Most small businesses have former staff with live access to something. Usually nobody has checked, and usually nothing happens, and occasionally something does.
TL;DR Maintain an access register per role. Revoke everything the same day, not the same week. Rotate any shared credential the person knew. Recover assets against a checklist and record what came back.
The access register
You cannot revoke what you have not recorded.
Build a register listing every system, per role
| System | Who has it | Revocation method |
|---|---|---|
| All | Admin console | |
| Field service app | Field, office | Admin console |
| Accounting | Office, owner | Admin console |
| Payment processor | Office, owner | Admin console |
| Google Business Profile | Marketing, owner | Often forgotten |
| Social accounts | Marketing, owner | Often forgotten |
| Domain registrar | Owner | Frequently a single point of failure |
| Password manager | All | Vault removal, then rotation |
| Supplier trade accounts | Field, office | Phone the supplier |
| Vehicle tracking | Managers | Admin console |
| Building alarm and key safe | Varies | Physical, needs recoding |
| Customer site keys | Field | Physical recovery |
The bottom half of that list is where the gaps are. Software access gets revoked because it is visible in an admin panel. Supplier accounts, alarm codes and physical keys do not appear anywhere and are routinely missed.
Audit the register twice a year against reality. Access accumulates.
Same-day revocation
The window between notice and revocation is the risk.
For a normal resignation: revoke on the final day, at the end of it.
For a dismissal or an acrimonious exit: revoke before or during the conversation. This is not paranoia, it is standard practice, and it protects both parties from an accusation later.
Sequence
- Disable, do not delete. Deletion loses records you may need.
- Forward email to a manager for a defined period.
- Reassign owned records: customers, open jobs, open conversations.
- Remove from all shared systems.
- Rotate shared credentials.
- Recover physical assets.
- Recode physical access.
- Confirm each step, with a date and a name against it.
Automate the trigger. Marking somebody as leaving in your HR or payroll system should generate the full checklist as tasks, with owners and due dates.
Rotate what they knew
Revoking an individual account is not enough if there were shared credentials.
Rotate
- Any shared account password, always.
- The Wi-Fi key, if it was shared.
- Alarm codes and key safe codes.
- Supplier account passwords.
- Any API key they had access to.
- Shared social account passwords, and remove them as an admin.
Shared credentials are the underlying problem here. Every rotation is disruptive precisely because the account is shared.
The better long-term fix: individual accounts everywhere, a password manager for anything genuinely shared, and no credential passed around in a message. Then offboarding is a removal, not a rotation.
Asset recovery
A checklist, signed by both sides.
Typical list
- Phone and charger.
- Tablet or laptop.
- Van and all keys.
- Tools, itemised against what was issued.
- Test equipment, with serial numbers.
- Uniform and PPE.
- Customer site keys and fobs.
- Fuel card.
- Building keys and access cards.
- Any physical files or documents.
Record condition and serial numbers. For test equipment particularly, because calibration records attach to serial numbers.
Sign it, both parties, and give them a copy. This protects them as much as you, and it prevents the disagreement three months later about whether a tool came back.
Deductions from final pay for unreturned items are regulated in most jurisdictions and often require prior written agreement. Check before assuming you can.
Data on personal devices
The awkward one, and increasingly common.
If staff used personal phones for work
- Customer contacts saved in the phone.
- Work email in a personal mail app.
- Work messaging apps with customer conversations.
- Photos of jobs and sites.
Ask for confirmation of deletion, in writing. That is usually as far as you can reasonably go without a prior policy.
The fix is upstream. A bring-your-own-device policy signed at onboarding, stating what may be stored and what happens at exit, and preferably containerised work apps that can be remotely removed.
If you have no policy, write one now and apply it to new starters. Retrofitting it to existing staff requires a conversation and probably consent.
Customer notification
For customer-facing staff, tell the customers.
Just to let you know, Dave has moved on. Sarah will be looking after you from now on. Her number is below, and she has your full history so nothing is lost.
Why it matters
- Prevents customers ringing a number that no longer reaches you.
- Prevents a departing employee taking accounts by default.
- Reassures customers that continuity is handled.
Do it promptly and neutrally. No commentary on why they left.
If they have gone to a competitor, check your contracts on solicitation. Enforceability of non-solicitation clauses varies enormously by jurisdiction and many are unenforceable as drafted. Take advice before acting on one.
The exit conversation
Separate from the security process, and worth doing.
- What worked and what did not.
- Why they are leaving, actually.
- What would have kept them.
- Any knowledge only they hold, captured before the last day.
The last point is operational, not sentimental. Every departure is a knowledge loss and the fortnight before the last day is your only chance to record it.
Measure it
- Time from last day to full revocation. Should be zero days.
- Checklist completion rate. Every item, every time.
- Access audit findings. Former staff with live access should be zero, and audit for it twice a year.
- Asset recovery rate.
- Knowledge capture completed before the last day.
Build the access register this week, listing every system and who has it. Most owners find at least one former employee still holding access to something, and that discovery alone justifies the hour.
Need a pro to build it? [BOOK A CALL]
