Skip to main content
+968 2284 4777 Head officeTalk to usMyIT Portal

What Happens to a Departing Employee's Access? A Security Checklist

When an employee leaves, the conversation usually focuses on handovers, exit interviews, and final paperwork. Their IT access — email, file systems, software licenses, VPN, company accounts — is just as important, and far more likely to be handled late, incompletely, or not at all.

Why offboarding is a security issue, not just an admin task

An account that still works after someone has left the company is a genuine security exposure — whether the departure was perfectly amicable or not. It’s also one of the most common gaps auditors and cybersecurity reviews flag in small and mid-size businesses, precisely because offboarding tends to be informal: someone remembers to disable email, but the CRM login, the shared drive access, or an old VPN credential quietly stays active for weeks.

A basic offboarding checklist should cover:

  • Email account disabled or access transferred
  • Access removed from all shared drives and internal systems
  • Software licenses reassigned or reclaimed
  • VPN and remote access credentials revoked
  • Company devices and access cards returned
  • Any shared passwords the person knew, rotated

The list itself isn’t the hard part — most IT teams know what needs to happen. The hard part is making sure every item actually gets done, every time, for every departure, without relying on someone’s memory on a busy day.

How a structured process closes the gap

The same logic that works for onboarding works in reverse for offboarding: one structured “Employee Offboarding” request, triggered the moment someone’s departure is confirmed, that generates the complete checklist automatically — access revoked, equipment return scheduled, licenses reclaimed — as one tracked process instead of several scattered reminders.

This is exactly the kind of workflow we build into the Service Catalogue as part of GigaManaged IT: a defined, repeatable offboarding process, set up around your business, so access gets revoked the moment someone leaves — not whenever someone happens to notice it wasn’t.