Most businesses put real effort into onboarding a new staff member, but offboarding tends to be an afterthought handled in a rushed final hour. That gap matters. A departing employee who keeps access to email, cloud files or a shared SaaS login is one of the most common, and most preventable, security risks an Australian SMB faces. A clear, repeatable offboarding process protects your data, your clients and your obligations under the Privacy Act.
Offboarding is a security event, not an HR formality
When someone leaves, the question is not simply “have we collected their laptop?” It is “can this person, or anyone who later compromises their old credentials, still reach our systems?” Disgruntled exits, dormant accounts and forgotten logins are all routes to data loss. Treating each departure as a security event, with the same discipline you apply to patching or backups, keeps small oversights from becoming expensive incidents.
Revoke access everywhere, not just email
Disabling a mailbox is the easy part. The harder part is the long tail of access most organisations have accumulated: Microsoft 365 or Google Workspace, accounting platforms, CRM and project tools, the password manager, VPN profiles, and any shared logins the person knew. Single sign-on helps, but plenty of apps sit outside it. Keep a living inventory of every system each role can reach, so offboarding becomes a checklist rather than a memory test. Don’t forget mobile device management, building or door access, and any API keys or service accounts the person created.
Reclaim and securely wipe the hardware
Collect laptops, phones, external drives and security keys on the final day, and confirm what is outstanding before the person walks out the door. Returned devices should be wiped to a recognised standard before they are reissued, resold or recycled, and you should keep a record of that erasure. This is where a managed offboarding process overlaps with proper IT asset disposal: hardware that leaves your business still carrying recoverable data is a breach waiting to happen, and a certificate of data erasure gives you the audit trail to prove it was handled correctly.
Automate the repetitive parts
Done manually, offboarding is slow and easy to get wrong, especially when several systems each need their own steps and someone is trying to remember all of them under time pressure. This is an ideal candidate for automation. A workflow that deprovisions accounts across every connected system in a single run, reassigns files to a manager and logs each action removes both the delay and the human error. If you want to move beyond manual checklists, our team at Kinsoft also builds custom AI workflows and business automation that can tie account deprovisioning, file handover and notifications together, so a single trigger does what used to take an hour of clicking. The same approach pays off on the onboarding side, provisioning access the moment a new hire signs.
Document, then review
Every offboarding should leave a paper trail: what access was removed, when, by whom, and which hardware was recovered and wiped. That record matters if you are ever audited or need to investigate an incident. Schedule a periodic review of accounts and licences as well, because the goal is to catch the orphaned logins and unused subscriptions that quietly accumulate between departures.
Make it a standard, not a scramble
Offboarding rarely happens on a convenient day, which is exactly why it should be documented and ideally automated rather than improvised. A short, well-maintained checklist closes the security gaps, keeps you compliant and saves your team from the last-minute scramble every time someone moves on. If you would like a hand building an offboarding process that fits the way your business actually works, that is the kind of thing a good managed IT partner should set up with you.