When someone leaves a small company, removing their building key is only one part of the job. A small business IT access offboarding checklist helps you close digital access across accounts, VPNs, email, SaaS tools, devices, and recovery methods.

Offboarding should follow a defined order. First, confirm the departure time and business authority. Next, preserve anything the business must retain. Then disable access, rotate shared secrets, and verify the changes. A rushed deletion can destroy records, interrupt operations, or leave an old session active.
Start with timing, authority, and an access inventory
Before changing an account, identify who approved the departure and when access should end. Some businesses need access removed immediately. Others plan a handoff at the end of a workday. Record the decision in a ticket or controlled document.
Use the inventory to find every place the person could sign in. Do not rely on memory or a single identity provider. Small companies often accumulate tools over time, including services that no longer appear on an official list.
- Employee name, role, manager, and final access time.
- Primary identity account and alternate login addresses.
- Email, calendar, file storage, and collaboration services.
- VPN, firewall, remote desktop, server, and phone system access.
- Accounting, payroll, customer relationship, marketing, and support platforms.
- Website hosting, domain registrar, DNS, WordPress, and cloud accounts.
- Company computers, phones, tablets, security keys, and access badges.
- Shared passwords, API keys, recovery codes, and service accounts known to the person.
Use the small business IT access offboarding checklist to record the system owner, account type, permission level, and last review date. A network documentation template for small business can help organize infrastructure details alongside the offboarding record.
Disable personal accounts and remote access first
Start with the central identity account when the company uses one. Disabling that account may block access to connected services, but it does not always revoke existing sessions. Review active sessions, remembered browsers, application tokens, and mobile devices.
Then remove direct access from systems that do not depend on central sign-in. Check local administrators, server users, firewall accounts, cloud consoles, and support portals. Remove the person from groups rather than changing only one visible permission.
VPN and server access
A VPN, or virtual private network, creates an encrypted path into a business network. Disable the user’s VPN account, certificate, device profile, or security key. Check firewall rules and remote desktop tools for named access or saved credentials.
For Linux servers, remove authorized keys linked to the departing person. Shared administrator accounts require special care because you may not know who still has the password. Rotate the password and record the new owner. Review SSH key authentication setup for Linux server access when individual keys need better control.
Do not assume a disconnected VPN proves that access has ended. Test from an appropriate account or device, review authentication logs, and confirm that old certificates or tokens no longer work.
Handle email, forwarding, and recovery methods carefully
Email deserves a separate review because it often controls password resets for other services. Disable sign-in at the planned time, revoke sessions, and remove the user from email groups. Preserve mailbox content only according to company policy and legal requirements.
Do not automatically delete a mailbox. Decide whether the business needs an archive, a temporary delegate, an approved shared mailbox, or a forwarding arrangement. If forwarding is required, document the destination, owner, start date, and end date. Avoid forwarding sensitive mail to a personal address.
- Remove mailbox delegates and calendar permissions.
- Delete automatic forwarding rules unless an authorized handoff requires them.
- Check inbox rules that redirect, delete, or hide messages.
- Remove alternate email addresses and recovery phone numbers.
- Replace the departing person’s recovery contact with a controlled business method.
- Review sent mail and shared drafts only when policy permits.
Recovery methods can quietly preserve access after a password change. Confirm that backup email addresses, authenticator devices, passkeys, security keys, and recovery codes belong to the business or an approved current user. If compromise is suspected, follow a separate incident process instead of treating the departure as routine. CISA’s Secure Our World guidance provides practical account security reminders.
For a mailbox handoff or provider change, keep offboarding separate from a full migration. The business email migration checklist covers broader planning for accounts, data, DNS, devices, and testing.
Remove SaaS access and protect business data
SaaS means software delivered through an online service. Examples include project management, accounting, CRM, payroll, design, storage, and customer support platforms. Each service may have its own user list, administrator role, session controls, and billing owner.
Export or transfer business records before deleting the user. Assign ownership of documents, dashboards, automations, forms, calendars, tickets, and customer records. Confirm that the replacement owner can open important files and complete routine tasks.
- Disable the user or suspend the account before deleting it.
- Remove administrator, billing, API, and integration permissions.
- Transfer owned files, workflows, reports, forms, and scheduled jobs.
- Revoke personal access tokens, OAuth grants, and application sessions.
- Remove the user from teams, groups, shared drives, and external workspaces.
- Check connected apps that may have stored the person’s credentials.
- Record retention, export, and deletion decisions.
Pay particular attention to services that use local passwords instead of company sign-in. A password manager may show shared entries, but its audit history may not reveal every place a password was copied. Ask the system owner which secrets require rotation.
Recover devices and rotate shared credentials
Collect company-owned laptops, phones, tablets, security keys, smart cards, and removable drives. Record the device identifier, condition, assigned user, and return date. If a device is missing, treat it as an access and data-protection concern.
Do not wipe a device before confirming that the business has recovered needed files and evidence. Preserve data when a legal hold, investigation, or policy requires it. Otherwise, remove the former user’s local account, enroll the device under a current management system, and apply the company’s standard reset process.
Shared credentials create a common offboarding failure. Rotate passwords for shared mailboxes, Wi-Fi administration, cloud consoles, domain registrars, hosting, phone systems, vendor portals, and physical security systems. Also rotate API keys, webhook secrets, backup codes, and service credentials if the person could view them.
Update the password manager and access documentation after each rotation. Never place new secrets in the offboarding ticket, email, spreadsheet, or chat message. Use the company’s approved secret-sharing method.
Review website, domain, DNS, and phone systems
Small businesses often overlook technical systems because they have no obvious employee directory. Review domain registrar users, hosting accounts, DNS providers, WordPress administrators, analytics platforms, advertising accounts, and deployment tools.
Remove individual access and transfer ownership to a current business account. Rotate credentials that were shared or stored on the returned device. Check application passwords and integration tokens separately from the main login. For WordPress, use revocable credentials for integrations where supported, following the official WordPress application password guidance.
Review the phone system, call queues, voicemail access, mobile apps, and administrator portals. Remove the user from extension groups and administrative roles. Change voicemail PINs or shared portal passwords when the person knew them.
Document the work and verify every important change
A completed task is not the same as a verified task. Create a simple record with the system, action, operator, timestamp, result, and follow-up owner. Avoid recording passwords or recovery codes in that record.
Keep the small business IT access offboarding checklist verification sequence in the same controlled record as the actions. This makes it easier to distinguish completed work from changes that still need human review.
Use this verification sequence after changes:
- Confirm the identity account shows disabled or removed.
- Check active sessions, devices, tokens, and connected applications.
- Test VPN, remote access, server, and administrative paths.
- Confirm email forwarding, delegates, rules, and recovery methods.
- Verify SaaS ownership transfers and access for the replacement owner.
- Confirm shared credentials and exposed keys have been rotated.
- Check returned devices, remote wipe status, and encryption records.
- Review logs for unexpected sign-ins after the access cutoff.
- Ask the manager to confirm business continuity and retained data.
Keep the final record with other operational documentation. Set a review date for temporary forwarding, delegated mail, transferred ownership, and replacement accounts. Temporary access becomes permanent surprisingly easily when nobody owns the follow-up.
Make offboarding repeatable without making it dangerous
Use a role-based template, but keep human review for high-impact systems. Automation can disable a central account or create tasks. It should not blindly delete mailboxes, wipe devices, or remove the only administrator.
Separate urgent access removal from routine cleanup. The first phase blocks sign-in and remote access. The second phase transfers data, rotates secrets, recovers devices, and updates documentation. This separation reduces the chance that an important record disappears during a rushed response.
Review the process after each departure. Add systems that were discovered late, clarify unclear ownership, and remove steps that no longer match the company’s tools. A short, accurate checklist is more useful than a long document nobody follows.
A small business IT access offboarding checklist works best when it has an owner, a deadline, and a verification step for every system. If your business has unclear account ownership, shared administrator passwords, or remote access that is difficult to audit, Tech Rescue Ops LLC can help review the process and build a safer operational plan.
