Passwords and access when someone leaves, on the same day
- Aug 29
- 3 min read
Updated: 4 days ago
Introduction
Somebody leaves after four years. Their email is left active in case something important arrives, they still have the shared account details for three systems, their access to the customer database is not removed because nobody remembers it exists, and the social media password is unchanged.
Two years later they still have all of it. Nothing malicious has happened, and the business has no idea what its actual security position is. Access removal is a five-minute task on the day and an archaeological exercise afterwards, and small businesses almost universally postpone it. And having postponed it once, nobody returns to it.
1. Passwords and access when someone leaves should be handled on the day
Not the following week.
Departures are frequently emotional or busy, and access removal is deferred. Making it part of the leaving process, with a checklist, is what ensures it happens at all.
2. Keep a list of what each person has access to
The prerequisite.
You cannot revoke what nobody has recorded. A simple list per role, updated when access is granted, is what makes removal possible and takes moments to maintain. Recording access when it is granted removes the need to reconstruct it later.
3. Stop using shared accounts
The underlying problem.
Where several people use one login, removing an individual's access means changing the password for everybody, which is why it never happens. Individual accounts make this trivial and are worth the administrative effort. They also tell you who did what, which shared logins never can.
4. Deal with email properly
Both access and continuity.
Revoke their access, and forward or delegate the mailbox to somebody who needs it rather than leaving the account live and logged in somewhere. Deleting it immediately loses information; leaving it open is a security gap.
5. Remember the accounts outside your main systems
The ones nobody lists.
Social media, review platforms, the domain registrar, hosting, payment providers, delivery accounts, software subscriptions and anything registered to their personal email. These are where the real exposure sits.
6. Recover devices and check what is on them
Physical as well as digital.
Laptops, phones, keys, access cards and any storage media. Where personal devices were used, agree what happens to the work data on them before their last day rather than afterwards.
7. Change anything they knew
Not just anything they held.
Shared passwords, alarm codes, safe combinations and anything written down. Knowledge does not disappear with access, and changing these is the only way to close it.
8. Check what is registered in their name
A serious continuity risk.
Domains, hosting, software licences, business listings and utility accounts registered to a departing employee's email or personal account. Businesses lose control of their own domain this way with some regularity. A domain registered to a former employee's personal address is a genuine risk.
9. Confirm and record what was done
Both for security and for evidence.
A completed checklist showing each item revoked and when. If something is later accessed inappropriately, this record is what establishes the position, and it also stops the same items being missed repeatedly.
Apply the same discipline to contractors, agencies and anybody else who was given access temporarily. These are granted for a project and rarely reviewed afterwards, and an agency that worked for you three years ago may still be able to reach your systems.
Conclusion
Revoke access on the day, using a checklist rather than memory.
Maintain a list of what each person has access to, replace shared accounts with individual ones so removal is possible, handle email by revoking access while preserving continuity, work through the accounts outside your main systems including social media and the domain registrar, recover devices and agree what happens to work data on personal equipment, change passwords and codes they knew as well as those they held, check what is registered in their name, record what was done, and apply the same process to contractors and agencies.
.png)



Comments