The still-open account of someone who has left the company is the most overlooked and most easily exploited security gap. No ill intent is required; a forgotten access becomes a risk on its own the day it falls into someone else's hands.
Short answer: which access must be closed when someone leaves?
Corporate e-mail and a laptop login are not the whole list: domain and hosting panels, server and database accounts, payment and advertising platforms, social media, cloud storage, third-party service accounts and shared passwords all belong in scope. The right approach is not to remember on the last day but to keep a record of who has access to what from the day they are hired. Offboarding is simply reading that list backwards.
Eight forgotten access points
| Access | Why it is missed | Risk |
|---|---|---|
| Domain and hosting panel | Rarely used; nobody knows who can log in | Full control of site and e-mail |
| Server / SSH and database accounts | Invisible outside the technical team | Data access and a persistent back door |
| Advertising and analytics accounts | Held in marketing; HR is unaware | Budget spending authority, data access |
| Payment and billing panels | Assumed to be "finance only" | Financial data and transaction authority |
| Social media accounts | Linked through a personal account | Direct impact on brand reputation |
| Cloud storage and shared folders | Shares to personal accounts are forgotten | Document leakage, data loss |
| Third-party services | Never inventoried | Access through the chain |
| Shared passwords | Belong to no one, so "cannot" be revoked | Untraceable persistent access |
The last row is the most critical. A shared password belongs to nobody, so nobody revokes it. The offboarding procedure must therefore include rotating it — otherwise access continues even after the account is deleted.
What to do in the first 24 hours
Whether the departure is planned or sudden, the first day's actions are the same, and their order matters:
- Terminate authentication sessions. Changing a password is not enough; active sessions and connected applications must be closed too.
- Do not delete the mailbox — hand it over. Immediate deletion destroys incoming correspondence. Close access and forward the inbox to an authorised colleague.
- Remove administrator rights. Records with "administrator" roles in domain, hosting and advertising panels should be reviewed one by one.
- Rotate shared passwords and issue the new ones only to those who need them.
- Review two-factor authentication records. A recovery phone number or backup codes may still sit with the departing person.
- Cut device access. If company hardware has not been returned, remote access and synchronisation must be stopped.
- Keep a record. Note which access was closed and when; that record serves both audit needs and future departures.
Handover and data ownership
The second overlooked dimension is what happens to the data inside the closed account. Three questions must be answered before departure:
- Which documents exist only in that person's space? Customer files on a personal drive become unreachable when the account closes.
- Where is that person the sole administrator? Single-administrator accounts are the riskiest structure; a second administrator must be added before departure.
- Which address carries customer communication? Correspondence running through a personal address should move to a team address.
These three should be asked at least a week ahead, not on the last day. In sudden departures they are never ready, which is why building corporate e-mail around team addresses is a sound investment from the start.
Offboarding checklist
- Is the access inventory current? Each employee's systems and permissions should be written down.
- Corporate e-mail access closed and forwarding set up.
- User lists in domain, hosting and server panels reviewed.
- Permissions removed from advertising, analytics and social accounts.
- Personal shares in cloud storage revoked.
- Shared passwords rotated.
- API keys and integration access reviewed.
- Company devices returned or remote access cut.
- Data handover completed; no critical document left in one person's space.
- All steps recorded with date and owner.
Netişlem expert view: the problem is not the departure, it is the missing inventory
Most requests reach us after someone has left: "we do not know who has access to this account." The problem is not the moment of departure but that access was never recorded. In small teams this looks natural — everyone has access to everything and nobody lists it. But the first departure turns that structure into real time and risk.
Our second observation is that domain and hosting panels are almost never reviewed. Users added over the years simply remain. Yet those panels carry authority over the entire site and corporate e-mail; they belong at the top of the offboarding list.
Third, the process should not feel like a punishment. Closing access is not a statement of distrust but a standard business procedure. When it is written down and applied identically to everyone, it becomes both easier to run and impossible to take personally.
Frequently asked questions
Should I delete the employee's mailbox immediately?
No. Deletion destroys past correspondence and incoming mail. Close access, forward the inbox to an authorised person, and retain the archive for the required period.
Who owns content the departing employee created?
Under employment contracts and applicable law it generally sits with the employer; but in practice the real problem is technical rather than legal: content left in a personal account becomes unreachable. Work should therefore be produced in corporate accounts by default.
What changes in a sudden departure?
The order changes: access is cut first and handover addressed afterwards. In a planned departure, handover comes first and access closes on the final day. Writing both scenarios down makes decisions easier under pressure.
Is this much procedure necessary in a small team?
The length of the procedure depends on the number of accesses, not the size of the team. Even a team of three managing domain, hosting, e-mail, advertising and social accounts needs the same list — it simply completes faster.
How should I keep the access inventory?
A simple table suffices: system name, who has access, permission level, last review date. What matters is not the sophistication of the tool but keeping the list current and reviewing it quarterly.
Conclusion
For prepared businesses, the security side of a departure is half a day's work; for unprepared ones it becomes weeks of uncertainty. The only thing that makes the difference is having access recorded in advance.
If you would like us to review your corporate access structure, get in touch. You can review our corporate e-mail, secure hosting and server management solutions.