When an Employee Leaves: What to Handle on the Technology Side
Someone is leaving. Maybe they resigned. Maybe the business made the decision. Either way, there's a to-do list that grows fast, and the technology side of it rarely gets the attention it needs in the moment.
In a small firm, a departure can affect client coverage, team workload, and the owner's own capacity all at once. The technology steps get deferred because the owner is focused on the human side first: the conversation, the transition, the rest of the team. That's understandable. But the longer the technology side waits, the harder it becomes to close cleanly. This post covers what should happen, ideally before or on the person's last day.
Two Different Tasks That Look Like One
When someone leaves, there are two separate things happening on the technology side. The first is removing the departing employee's access: their logins, their credentials, their ability to reach business systems. The second is preserving what belongs to the business: email history, client correspondence, project files, shared resources.
These are not the same task, even though they happen at the same time. Most small businesses treat them as one, which is how accounts stay active longer than they should and business information quietly walks out the door.
A short, repeatable process handles both. Remove the person's access. Preserve the business's information. Confirm the change. If you read Part 1 of this series on new hire setup, this is the other half of the same process.
Three Things to Get Right When Someone Leaves
Hand Off the Work
Before anything gets disabled, determine who inherits the departing employee's responsibilities. Client conversations, ongoing projects, shared files, and unfinished work all need a named owner. If nobody claims them before the departure, they tend to fall through the cracks or become inaccessible.
For email, decide how the business will preserve necessary correspondence and who needs access to it. In many cases, a former employee's mailbox can be converted into a shared mailbox: a business mailbox the former employee can no longer sign into, but that a designated manager or successor can access for ongoing correspondence. This keeps the email history available without leaving a live, login-capable account open or paying for an unused license.
If the business takes this approach, assign access to a specific person rather than an undefined group. Set a review date for how long the shared mailbox needs to stay active. Treat client correspondence and any sensitive messages thoughtfully, following the business's own policies. "Indefinitely because nobody revisited it" is not a retention plan.
The common miss here is that nobody decides who inherits the work until after the departure. Client contacts, project history, and communication context leave with the employee because they lived in that person's inbox or personal folders rather than in a shared system.
Close Individual Access
Disable or remove the departing employee's logins and access to every business system and cloud platform they used. Remove them from email distribution lists and shared mailboxes. Change any shared passwords they knew.
A current record of accounts, devices, and role-specific access makes this straightforward. If the business doesn't have one today, use this departure as the starting point for building it. Even a simple list of systems and who has access to each one is better than reconstructing from memory under pressure. (Our onboarding post covers how to build that record from the start.)
The common miss is that accounts stay active with no timeline for when they'll be disabled. Weeks or months later, the former employee may still be able to sign in to email, file storage, or client-facing systems. Nobody intends for that to happen. It happens because nobody owns the step.
Recover, Confirm, and Record
Collect any business-owned devices. Disconnect business accounts and remove business files from personal devices, following the business's established policies for how personal devices are handled.
Then document what was done: what access was revoked, what devices were recovered, what data was transferred, and who now owns the departing employee's responsibilities. Update whatever record the business keeps for accounts and access. The information should live in one reliable place, not in someone's memory or inbox.
The common miss is that nobody updates anything. The laptop goes back in the closet without being wiped or reconfigured. Files stay in a personal folder nobody else can reach. The next time someone asks "does anyone still have access to that system?" there's no reliable answer.
When the Timing Is Short
In a planned departure with notice, the business has days or weeks to work through these steps. The handoff can happen gradually. The technology changes can be completed by the agreed transition date.
In an unplanned departure, the same steps apply, but the window is much shorter. The difference is not the checklist. It's whether the checklist exists before it's needed.
The technology plan for an unplanned departure should already be in place: who is authorized to initiate the technology steps, where the access list is stored, who handles devices, and who inherits the departing employee's work. When that preparation exists, a difficult moment stays manageable. When it doesn't, the owner is making decisions on the fly during one of the most stressful situations in running a business.
Coordinate the timing of technology changes with the people responsible for the employment process. Follow the business's own established procedures. The technology side should be ready to execute as part of that process, not scrambling to figure out what needs to happen after the fact.
A Starting Point
The checklist below is a starting point, not a complete offboarding process. A complete process also defines who is responsible for each step and when it should happen relative to the employee's last day. Every business will need to add items specific to their own tools and workflows.
Continuity
Identify who inherits the departing employee's responsibilities and ongoing work
Decide how to preserve necessary email history and assign access to a specific person
Set a review date for any retained mailboxes or temporary access
Transfer files, client data, and project information to the appropriate person
Access
Disable individual logins for all business systems and cloud platforms
Remove from email distribution lists and shared mailboxes
Change any shared passwords the employee knew
Devices and Records
Collect business-owned devices
Disconnect business accounts and remove business files from personal devices
Sign business accounts out of shared or returned devices and remove saved logins
Document what was revoked, recovered, and transferred
What Comes Next
Departures are never easy. But the technology side doesn't have to add to the stress. A short, repeatable process protects the business without turning a difficult moment into a disorganized one.
Onboarding and offboarding are two sides of the same process. What was set up is what needs to be removed. When both are documented, neither one depends on whoever happens to remember.
If your team would have to reconstruct accounts, devices, and access from memory today, building a simple process before the next transition is a good place to start. We can help.