Article summaryWhen an employee leaves, the security risk does not end on their last day. Dormant accounts, shared passwords, and cloud access that was never revoked create real exposure that can last months. A digital offboarding checklist turns a scattered, manual process into a repeatable, auditable shutdown of every access point a departing employee held. An employee leaves the company on Friday. By Monday, they should have no access to company systems. Yet in many organisations, accounts remain active long after an employee’s departure. Shared applications are overlooked, permissions stay in place, and dormant accounts quietly accumulate risk. According to the BetterCloud 2025 State of SaaS Report, 33% of organisations reported that an ex-employee was not offboarded within 24 hours of leaving. During that time, access can remain open to systems, data, and business applications. Most businesses have onboarding figured out. Digital offboarding gets treated as an afterthought. The fix is a digital offboarding checklist tied to a defined process with a named owner. Not a note in someone’s head.

Why Digital Offboarding Keeps Getting Missed

It fails for one predictable reason: nobody owns it. HR handles the exit interview. Finance processes the final payslip. IT might disable the email account. Nobody keeps a full list of the SaaS tools, shared logins, and admin roles the person held. These compounds in small businesses where access is granted informally.  Someone is added to a Slack workspace, a shared Google Drive, or a client portal. No ticket was created. No record was kept. When that person leaves, no one knows how to revoke it. The 2021 Colonial Pipeline breach demonstrated the cost at scale.  Attackers entered through a dormant VPN account that had never been deactivated. One forgotten credential was the entry point for a $4.4 million ransom and a multi-day shutdown of fuel supplies across the East Coast of the United States. The Colonial Pipeline attack is often cited as a reminder that dormant accounts can become serious security liabilities.  The 2025 Verizon Data Breach Investigations Report found that 60% of confirmed data breaches involved a human element: errors, privilege misuse, stolen credentials, or social engineering. Former employees with active access fit squarely into that category.

The Digital Offboarding Checklist

Step 1: Disable the primary login immediately

The priority on an employee’s final day is to remove access. Suspend their primary account in Microsoft 365, Google Workspace, or your identity platform as soon as their employment ends. This immediately blocks sign-ins while preserving email, files, forwarding rules, and other data that may still be required for business continuity. Resist the urge to delete the account immediately. Disable access, complete any required audits and data retention steps, and then remove the account according to your organisation’s retention policy.

Step 2: Revoke access to every cloud and SaaS app

Disabling a directory account removes access to core systems, but it does not automatically revoke access to every SaaS application the employee used. Those permissions, sessions, and integrations must be reviewed separately. Work through every app they touched:

  • CRM platforms: Salesforce, HubSpot, Pipedrive
  • Project management: Asana, Monday, Jira, Trello
  • Communication: Slack, Teams, Zoom
  • Cloud storage: Dropbox, Box, Google Drive, OneDrive
  • Finance and billing tools
  • Any client-facing portals or external vendor systems

Check admin roles separately. A former employee who held admin access on a SaaS subscription can still reset passwords and access billing settings even after their standard user access is removed.

Step 3: Handle shared credentials

Teams often share logins for tools that only support a single account: a social media profile, a vendor billing portal, a domain registrar. Anyone with knowledge of those credentials retains access when they leave.  Change every shared password the departing employee had access to. Start moving shared accounts toward individual logins with role-based permissions wherever the service supports it. That shift pays off across every future departure.

Step 4: Recover company data from personal devices

If the employee used a personal device for work, company data may be sitting on it. Email attachments, downloaded files, local copies of documents, Slack history. It all leaves with the device. Mobile device management (MDM) software can remotely wipe work profiles from personal devices at separation. It works cleanly when the device is enrolled in advance. Without enrollment, you have to rely on the employee’s cooperation.   Building MDM into your setup is worth discussing with your IT provider. More on how employee access creates security risks from day one is covered in our post on new staff and security exposure, and how the same principles apply at offboarding.

Step 5: Forward email and reassign accounts

Before disabling an email account, set up forwarding to a manager or a shared internal inbox. Clients and vendors who email a former employee’s address have no way to know that person has left. A bounced message looks unprofessional at best and causes real operational problems at worst. Reassign ownership of any accounts they held: cloud storage folders, shared inboxes, calendar resources, and admin roles on subscriptions. If they were the sole admin on a paid tool, transferring admin access before removal is the critical step.

Step 6: Run an audit and document what was done

After completing the checklist, search for the employee’s name, email address, and username across your key systems. Check for active sessions. Review admin access lists on cloud tools. Confirm nothing was missed. Document each completed step: what was done, by whom, and when. This is your evidence trail if questions arise later. It also makes every subsequent offboarding faster because the process is already mapped.

Build the Checklist Before You Need It

The best time to build an offboarding process is before someone hands in their notice. The worst time is when you’re trying to manage a departure in real time. Departures are sometimes sudden. When there is no checklist, steps get skipped. Set up a simple, assigned procedure before anyone leaves. Specify who owns each step, which systems are covered, and who signs off on completion. Your digital offboarding checklist should cover your actual application stack, not a generic template. A managed IT partner can audit your current SaaS footprint, identify shared credentials that were never documented, and help you build a repeatable offboarding workflow tied to the tools your business actually uses.

Ready to Close the Gaps?

Dormant accounts are one of the most avoidable security risks in any organisation. Once an offboarding process is documented and tested, the priority becomes following it consistently every time an employee leaves. Contact Managed IT Asia to build or review your offboarding process. Call us at +65 6814 0818, reach us online, or email enquiries@managedit.sg.

Article FAQs

What is digital offboarding?

Digital offboarding is the process of revoking a departing employee’s access to all company systems, applications, and data. It covers disabling their primary login, removing access to SaaS tools, updating shared credentials, recovering company data from personal devices, and documenting everything that was completed.

How quickly should access be revoked when an employee leaves?

Access to critical systems should be revoked on the last day of employment or at the moment of termination for involuntary separations.

What is the difference between disabling and deleting an account?

Disabling suspends access immediately without destroying data, email history, or active integrations you may still need to review. Deletion is permanent. The right sequence is to disable first, then audit what the account was connected to, and delete once you have confirmed nothing critical will be lost.

    Name (Required)

    Email (Required)

    Phone

    Are You a Robot?

    Request for a call-back

     

    MANAGED IT ASIA, we are an IT Support, IT Solutioning and Managed IT Service Provider specializing in serving Small Businesses across Asia. Call us at +65 6748 8776 and let us manage your Small Business IT today!