When Someone Leaves Your Business, Their Access Should Not Stay Behind

Wednesday, July 22, 2026

Hiring gets a lot of attention. Onboarding processes, orientation checklists, access setup, introductions to the team. Businesses put real effort into bringing someone in the right way.

The day someone leaves? That process is often a handshake and a returned laptop.

Most departures are fine. The person moves on, wishes everyone well, and that's that. But what happens to the accounts? The logins? The platforms they were using? The shared credentials they knew?

For most small businesses, the honest answer is: those things get cleaned up eventually. Sometimes weeks later. Sometimes never.

And that's where the problem starts.

THE ACCESS THAT STAYS BEHIND

When someone leaves a company, they typically walk out with something valuable: working knowledge of your systems. Not because they planned to, but because they used those systems every day.

They know the email login. They know the file-sharing platform. They may have their own credentials to the accounting software, the project management tool, the client portal. They may have had admin access to things that seemed fine at the time.

In most cases, this doesn't lead to anything. The person has moved on and has no interest in your systems. But in some cases, lingering access becomes a problem. And you often don't know about it until it does.

Every account a former employee can still access is a door you have left open. It's not about trust. It's about closing doors you no longer need to leave open.

SUMMER TURNOVER MAKES THIS MORE COMMON

Summer tends to bring more employment changes than other seasons. Seasonal workers finish up. Contract arrangements end. Interns wrap their time. The occasional full-time employee who has been thinking about a change decides this is the summer to make it.

More departures mean more access to clean up. And when the team is thinner because of vacations, offboarding can feel like one more thing that will get handled when things settle down.

The issue is that "when things settle down" can mean weeks of unnecessary access lingering in your systems.

WHAT A GOOD OFFBOARDING PROCESS COVERS

You don't need an elaborate process. You need a consistent one. When someone leaves, run through these:

- Disable or delete their work email account

- Revoke access to all business platforms and software tools

- Remove them from shared password vaults or change shared credentials they had access to

- Reassign any vendor or service accounts they owned

- Check for any personal devices that had business data or apps installed

- Review any admin or elevated permissions they held

The goal is to reach a state where their departure doesn't leave any persistent connection between them and your systems. Not because you assume bad intent, but because that's just clean operational practice.

THE CONTRACTOR AND FREELANCER GAP

Full-time employees are usually visible on the offboarding radar. Contractors and freelancers often aren't.

If you've worked with a freelancer on a project, they may have been given access to a project management tool, a shared drive, or a communication platform. When the project ends, that access often stays active. Nobody thinks to revoke it because technically the relationship isn't ending, it's just pausing.

Except it may not be pausing. And even if it is, temporary access shouldn't be permanent.

A good rule of thumb: if you wouldn't want a random person to have access to it, review whether contractors and former freelancers still do.

SHARED CREDENTIALS ARE THE HARDEST PART

Shared logins are one of the trickiest offboarding challenges. When multiple people use the same credentials for a platform, removing one person's access means changing the password for everyone.

That's inconvenient. And because it's inconvenient, it often doesn't happen. So the former employee effectively still has access because the password hasn't changed.

The better long-term solution is to move away from shared credentials entirely. Individual accounts, where the platform supports it, are easier to manage. When someone leaves, you disable their account. Nobody else is affected.

A password manager helps here too. Credentials stored in a vault can be updated and redistributed to current team members without anyone needing to remember or share a new password manually.

HOW VISIBILITY MAKES THIS MANAGEABLE

The reason offboarding access is hard to manage isn't that people are careless. It's that most businesses don't have a clear picture of who has access to what at any given moment. So when someone leaves, you're doing an audit on the fly, in a hurry, while also managing the workload disruption of the departure itself.

Building a habit of reviewing access before there's a departure makes the process much simpler. A quarterly check of active accounts across your core platforms doesn't take long. And when a departure does happen, you already know what needs to be cleaned up.

Lockwell's digital asset management gives you that visibility. You can see who has access to what, identify accounts that may be unnecessary, and make sure your access list reflects your actual team, not a historical one.

Goodbyes don't have to be complicated. But they do need to be complete. When someone walks out the door, their access should go with them.

It's one of the quietest ways to keep your business secure. And one of the most consistently overlooked.

QUICK CHECK

Think of the last two people who left your business, either permanently or at the end of a contract. Do you know with certainty that their access was fully revoked? If not, that's where to start.