When a Staff Member Leaves, Close Their Digital Doors
A departing employee can leave more than an empty shift on the schedule. Use a calm, repeatable account handoff to protect customer information, keep business tools accessible, and avoid locking the owner out of the shop's own accounts.
When a team member leaves, the obvious jobs come first: cover the shift, collect keys, and tell customers who will help them next. Digital access is easier to overlook. A former worker may still be signed in to a shared inbox, scheduling app, point-of-sale dashboard, or social account. Meanwhile, the business owner may discover that the departing employee was the only person who knew the password.
A short offboarding routine can prevent both problems. It does not need to feel like an investigation or a complicated IT project. The goal is simply to remove access that is no longer needed, preserve business records, and make sure the people still working can get on with their jobs.
Start with a list of doors, not a hunt for passwords
Keep a basic inventory of the digital tools your business uses and who administers each one. Include email, payroll, scheduling, customer records, payment tools, file storage, website hosting, social media, online listings, and any remote-access service. For each tool, note the business owner or administrator, the work purpose, and whether a person has an individual account or shares access.
This list is useful before anyone leaves. It turns a stressful last-minute memory test into a routine update. It also helps answer a practical question: if the person who normally handles a tool is unavailable, who can still reach it?
Do not put passwords in the inventory. Use a reputable password manager or the service's own access controls, and make sure at least one authorized business owner can manage the account. If a tool has only one administrator, add a second trusted administrator before there is a departure to handle.
Remove access, but keep the work
On the person's last day, or at another planned time that fits the circumstances, disable their individual accounts in business systems. Check email, shared files, customer-service platforms, staff scheduling, point of sale, social media, website tools, and any app used to access the business network. If the person used a company phone or laptop, sign out of work accounts and arrange for the device to be returned or wiped under your normal process.
Then look for access that does not appear under the employee's name. A shared password, an old recovery email, or a login saved on a tablet can remain usable after an individual account is closed. Change shared credentials when appropriate, update recovery details, and review active sessions or connected devices if the service provides those controls. Do not assume that removing one user from a staff list closes every route into an account.
For higher-risk systems, ask the service provider or a qualified IT professional to help. That is especially sensible when the departing person had administrator privileges, access to financial systems, or remote access to office devices. A small business does not need a dramatic security operation for every departure, but it should know when a routine account change is not enough.
Keep customer communication from disappearing
Closing an account should not erase useful business correspondence. Before disabling access, identify business records that need to stay with the company, such as open customer requests, order details, project files, or vendor contacts. Move or assign those records through the service's normal business controls. Avoid forwarding an employee's entire mailbox to another person by default; it can expose personal material and send far more information than the business needs.
Instead, make a narrow handoff. Assign open conversations to a shared team inbox, set an appropriate out-of-office message, or arrange a limited forwarding period for business requests if company policy and local rules allow it. Tell customers who will take over and give them a working contact route. A quiet change in account access should not turn into a customer wondering why nobody has answered their invoice question for a week.
Keep only records the business has a legitimate reason to retain, and follow the retention rules that apply to your industry and location. If you are unsure about employment, privacy, or recordkeeping obligations, check with an appropriate professional rather than improvising a policy in the middle of a busy day.
Use a handoff checklist that fits your shop
A simple checklist can live beside the equipment-return form or in the owner's operations folder. Keep it short enough that someone will actually use it:
- Confirm the final work date and the person responsible for the handoff.
- Review the tool inventory and identify accounts the worker could access.
- Transfer active customer or business work to an authorized colleague.
- Disable individual accounts and remove access from shared tools.
- Update shared passwords, recovery contacts, and administrator access where needed.
- Collect company devices and check for saved work sessions.
- Test that the remaining staff can sign in and reach the tools they need.
- Record what changed and who completed the checks.
The sequence can vary. For an involuntary departure or a role with broad system access, access changes may need to happen at the time of the separation rather than after a leisurely handoff. Plan that process with the right manager or IT support. For a friendly, planned departure, a transition period can make it easier to transfer customer work before access is removed.
Do a quick check after the last day
Once access changes are made, ask a current employee to test the important tools using their own account. Can they answer customer email? Can the manager update a product listing? Can the owner reach payroll and the business's social pages? This catches the awkward cases, such as a recovery code that went to a former worker's phone or an account that was registered with a personal email address.
Also check for new sign-in alerts or unexpected account changes during the transition. That does not mean you should monitor former employees' personal activity. Keep the review focused on company systems and follow the rules that apply to your business. If you see an unfamiliar sign-in or cannot regain control of a business account, contact the service provider promptly and preserve relevant business records.
The CISA guide to employee separations covers risk assessment, information-technology access, and post-separation checks. Its recommendations are written for a broad range of organizations, so a small shop can scale the steps to its own tools and risks rather than copy a large-company process word for word.
Make the next departure easier
After the handoff, spend ten minutes improving the inventory. Was there a tool nobody remembered? Did one person control a page the owner thought belonged to the company? Add the answer to the list, assign a backup administrator, or change the account setup so the business owns the login.
Good offboarding is mostly ordinary housekeeping done at the right time. Keep business accounts under business control, close access when a role ends, preserve only the work the team needs, and confirm that someone still has the keys. Then the next staff change can stay a people-and-schedule task, not a scramble to find the password to everything.