Employee Offboarding: A Practical IT Leaver Checklist for UK SMEs

When a member of staff leaves, small businesses are often focused on the practical handover: clients, projects, equipment and payroll. IT access can become an afterthought, creating real risk.

Blog Main Image

When a member of staff leaves, small businesses are often focused on the practical handover: clients, projects, equipment and payroll. IT access can become an afterthought.

That creates a risk. A former employee may still be signed in on a phone, have access to a cloud application, know a shared password or own files and workflows that the business needs. Even when the departure is completely amicable, leaving access in place is unnecessary and makes it harder to control company information.

For a UK SME, a clear IT leaver process helps reduce the risk of data loss, accidental changes, account misuse and disruption to customers. It also makes the handover more professional for everyone involved.

The Most Common Gaps in an SME Leaver Process

Offboarding problems are rarely caused by one dramatic mistake. They usually come from a checklist that covers the main account but misses the surrounding services.

Common gaps include a Microsoft 365 or Google Workspace account being disabled later than planned, active sessions remaining open on a phone, home computer or browser, access to CRM, accounting, project-management or industry software being overlooked, membership of Teams, SharePoint, shared drives or groups not being reviewed, mailbox forwarding, delegates or automatic rules being left in place, a laptop, phone, security key or access card not being returned, a contractor or temporary worker retaining access after their agreed end date, and shared passwords not being changed when the departing person knew them.

The more cloud services a business uses, the easier it is for one missed account to become a hidden access route.

A Practical IT Offboarding Checklist

The exact order will depend on the circumstances and the person's role. For a planned departure, you may be able to prepare during the notice period. For an immediate departure, access controls should take priority and the process should be handled discreetly by the appropriate people.

1. Confirm the Timeline and Responsibilities

Agree the employee's final working time, who is authorised to approve changes, and who will own the handover. Write this down rather than relying on informal messages.

For higher-risk roles, consider removing privileged access before the person moves to a new role or reaches their final working period. The National Cyber Security Centre advises small organisations to revoke accounts that are no longer required promptly, particularly administrator accounts.

2. Disable the Main Account and End Active Access

Disable the user's main Microsoft 365, Google Workspace or directory account at the agreed time. In Microsoft Entra, administrators can also revoke sessions as part of the process.

This matters because signing out on one laptop does not necessarily end every session elsewhere. Different applications handle tokens and sessions in different ways, so a sensible process should include both account disablement and session revocation where available.

Do not assume this step removes access to every service. Review applications that use separate logins or do not automatically follow your main identity provider.

3. Review Access to Business Systems

Use a simple list of the systems the person could access, including email, Teams, SharePoint, OneDrive and shared mailboxes; CRM, finance, payroll, HR and project-management platforms; remote support, VPN, remote desktop and password-management tools; customer, supplier and industry portals; social media, website, domain and hosting accounts; and backup, security and administrator consoles.

Remove the person's account, group memberships, licences and admin roles where they are no longer needed. If a service needs an owner, transfer ownership to a current member of staff before deleting anything.

4. Protect Files, Mailboxes and Business Continuity

A departing employee may hold important customer correspondence, quotes, documents and calendar information. Before removing or deleting anything, identify what the business needs to retain and who should take responsibility for it.

Set up an appropriate mailbox handover or shared mailbox arrangement, transfer important files, and check that automated workflows do not depend on the leaver's account. Avoid simply sharing everything with a wider audience; only give the replacement owner the access they need.

This is also a good moment to check for unexpected forwarding rules or changes to mailbox permissions, particularly if there has been any concern about account compromise.

5. Recover Devices and Physical Access

Collect laptops, mobiles, tablets, security keys, chargers, access cards and any other business equipment. Record what was returned and what remains outstanding.

If a device is lost, personally owned or still contains company data, use your device-management and security process to protect it. That may include locking it, removing business data or arranging a secure reset, depending on the device and your policies.

6. Change Shared Secrets Where Necessary

Individual accounts should be the default, but many SMEs still have a few shared credentials for older systems, alarms, Wi-Fi, supplier portals or specialist software.

If the departing person knew one of these passwords, change it and record where the new credential is stored. Do not send important passwords through an ordinary email or leave them in a spreadsheet that everyone can open.

7. Keep a Completion Record

A short record should show what was checked, when it was completed and who carried it out. It does not need to be complicated.

Record items such as account disabled and sessions revoked, applications and group access reviewed, files and mailbox ownership transferred, equipment returned or actions taken for missing items, shared passwords changed where required, and outstanding follow-up actions and their owner.

The Information Commissioner's Office recommends documenting leaver processes, checking that access is removed in a timely manner and keeping records to demonstrate that this is happening. A clear record also helps an IT provider support the business quickly if questions arise later.

Make the Process Work for Small Teams

A leaver checklist should be proportionate. A five-person business may not need a large identity-governance platform, but it still needs a reliable process that someone can follow under pressure.

Keep one current list of systems and owners. Use joiner, mover and leaver tasks in your service desk or project tool. Review temporary access and contractor accounts regularly, and schedule end dates wherever the platform allows it.

The aim is not to make employment changes feel technical or hostile. It is to ensure that the business, rather than an individual's account, remains the owner of its data, systems and relationships.

What to Do Next

Choose one recent leaver or contractor as a test case and work through the systems they could access. Note every account, device, shared credential and file ownership issue you find.

Then turn those lessons into a short checklist with named responsibilities and a clear trigger for action. Test it with your IT provider or internal administrator so the process is understood before the next departure.

Managed Technology Group helps UK SMEs put practical access, security and handover processes in place without adding unnecessary complexity. It is part of our approach: Your Technology, Managed the Right Way.

If your current leaver process depends on memory or a few informal messages, a short review can identify the gaps and give your team a calmer, more consistent way to protect access when roles change.

Ready to Work With an IT Company That Actually Gives a Damn?

Book a free IT review and we'll show you exactly where your current setup is costing you money, leaving you exposed, or slowing your team down. No obligation, no hard sell.

IT Review Consultation