Employee offboarding is often treated as paperwork: collect a laptop, turn off an email address, and wish someone well. For a small business, it is also a security deadline. A departing employee may still have access to cloud apps, a shared inbox, saved browser sessions, a password vault, a company phone, recovery email addresses, or a vendor portal that nobody remembered to list.
The risk is not limited to a hostile departure. Most lingering access is accidental. A former employee can keep receiving notifications, a shared account can retain their phone number for recovery, or an automation can continue running under an account that no one is monitoring. Those loose ends create opportunities for account takeover, data exposure, and confusion at exactly the moment a team is changing.
Key Takeaway: A good offboarding process removes access at the source, checks the recovery paths around it, and transfers the work the account performed. Disable first, preserve business records, then verify that no old session or shared credential still provides a way back in.
Why SaaS offboarding is harder than disabling email
Email is only one identity. Most businesses now run on dozens of web services, many of which were adopted one team at a time. A departing sales manager may have access to the CRM, proposal tool, e-signature service, expense platform, calendar, shared drives, customer-support portal, and a supplier website. A marketing contractor may be an administrator in a social account or domain registrar. An operations employee may be the only person receiving security alerts from a payment processor.
Turning off the primary email account can help, but it does not automatically end every session or remove every role. Some services allow a user to sign in with a personal address, an existing browser cookie, a mobile device, a shared password, or a recovery phone number. Others keep API tokens and automated connections working after the original employee has left.
The goal is not to create a perfect inventory overnight. It is to make offboarding a repeatable control with a short, accountable checklist. Every departure should improve the list.
Start before the last day
The best time to prepare is as soon as the departure is confirmed. HR, the manager, and whoever administers technology should agree on the exact time access changes. For routine departures, that may be the end of the final workday. For a sensitive role, involuntary termination, or suspected misuse, access may need to end before the conversation takes place.
Keep the plan limited to people who need to know. Then gather four things:
- the employee's company email addresses, usernames, devices, and phone numbers
- the systems their team uses and any administrator roles they hold
- business records or customer conversations that must be retained or reassigned
- every recovery method tied to their accounts, including personal email and phone numbers
Common Mistake: Waiting until the employee has left the building to discover which applications they administered. At that point, a rushed team may reset shared passwords without preserving customer records or may leave a hidden recovery path in place.
The practical SaaS offboarding checklist
Use the following list as a baseline. Assign each item to a named owner and record when it was completed. If a service cannot be removed immediately because work must be transferred, reduce the account to the minimum role and set a short deadline.
1. Disable the central identity first
Disable the employee in the identity provider, Microsoft 365, Google Workspace, or other primary directory. Revoke active sessions and refresh tokens where the platform supports it. Do not simply change a password and assume that logged-in browsers and phones are disconnected.
If single sign-on is used, confirm that the change is flowing to connected applications. If it is not, make a manual list of the exceptions. This one step can remove access from many services, but it is not a substitute for reviewing privileged apps.
2. Reassign email, files, and customer conversations
Decide what happens to incoming mail, calendar ownership, cloud-drive documents, support tickets, and CRM accounts. Set forwarding rules carefully and for a defined period. An indefinite forward to a manager can expose personal or confidential messages and is easy to forget.
Transfer ownership of shared documents and calendars, then remove the former employee's direct permissions. For customer-facing roles, make sure a live teammate owns open opportunities, support queues, and renewal reminders before disabling the account.
3. Remove privileged SaaS roles and shared access
Review the applications with the greatest impact: accounting, payroll, banking, payment processing, domain registration, cloud hosting, code repositories, customer support, marketing platforms, and identity administration. Remove the account, not only the administrator role, unless there is a documented business reason to preserve limited access temporarily.
Check for shared mailboxes, team aliases, delegated calendars, and shared SaaS accounts. Replace passwords for truly shared credentials, move them into a password manager, and make future access traceable to named people.
4. Clean up password vaults, MFA, and recovery methods
Remove the person from password-manager vaults and shared collections. Rotate any credentials they could have viewed but that cannot be restricted to individual users. This matters most for administrator, finance, vendor, and emergency accounts.
Also review the quiet routes back into an account: MFA devices, backup codes, recovery email addresses, trusted phone numbers, app-specific passwords, and hardware security keys. A disabled employee profile is not enough if a shared admin account can still be recovered through the former employee's phone.
5. Revoke devices, browser sessions, and API access
Collect company laptops, phones, badges, security keys, and storage devices. Use mobile-device management or endpoint tooling to lock or wipe corporate devices when appropriate. For personally owned devices used for work, remove the work profile, managed applications, and corporate certificates according to your policy.
Do not overlook browser sessions. A laptop with a signed-in browser can hold access to email, cloud storage, and SaaS apps even after a password is changed. Revoke sessions from the service side and confirm device enrollment is removed.
Finally, look for API keys, personal access tokens, service credentials, and automations owned by the departing user. Transfer them to a managed service account where possible. A workflow that stops silently is an operational problem. A token that remains active is a security problem.
6. Verify vendor and external access
Employees may have logins to a managed service provider, payroll company, insurer, supplier portal, legal platform, or customer system. Ask the manager to list external parties the employee worked with, then remove or update their access. For high-risk vendors, notify the vendor's account owner through a known contact channel so that a social-engineering request cannot be made in the former employee's name.
Pro Tip: Keep a simple register of the systems that can move money, change DNS, reset identity, or expose customer data. Those systems deserve an explicit offboarding check every time, even if the person leaving was not an administrator on paper.
Make verification part of the process
Offboarding is not complete when the checklist is checked. It is complete when someone verifies the results. Have a second person confirm that the central account is disabled, the password-manager access is gone, the highest-risk SaaS roles are removed, and recovery methods now point to active staff.
Review sign-in logs for a short period after the change. An attempted sign-in from an old session, a password reset request, or a new MFA enrollment can reveal a missed access path. Treat it as a signal to investigate, not proof of wrongdoing.
For sensitive departures, preserve relevant logs and account information before changing anything, following the organization's legal and HR process. Security work should protect the business without turning routine employee changes into unnecessary surveillance.
Turn one checklist into a durable control
After each departure, note the services that were difficult to find, the ownership questions that slowed the team down, and the credentials that had to be rotated. Add those lessons to an application inventory. Over time, the business gains a clearer view of who owns each system, how access is granted, and which accounts are too important to depend on one person.
The useful measure is not how many boxes you checked. It is whether a former employee can still read company data, reset a critical account, or enter a high-impact system through a forgotten route. A short, rehearsed SaaS offboarding checklist keeps that answer from depending on memory during a busy transition.