The IT checklist for when an employee leaves

The version we keep meeting looks like this. Monday morning, a laptop on the reception desk with the charger coiled beside it. Someone’s already been thanked, the card’s signed, the cake’s eaten. The laptop is back, the keys are back, the file is closed. And somewhere out in the world, a phone in a coat pocket is still quietly downloading her work email.

That’s the gap this checklist exists for. A leaver’s access isn’t on the laptop. Closing the mailbox and removing the access are two separate jobs, and deleting the account is the item that feels most like finishing. It isn’t. Access lives in sessions, in shared links, in group chats, in third-party logins nobody bought through IT, and above all in whatever device is still signed in.

Work down this list, in this order.

1. Decide what happens to the mailbox

Before anything gets switched off, decide who receives the mail that keeps arriving. Someone will email that address next Tuesday about an invoice, and they won’t know she’s left.

There are usually three options, and the right one depends on the role. Close it and set a bounce naming a replacement contact. Forward it to a colleague for a defined period. Or convert it to a shared mailbox the team can open, which on many plans no longer needs a paid licence; check yours rather than assuming.

The classic failure: “forward everything to the manager”, never turned off. Eighteen months later a director is still receiving supplier newsletters. Put an end date on it, and write the date somewhere you’ll actually look.

2. Sign out every device, especially the phone

This is the one that gets missed.

Ask what the work account was signed in on. The laptop is obvious; it came back in a box. The phone didn’t come back, because the phone is hers. A personal handset with a work account added to it isn’t a device anyone thinks of as an account. It has no asset tag, it was never issued, and it never makes the list.

Two things follow. The phone keeps receiving mail long after the laptop is wiped; the app just sits there refreshing. And the phone may be holding the second factor: the code or approval prompt that proves it’s really you is very often tied to an authenticator app or a phone number on a personal device. Leave that in place and the phone can approve a password reset, which quietly makes it the master key rather than a stray inbox.

The fix isn’t asking the person to delete the app. They usually would, but “I’ll sort it tonight” isn’t a control, and it puts them in an awkward spot on their last day for no reason.

Do it from the admin side. Revoke the active sessions, which forces every signed-in copy of the account to ask for a password it no longer has. If the phone’s enrolled in your device management, issue a wipe of the work data only: a selective wipe removes the work account, mail and files and leaves everything else alone. Her photos, her messages, her banking app: untouched. It’s built for exactly this moment. Whether you have it depends on your licence and how the phone was enrolled, so find that switch now rather than on the morning you need it.

Then remove the phone number and authenticator registration from the account itself. Otherwise the phone stays a recovery route even after the sessions are gone.

3. Untangle the shared files

Everyone thinks about what was shared with her. Fewer people think about what was shared by her.

Over the years she may have sent out sharing links: a price list to a customer, a spreadsheet to a supplier, a folder to a contractor. Some links are tied to her account and could break when it closes, which is disruptive but at least visible. Others keep working indefinitely for whoever holds the URL. Which behaviour you get depends on the platform and how each link was created.

Her personal work drive is the other half. Whatever sits in there, the only copy of the pricing model or the client folder she was midway through, needs an owner before the account closes. Most platforms give you a window to reassign it, and the window is finite. Before you let anything expire, know your restore position; our guide to whether OneDrive is a backup covers how to test it.

4. Remove her from the chats and channels

Group chats are nobody’s job by default, which is why she’s still in six of them at Christmas.

Team channels, project groups, the WhatsApp group for the delivery drivers. None appear on any offboarding form, because none were formally granted; they accumulated. Walk through the tools you actually use, and check whether she owned any of them, because an ownerless group is its own small problem later.

5. Chase the logins that never went through IT

The booking system. The courier account. The design app somebody expensed. The supplier portal with one shared login and the password taped inside a drawer.

No central list exists for these, because they were bought with a card by whoever needed them that afternoon. Nothing wrong with that; it’s how small businesses move. But it means the only reliable way to find them is to ask while she’s still there to answer. And if a shared password was involved, it changes when she leaves. Not because of her. Because a credential known to a former colleague is no longer a credential you control.

6. Then, and only then, deal with the licence

Removing the licence last is deliberate. Strip it first and you can lose access to the mailbox you were about to convert, or start a deletion clock on files you haven’t reassigned. Sort the mail and the data, then release the seat.

And check it actually gets released. Paying for a subscription belonging to someone who left in March is a common and entirely silent expense.

Timing: before, during, a week after

Before the last day. Book twenty minutes with her. What is she signed in on, what does she pay for, what recurring jobs does she do that nobody else touches? Write it down. That conversation is worth ten times more before the goodbye card than after.

On the day. Sessions revoked, devices signed out or selectively wiped, mailbox handled, files reassigned, chats cleared. Aim for the end of the working day rather than 9am; cutting someone off mid-morning is a needlessly cold way to end a good relationship.

A week later. Ten minutes, and check: anything still forwarding, any sharing link surfaced, licence actually gone, chats actually cleared. Something almost always turns up, because the day itself is busy and the misses are quiet. This is the check nobody does, and it’s the cheapest one on the list.

When the leaver was the person who knew everything

Sometimes the person leaving set up the phone system, knows which supplier portal has the good pricing, and is the only human who understands the spreadsheet. Often nobody appointed them; they were just good with computers, and it accreted.

We take over from that arrangement regularly, and what we find when it ends is consistent. They’re often the only global administrator, the one account that can change anything. Sometimes the recovery codes ring their phone. And what they know is written down nowhere. The first two are annoying but usually recoverable, given time and proof of who owns the business. The third one doesn’t come back.

So don’t ask for a handover document; a leaver working notice has limited enthusiasm for writing one. Ask questions instead. What breaks if you’re not here? What do you log into that we don’t know about? Who do you ring when the thing goes wrong? Do it early in the notice period, while she’s still cheerfully answering. Goodwill has a half-life, and it’s shorter than four weeks.

The leaver’s access card

Keep this on one page, wherever the leaver paperwork lives:

  • Mailbox: closed, forwarded or converted, with an end date
  • Sessions: revoked on all devices
  • Personal phone: work data removed, MFA registration removed
  • Shared files: owned by someone, links reviewed
  • Chats and channels: removed, ownership reassigned
  • Third-party and shared logins: identified and changed
  • Licence: released, billing confirmed
  • Diary: the one-week check booked

Print it and put it in the folder with the P45 template. Starters need their own card, but that’s a different post. And if the process feels like more than anyone has time for, that’s the point where a managed IT provider earns its keep: for our clients, this list is what happens by default rather than by memory.

None of this is difficult. It’s just longer than it looks, and the parts that get missed are the ones without a piece of hardware attached.

Quick answers

Should we run this for contractors too? Yes, and often more thoroughly. Contractors are likelier to have used their own devices and their own tools, so steps 2 and 5 carry more weight, and their access sometimes has no formal start record to work back from. Same card, heavier tilt.

Do we need the leaver’s consent to wipe work data from their phone? A selective wipe removes the work profile only, and the ability to do it was agreed when the account was added to the device. Set that expectation in writing at enrolment, not at exit. If the phone was never enrolled, revoke sessions and remove the MFA registration from the account side; that closes the door without touching the handset.

What if someone left months ago and none of this happened? Run the card today as an audit, in the same order. The quiet items survive indefinitely until someone looks.

If you would like any help or advice, get in touch today!

Owen Williams Owen Williams · Managing Director

Want this handled for you?

Everything we write about, we do for businesses of 5–250 people across Suffolk and East Anglia. Book a relaxed 30-minute call with Owen.

01449 798119 · enquiries@westviewit.co.uk

Book your call →