Your co-founder is leaving. The digital separation checklist.
An employee's departure is a checklist. A co-founder's departure is that checklist with the stakes inverted: founders don't just have access, they have *root*. They registered the domain in 2019, their personal Gmail is the cloud root account, their phone is the 2FA for the payment platform, and half the company's recovery paths quietly terminate at inboxes they'll keep forever.
Whether the split is warm or hostile, the digital separation deserves the same rigour as the equity conversation — and it's far cheaper to run while things are still cordial. Here's the checklist, in order of stakes.
The root layer (do these first)
- 1Domain & registrarIs the departing founder the registrant, or the registrar-account holder? Transfer to a company-controlled account before anything else — every other recovery path assumes you control the domain.
- 2Cloud root accountAWS/GCP/Azure root credentials created on a personal email are the classic founder time bomb. Re-point the root email to a company mailbox, rotate credentials, re-enrol MFA on a device that stays.
- 3Google Workspace / Microsoft 365Make sure super admin / global admin doesn't leave with them — add a second admin from the remaining team, then remove theirs (guides linked below).
- 4Payments & payoutsStripe/PayPal account ownership, and the bank the payouts land in. If they're the platform account owner, run the transfer while they're cooperative — support-mediated recovery later is slow.
- 5Code & infrastructureGitHub org ownership, DNS (Cloudflare super admin), deploy keys, package registries, app-store accounts. Developer-founders usually hold all of these personally.
The invisible layer: recovery paths
Even after every role is reassigned, ask the quieter question: where do the *recovery* flows go? Password resets, backup codes, recovery phones, billing receipts — if any of them point at the departing founder's personal email or number, that person can re-enter (or accidentally lock you out) long after the handshake. Walk every root account's security settings and re-point recovery to company-controlled contacts.
The same applies in reverse: help them cleanly extract their personal life from company systems — their personal Gmail shouldn't stay tangled in your infrastructure any more than your assets should stay in theirs. Clean separation protects both sides.
Put it in the paperwork
Treat digital assets the way an acquisition treats them (our due-diligence guide applies almost verbatim): schedule the accounts in the separation agreement, name the transfer mechanism and deadline for each, and verify each transfer happened — sign in, check the role — before the agreement closes. "We'll sort out the logins" is the digital equivalent of an unsigned cap table.
If it's already hostile
- Prioritise by blast radius: domain, then cloud root, then payments — in a dispute, control of these is leverage.
- Use each platform's official recovery/transfer processes (linked throughout this blog) rather than improvised workarounds; they create a paper trail.
- Document everything: what they hold, what you've requested, when. It shortens both the legal conversation and any support-ticket queue.
- Don't retaliate by locking them out of genuinely personal assets — it muddies your own claims to the company ones.
The free scan maps your domain, email, cloud, social and tools from public records — and shows what you'd lose access to tomorrow. No login, nothing to install.
Check my business