Offboarding a leaver in under an hour

The riskiest account in most offices belongs to someone who left six months ago. Here is the checklist we run the day a person leaves, and why the hour matters.
Written By
Dev Raman
Note
4 min read

Ask any office how many accounts belong to people who no longer work there and the honest answer is usually “not sure”. Those accounts still have a password, still get email, and are still a way in. Nobody is watching them, which is exactly what makes them useful to someone who should not have them.

What we do on the day

The client tells the helpdesk that someone is leaving and when. At that time, an engineer:

  • Disables sign-in on every account, so the password stops working everywhere at once.
  • Turns the mailbox into a shared mailbox owned by their manager, so nothing sent to it is lost and no licence is wasted.
  • Forwards the calendar and moves their files into the team’s shared drive.
  • Removes them from every group, distribution list and shared login.
  • Signs them out of any device that has not come back yet, and wipes it remotely if it does not come back within the week.
  • Confirms all of that to the manager, in writing, with the time it was done.

The whole list takes under an hour. Most of it is done in the first ten minutes.

Why the hour matters

Because the gap between a person leaving and their access being removed is the window in which things go missing, whether by accident or not. A same-day process closes it. A “we will get to it” process leaves it open for as long as nobody remembers.

The other half

Starters get the reverse: laptop, accounts, groups and access ready before their first morning. It is the same checklist run forwards, and it is included on the Complete and Secure plans.