When a member of staff leaves, small businesses are often focused on the practical handover: clients, projects, equipment and payroll. IT access can become an afterthought, creating real risk.

When a member of staff leaves, small businesses are often focused on the practical handover: clients, projects, equipment and payroll. IT access can become an afterthought.
That creates a risk. A former employee may still be signed in on a phone, have access to a cloud application, know a shared password or own files and workflows that the business needs. Even when the departure is completely amicable, leaving access in place is unnecessary and makes it harder to control company information.
For a UK SME, a clear IT leaver process helps reduce the risk of data loss, accidental changes, account misuse and disruption to customers. It also makes the handover more professional for everyone involved.
Offboarding problems are rarely caused by one dramatic mistake. They usually come from a checklist that covers the main account but misses the surrounding services.
Common gaps include a Microsoft 365 or Google Workspace account being disabled later than planned, active sessions remaining open on a phone, home computer or browser, access to CRM, accounting, project-management or industry software being overlooked, membership of Teams, SharePoint, shared drives or groups not being reviewed, mailbox forwarding, delegates or automatic rules being left in place, a laptop, phone, security key or access card not being returned, a contractor or temporary worker retaining access after their agreed end date, and shared passwords not being changed when the departing person knew them.
The more cloud services a business uses, the easier it is for one missed account to become a hidden access route.
The exact order will depend on the circumstances and the person's role. For a planned departure, you may be able to prepare during the notice period. For an immediate departure, access controls should take priority and the process should be handled discreetly by the appropriate people.
Agree the employee's final working time, who is authorised to approve changes, and who will own the handover. Write this down rather than relying on informal messages.
For higher-risk roles, consider removing privileged access before the person moves to a new role or reaches their final working period. The National Cyber Security Centre advises small organisations to revoke accounts that are no longer required promptly, particularly administrator accounts.
Disable the user's main Microsoft 365, Google Workspace or directory account at the agreed time. In Microsoft Entra, administrators can also revoke sessions as part of the process.
This matters because signing out on one laptop does not necessarily end every session elsewhere. Different applications handle tokens and sessions in different ways, so a sensible process should include both account disablement and session revocation where available.
Do not assume this step removes access to every service. Review applications that use separate logins or do not automatically follow your main identity provider.
Use a simple list of the systems the person could access, including email, Teams, SharePoint, OneDrive and shared mailboxes; CRM, finance, payroll, HR and project-management platforms; remote support, VPN, remote desktop and password-management tools; customer, supplier and industry portals; social media, website, domain and hosting accounts; and backup, security and administrator consoles.
Remove the person's account, group memberships, licences and admin roles where they are no longer needed. If a service needs an owner, transfer ownership to a current member of staff before deleting anything.
A departing employee may hold important customer correspondence, quotes, documents and calendar information. Before removing or deleting anything, identify what the business needs to retain and who should take responsibility for it.
Set up an appropriate mailbox handover or shared mailbox arrangement, transfer important files, and check that automated workflows do not depend on the leaver's account. Avoid simply sharing everything with a wider audience; only give the replacement owner the access they need.
This is also a good moment to check for unexpected forwarding rules or changes to mailbox permissions, particularly if there has been any concern about account compromise.
Collect laptops, mobiles, tablets, security keys, chargers, access cards and any other business equipment. Record what was returned and what remains outstanding.
If a device is lost, personally owned or still contains company data, use your device-management and security process to protect it. That may include locking it, removing business data or arranging a secure reset, depending on the device and your policies.
Individual accounts should be the default, but many SMEs still have a few shared credentials for older systems, alarms, Wi-Fi, supplier portals or specialist software.
If the departing person knew one of these passwords, change it and record where the new credential is stored. Do not send important passwords through an ordinary email or leave them in a spreadsheet that everyone can open.
A short record should show what was checked, when it was completed and who carried it out. It does not need to be complicated.
Record items such as account disabled and sessions revoked, applications and group access reviewed, files and mailbox ownership transferred, equipment returned or actions taken for missing items, shared passwords changed where required, and outstanding follow-up actions and their owner.
The Information Commissioner's Office recommends documenting leaver processes, checking that access is removed in a timely manner and keeping records to demonstrate that this is happening. A clear record also helps an IT provider support the business quickly if questions arise later.
A leaver checklist should be proportionate. A five-person business may not need a large identity-governance platform, but it still needs a reliable process that someone can follow under pressure.
Keep one current list of systems and owners. Use joiner, mover and leaver tasks in your service desk or project tool. Review temporary access and contractor accounts regularly, and schedule end dates wherever the platform allows it.
The aim is not to make employment changes feel technical or hostile. It is to ensure that the business, rather than an individual's account, remains the owner of its data, systems and relationships.
Choose one recent leaver or contractor as a test case and work through the systems they could access. Note every account, device, shared credential and file ownership issue you find.
Then turn those lessons into a short checklist with named responsibilities and a clear trigger for action. Test it with your IT provider or internal administrator so the process is understood before the next departure.
Managed Technology Group helps UK SMEs put practical access, security and handover processes in place without adding unnecessary complexity. It is part of our approach: Your Technology, Managed the Right Way.
If your current leaver process depends on memory or a few informal messages, a short review can identify the gaps and give your team a calmer, more consistent way to protect access when roles change.
Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.
