thing that makes offboarding work, and it has to exist before somebody leaves.

For each person: every account they can reach, what level of access, and who granted it.

Update it at the moment access is granted, rather than trying to reconstruct it afterwards, which cannot be done with any accuracy at all.

A spreadsheet is entirely sufficient for this. What matters is that it is complete, current, and that more than one person knows where to find it.

For a business of three people this feels excessive right up until the first departure, when it takes twenty minutes instead of a fortnight of trying to remember.

The order to work through

  1. Email and anything that resets passwords, first.
  2. Financial and payment systems.
  3. The domain, hosting and the website.
  4. Supplier accounts with credit.
  5. Shared storage and documents.
  6. Listings and social profiles.
  7. Physical: keys, fobs, vehicles, equipment.

The first two are worth doing on the day rather than the week, particularly where the departure was not amicable.

The seventh belongs on the same list, because it is the one people always remember, and the digital equivalents are the ones that quietly get forgotten.

Shared accounts and why they complicate this

The structural problem behind most of the difficulty.

Where several people use one login, removing one person means changing the password and telling everybody else, which is disruptive enough to get postponed.

Which is the practical argument for individual accounts wherever a service supports them: removal becomes a single action affecting nobody else.

Where a shared login is unavoidable, storing it in a password manager means it can be changed once and everybody else picks up the new one automatically.

That arrangement turns an awkward task into a routine one, which is what determines whether it actually happens.

The counter-case

Where immediate removal is not the right approach.

A contractor still finishing work, where cutting access mid-project creates a problem rather than solving one. There the answer is a date rather than an exception.

Somebody leaving on good terms whose knowledge you may need for a handover, where a limited period of continued access is reasonable if it is time-boxed and recorded.

And a bookkeeper or accountant who genuinely needs ongoing access, which is a continuing relationship rather than a departure.

The distinction is whether the access has an end date. Indefinite access with no review is the thing to avoid, whoever holds it.

Doing the audit now

Whether or not anybody has left recently.

List every account the business depends on. For each, look at who has access, and check whether every name still works there.

Expect to find at least one surprise. Most businesses do, and it is usually a contractor from an old project rather than a former employee.

Then remove what should not be there, and write down what remains, which becomes the list you did not have.

An hour, once, and it converts a complete unknown into something you can actually maintain going forward.

What to do with their mailbox

The specific problem that causes most accounts to be left running.

Closing somebody's mailbox loses the correspondence in it, which is frequently the only record of ongoing conversations with customers.

So it gets left open, and left open means still accessible from whatever devices had it configured.

The proper sequence: change the password so existing devices stop syncing, set the address to forward to somebody who will handle it, and export the mail history into your own records.

Then close the mailbox once the forwarding period has passed, usually a few months.

That keeps the history, keeps the address working for anybody who writes to it, and removes the access, which is what everybody wanted and nobody knew how to achieve.

Doing it kindly

Worth saying, because this can feel accusatory and does not need to.

Removing access is routine administration rather than a statement about trust, and saying so removes the awkwardness.

Telling somebody in advance that their access will be removed on their last day is normal in any organisation and reads as organised rather than suspicious.

And for a departing contractor, asking them to confirm what they still have access to is frequently the fastest way to complete your list.

Most people are helpful about it, and several will remember an account you had entirely forgotten existed.

The wider record of what those accounts are is covered in who holds the keys to your site.


Frequently asked questions

Why does this accumulate?

Access is granted one account at a time over years, and removing it requires remembering every grant at a moment when the business is short-handed.

What is usually missed?

Shared inboxes, website admin, hosting and registrar, the business listing, cloud storage, supplier accounts with credit, and social profiles.

Which has immediate financial consequences?

Supplier accounts, where somebody can still order in your name on your credit terms. It is also the one least often checked.

What prevents it?

A list of what each person can reach, updated when access is granted rather than reconstructed later, which cannot be done accurately.

What order should I work through?

Email first, then financial systems, then domain and hosting, then supplier accounts, then storage, then listings, then keys and physical items.

When is immediate removal wrong?

A contractor still finishing work, or a handover period. Both are fine if time-boxed and recorded. Indefinite access with no review is the thing to avoid.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Not sure who still has access?

An hour listing every account and who can reach it usually turns up at least one surprise, generally a contractor.

Start a Conversation