The Access Shutdown Checklist for When an Employee Leaves

Homepage News from Us The Access Shutdown Checklist for When an Empl...
The Access Shutdown Checklist for When an Employee Leaves

The still-open account of someone who has left the company is the most overlooked and most easily exploited security gap. No ill intent is required; a forgotten access becomes a risk on its own the day it falls into someone else's hands.

Short answer: which access must be closed when someone leaves?

Corporate e-mail and a laptop login are not the whole list: domain and hosting panels, server and database accounts, payment and advertising platforms, social media, cloud storage, third-party service accounts and shared passwords all belong in scope. The right approach is not to remember on the last day but to keep a record of who has access to what from the day they are hired. Offboarding is simply reading that list backwards.

Eight forgotten access points

AccessWhy it is missedRisk
Domain and hosting panelRarely used; nobody knows who can log inFull control of site and e-mail
Server / SSH and database accountsInvisible outside the technical teamData access and a persistent back door
Advertising and analytics accountsHeld in marketing; HR is unawareBudget spending authority, data access
Payment and billing panelsAssumed to be "finance only"Financial data and transaction authority
Social media accountsLinked through a personal accountDirect impact on brand reputation
Cloud storage and shared foldersShares to personal accounts are forgottenDocument leakage, data loss
Third-party servicesNever inventoriedAccess through the chain
Shared passwordsBelong to no one, so "cannot" be revokedUntraceable persistent access

The last row is the most critical. A shared password belongs to nobody, so nobody revokes it. The offboarding procedure must therefore include rotating it — otherwise access continues even after the account is deleted.

What to do in the first 24 hours

Whether the departure is planned or sudden, the first day's actions are the same, and their order matters:

  1. Terminate authentication sessions. Changing a password is not enough; active sessions and connected applications must be closed too.
  2. Do not delete the mailbox — hand it over. Immediate deletion destroys incoming correspondence. Close access and forward the inbox to an authorised colleague.
  3. Remove administrator rights. Records with "administrator" roles in domain, hosting and advertising panels should be reviewed one by one.
  4. Rotate shared passwords and issue the new ones only to those who need them.
  5. Review two-factor authentication records. A recovery phone number or backup codes may still sit with the departing person.
  6. Cut device access. If company hardware has not been returned, remote access and synchronisation must be stopped.
  7. Keep a record. Note which access was closed and when; that record serves both audit needs and future departures.

Handover and data ownership

The second overlooked dimension is what happens to the data inside the closed account. Three questions must be answered before departure:

  • Which documents exist only in that person's space? Customer files on a personal drive become unreachable when the account closes.
  • Where is that person the sole administrator? Single-administrator accounts are the riskiest structure; a second administrator must be added before departure.
  • Which address carries customer communication? Correspondence running through a personal address should move to a team address.

These three should be asked at least a week ahead, not on the last day. In sudden departures they are never ready, which is why building corporate e-mail around team addresses is a sound investment from the start.

Offboarding checklist

  • Is the access inventory current? Each employee's systems and permissions should be written down.
  • Corporate e-mail access closed and forwarding set up.
  • User lists in domain, hosting and server panels reviewed.
  • Permissions removed from advertising, analytics and social accounts.
  • Personal shares in cloud storage revoked.
  • Shared passwords rotated.
  • API keys and integration access reviewed.
  • Company devices returned or remote access cut.
  • Data handover completed; no critical document left in one person's space.
  • All steps recorded with date and owner.

Netişlem expert view: the problem is not the departure, it is the missing inventory

Most requests reach us after someone has left: "we do not know who has access to this account." The problem is not the moment of departure but that access was never recorded. In small teams this looks natural — everyone has access to everything and nobody lists it. But the first departure turns that structure into real time and risk.

Our second observation is that domain and hosting panels are almost never reviewed. Users added over the years simply remain. Yet those panels carry authority over the entire site and corporate e-mail; they belong at the top of the offboarding list.

Third, the process should not feel like a punishment. Closing access is not a statement of distrust but a standard business procedure. When it is written down and applied identically to everyone, it becomes both easier to run and impossible to take personally.

Frequently asked questions

Should I delete the employee's mailbox immediately?

No. Deletion destroys past correspondence and incoming mail. Close access, forward the inbox to an authorised person, and retain the archive for the required period.

Who owns content the departing employee created?

Under employment contracts and applicable law it generally sits with the employer; but in practice the real problem is technical rather than legal: content left in a personal account becomes unreachable. Work should therefore be produced in corporate accounts by default.

What changes in a sudden departure?

The order changes: access is cut first and handover addressed afterwards. In a planned departure, handover comes first and access closes on the final day. Writing both scenarios down makes decisions easier under pressure.

Is this much procedure necessary in a small team?

The length of the procedure depends on the number of accesses, not the size of the team. Even a team of three managing domain, hosting, e-mail, advertising and social accounts needs the same list — it simply completes faster.

How should I keep the access inventory?

A simple table suffices: system name, who has access, permission level, last review date. What matters is not the sophistication of the tool but keeping the list current and reviewing it quarterly.

Conclusion

For prepared businesses, the security side of a departure is half a day's work; for unprepared ones it becomes weeks of uncertainty. The only thing that makes the difference is having access recorded in advance.

If you would like us to review your corporate access structure, get in touch. You can review our corporate e-mail, secure hosting and server management solutions.