Skip to content
BlogAccess control

Employee offboarding: accounts, sessions and integrations to review

Disabling email is one step. Review open sessions, independently authenticated apps and tasks that relied on the departing person.

Test worksheet: Employee offboarding: accounts, sessions and access

Disabling email is one step. Review open sessions, independently authenticated apps and tasks that relied on the departing person. Record inputs, expected outcome, evidence, owner and observed result.

Download CSV worksheet
In this guide

Start with where the person works

At a service company, a coordinator may use email, calendars, an ERP, evidence storage and a routing provider's application. Some tools use corporate sign-in; others have independent accounts. List each owner, access method and offboarding check. Include groups, pending invitations and administrative recovery, without storing passwords in the worksheet.

Microsoft 365 documents access blocking, content retention or transfer and deletion separately. Google Workspace explains that suspension preserves data and some effects depend on the service and session. Follow each product's procedure; changing an email account does not prove immediate revocation in every connected application.

Fictional example: ANA-07 leaves coordination

The business authorizes ANA-07's departure access change at 17:00. There are three known working sessions, a separate routing-portal account and a nightly task using her credential to download orders. This is a synthetic scenario. The intended result is to block her future access, retain authorized documents and keep the task under an appropriate identity and owner.

The nightly task should not retain a personal credential merely because it still works. It also should not be interrupted without notice if operations depend on it. Identify who can change it, which permission it needs and how they will test a controlled run. An offline device remains a recorded dependency: revoking server access does not demonstrate immediate removal of its local copy.

ActionPurposeVerification
Block accessPrevent new authorized sign-insControlled attempt rejected
Revoke sessions or tokensClose existing paths according to the productTest and documented limitations
Transfer documents and tasksContinue work under authorized custodyNew owner completes the task
Delete accountApply the agreed retention decisionOwner checks data and dependencies

Verify both access and continuity

Use authorization, test accounts or a documented administrative procedure for checks. Record time, system, result and limitation. You do not need to inspect private information to establish that an identity is blocked. If an external application cannot be verified, leave it pending with an owner; the number of checked boxes does not determine completion.

CaseExpected resultEvidence
New sign-in after 17:00Corporate access blockedAdministrative event and controlled test
Previously open sessionBehavior confirmed for that providerTime, session and outcome
Routing portal accountIndependent revocation verifiedPortal administrator record
Nightly task credentialNew custody with sufficient bounded permissionsIdentity and rehearsal run
Task retryDownloaded orders not duplicatedBatch reference and count
Offline deviceVisible pending state and recovery procedureOwner and local limitation

Separate the person from shared identities

If someone knew a shared credential, disabling their user does not change that credential. Review secrets or keys other devices could use, then plan rotation with affected dependencies. A legitimate integration must have a business owner even when using a technical identity. Do not distribute a replacement key through the same channel or file the departed person can still access.

Review delegated app permissions, emergency access and recovery methods too. Distinguish personal credentials, delegated authorizations and service identities: each may require different actions. Scope depends on the contract, available administrator and product features; do not promise that a single command revokes every mechanism.

Close with explicit remaining tasks and owners

Retain evidence of verified actions and a list of pending ones. Agree who receives operational email and locates relevant files under the applicable policy. Deleting data is not proof of complete offboarding. Review digital keys, internal roles and permissions and a restore test when continuity depends on one person.

The downloadable worksheet contains no secrets or approved results. Bring an anonymized inventory of applications, dependent tasks and owners to a free consultation for cybersecurity. We can review gaps and ways to verify them without assuming that all access belongs to one provider.

Review access and tasks before offboarding

Identify applications, sessions and tasks that depend on one person. In a free consultation, decide who blocks each access method, transfers the work, and verifies what remains unresolved.

  • Anonymized application and access-method inventory
  • Tasks and documents dependent on a personal identity
  • Owners authorized to block, transfer and verify
Book a free consultationAsk on WhatsApp

Related

Frequently asked questions

Do not assume so. Existing sessions, application tokens and independent accounts may behave differently. Follow product documentation and test relevant access paths. A changed password also does not prove that a local file has disappeared.

Separate access blocking from information retention first. Documents, tasks and administrative recovery may depend on the identity. Deletion should follow the authorized decision and product procedure, considering the applicable retention policy.

Identify its owner, permission and queued work. Transfer or replace the credential through a controlled test before closing the dependency. Test a retry too, so reconnecting does not duplicate work.

Mark it pending with a reason, owner and next action. A third-party-managed application or offline device may need additional evidence. Requesting removal is not the same as verifying revocation.

Sources

  1. Remove a former employeeMicrosoft
  2. Suspend a user temporarilyGoogle

Last updated:

Keep reading

Free consultation

Do you know who can get into your business accounts?

We review your systems, accounts and settings and tell you what to fix first. From $600 MXN per hour. We reply the same business day.

  • Free, no commitment
  • Proposal in 1 business day
  • Delivered in stages