An employee gives notice, works out three weeks, leaves on good terms, and the email account is disabled that afternoon. Everybody involved considers the matter closed. Eighteen months later a supplier portal is still accessible with credentials that person knows, a shared account for the scheduling software has never had its password changed, and a phone in a drawer still has the company files on it. None of that requires bad intent to become a problem, and all of it is straightforward to prevent with a list written before it is needed.
The Accounts You Own and the Ones You Only Use
The accounts a business controls directly are the easy half. Email, the file storage, the accounting software, the project system: these are administered centrally, they can be disabled in minutes, and the person doing it can see a list of who has access. The discipline here is only to disable rather than delete, at least initially, because deleting a mailbox destroys correspondence that may be needed and is difficult to recover once the retention period lapses.
The harder half is everything the business uses without owning. Supplier ordering portals, a trade account with a merchant, the manufacturer’s warranty registration site, the parts distributor, the county permit system. Each of those was set up by whoever needed it first, frequently under a personal email address, and there is no central list of them anywhere. Building that list is a task for a quiet week rather than for the day somebody resigns.
Shared Credentials, Which Are the Real Problem
Almost every small business runs on shared logins, because per-user seats cost money and because it was simpler. The consequence is that a departure does not remove access from anyone; it requires a password change, and a password change breaks the login for everybody else still using it, on a day when the business has other things to do. That friction is why the change gets postponed, and then postponed again, and the credential a former employee happens to know stays valid for years afterward without anybody deciding that it should.
The remedy is structural rather than procedural. A shared password manager, with a vault the business rather than an individual controls, converts every shared credential into something that can be rotated centrally and withdrawn from one person without disrupting anyone else. It is the single highest-value change a small business can make in this area, it costs a modest amount per user, and it turns an offboarding task nobody wants to face into one that takes a few minutes on the afternoon it is needed.
Devices, and the Data That Lives on Them
Physical items come back and their contents frequently do not. A returned laptop should be checked before it is reissued, since local files, saved browser passwords and cached sessions all survive a change of user. A phone that belonged to the business should be wiped rather than simply collected. A personal phone that was used for work is a different question entirely, and one that should have been settled by a written policy long before the resignation.
The items easiest to forget are the ones that never looked like technology. Keys and access fobs. A vehicle tracker login. A code for the yard gate or the alarm, which cannot be individually revoked and therefore has to be changed for everyone. Guidance the Federal Trade Commission publishes for small businesses makes the same point in a broader context, which is that an inventory of what exists has to precede any attempt to secure it, and almost no small business has one until something prompts it.
The Access That Is Not a Login
A final category has no password attached and is missed almost universally. Email forwarding rules set up by the departing person, which can quietly copy correspondence onward after the account is closed. Authority on a bank account or a card, which requires a call to the bank rather than a click. A named contact on a supplier account who can still place orders by telephone because the supplier recognizes the voice. Domain and hosting control, which is occasionally registered to an individual rather than to the business.
Each of these persists because it exists in somebody else’s system rather than in one the business administers. Working through them means contacting the third party, confirming who is currently authorized, and putting the change in writing, which is a morning of phone calls rather than an afternoon of clicking. It is also the part of offboarding with the largest consequences, since an order placed on a trade account by a former employee is a debt the business owes.
Timing the technical steps against the human ones is the part that requires judgment. For an ordinary resignation on good terms, disabling access on the final afternoon is proportionate and nobody is offended by it. For a departure that is contested, or where the person had access to customer lists, pricing or financial systems, access should end at the moment the conversation does, which means preparing the list beforehand rather than working it out afterward. Getting that sequencing wrong in either direction is costly: too early looks like an accusation, and too late is how data leaves.
Doing It on the Day Rather Than the Week After
The practical answer to all of this is a written checklist, built once from the accounts the business actually uses, kept somewhere it will be found, and worked through on the last day rather than when somebody remembers. It should include who to call as well as what to click, and it should end with a note of the date each item was done. Departures on good terms are the overwhelming majority, which is exactly why the process has to be routine rather than a reaction, since the version that only gets followed when somebody leaves badly is the version that is never practiced.



