The employee offboarding checklist for digital accounts
Most offboarding checklists cover the laptop, the badge, and the email account — and stop. But in a small business, a person's digital footprint is wider and stranger than their HR file: they're the backup admin on the domain, the recovery phone for Instagram, the cardholder behind three renewals, and the outright owner of a tool they signed up for in a hurry two years ago.
Offboarding fails because that footprint is invisible at departure time. Here's the checklist that catches it — organised by the five ways a person can be entangled with an account.
The five kinds of dependency
- Member — they have a login on a company-owned account. Easy: remove the user.
- Admin — they hold elevated rights (page admin, super admin, account owner's deputy). Reassign before removal so you don't orphan the asset.
- Owner — the account is theirs: their email is the login, they created it. Hardest case; needs a transfer, not a removal.
- Recovery path — their personal phone or inbox is the 2FA device or recovery contact, even on accounts they never used. Invisible until a reset fails.
- Billing — their card quietly renews something. Invisible until the card expires and the service lapses.
Before their last day (the transfer window)
- 1Pull their footprintFrom your register — or, failing that, one hour with them and this list: what do you own, admin, recover, or pay for?
- 2Transfer any accounts they own outrightOwnership transfers need the departing person's cooperation, which is cheapest while they're still an employee. Per-platform guides: Google Workspace, Microsoft 365, Shopify, Stripe, Mailchimp, Instagram — see below.
- 3Reassign their admin rolesEvery role they hold gains a second holder from the remaining team before departure day.
- 4Move recovery contacts and 2FARe-point recovery emails/phones to company-controlled ones; re-enrol 2FA on a device that stays.
- 5Replace their card on fileAnything renewing on their personal card moves to a company card now — renewals fail silently months later otherwise.
Departure day
- 1Suspend identity firstEmail / SSO account suspended — this alone closes every properly-SSO'd tool.
- 2Remove direct loginsWork down the footprint list: every non-SSO tool where they're a member or admin.
- 3Rotate shared secretsAny password that lived in a shared vault or spreadsheet they could see — rotate, don't debate whether they'd use it.
- 4Revoke tokens and keysAPI keys, OAuth grants, and integrations they created keep working after their user is gone — kill or re-issue them.
- 5Check the socials explicitlyPage access, Instagram credentials, LinkedIn page admins — social platforms are the most common stragglers.
The 30-day sweep
Some dependencies only surface on a delay: a renewal notice bouncing to their dead inbox, a billing failure on their removed card, a vendor emailing them instead of you. Thirty days after departure, re-check the register, the monitoring alerts, and any invoice or notice that went unanswered. Then close the loop: mark the person as departed in your records so the next audit doesn't rediscover them.
The free scan maps your domain, email, cloud, social and tools from public records — and shows what you'd lose access to tomorrow. No login, nothing to install.
Check my business