A staff member handing in their notice usually starts a sensible list of jobs: tell customers, arrange handover, collect keys and return equipment. One task can be missed until the last minute: deciding how to manage departing staff accounts.
It is rarely complicated, but it does need clear ownership. A former employee’s email address, shared files, cloud applications and saved passwords can all be tied into the working day. Closing everything too quickly can interrupt the team. Leaving everything open indefinitely creates confusion and makes it harder to see who has access to what.
The aim is not to turn an ordinary leaver into a security incident. It is to make a calm, planned change that protects business information while allowing work to continue.
Start before the final working day
The best time to deal with account access is when the employee gives notice, not after they have left. A short conversation between the manager, whoever handles HR, and IT is usually enough to establish what needs to happen and when.
Start with the practical questions. What systems does the person use? Do customers contact their direct email address? Are they the only person with access to a supplier portal, social media profile, shared mailbox or business phone? Have they created files that others will need to find?
For a small business, this may be a simple checklist rather than a formal offboarding process. The important part is that somebody owns it. Without that ownership, small daily details tend to sit with the departing employee simply because nobody else realised they were there.
It also helps to separate access needed during the notice period from access needed after departure. A person should normally retain the tools required to do their job until their final day. Removing access early can make handover harder and may feel needlessly awkward. Planning ahead gives you time to transfer responsibility without disrupting the work.
How to manage departing staff accounts without disruption
A good departure process is about continuity as much as security. Your remaining staff should be able to answer enquiries, find documents and carry on serving customers without hunting through old inboxes.
Keep the email address, but change who receives it
Email is often the most visible part of an employee leaving. Customers, suppliers and colleagues may continue to use an address for months, especially if it appears on old paperwork or is saved in their contacts.
Rather than deleting the mailbox immediately, decide how it will be handled. In many cases, you can set an automatic reply explaining that the person has left and directing senders to the right colleague or general business address. You may also choose to forward relevant messages to a manager or shared mailbox for a limited period.
There is a balance here. Indefinite forwarding can create a messy, permanent dependency on an old account. It can also mean private or irrelevant messages arrive with someone who does not need them. A clear handover period, followed by closure or archiving, is usually more manageable.
If the address is used for a role rather than a person, such as accounts@ or sales@, shared access is often a better long-term arrangement. It means the business is less dependent on one individual from the beginning.
Transfer access, not just passwords
Changing a password is useful, but it is not the whole job. Many cloud services allow access through individual user accounts, shared permissions, app connections or mobile devices. A departing team member may also be the named owner of a service, even though several people use it.
Look beyond the obvious systems. This can include Microsoft 365, accounting software, online banking approval tools, website hosting, domain registration, customer relationship systems, payroll platforms, booking systems and social media accounts. The right list depends on the business. A trades company, a consultancy and a small retailer will each have different essentials.
Where possible, transfer ownership to a suitable current employee or a business-controlled account. This avoids a useful service being tied to an address nobody can access later. It is also a good moment to check whether several people have administrator access where appropriate, rather than relying on one person alone.
Do not share a departing employee’s password around the office. It may feel like the quickest solution, but it makes future access difficult to track. Properly assigning access is cleaner and far less likely to cause IT gremlins later.
Protect files while preserving the handover
Files are another area where a little preparation saves time. Ask the employee to place current work in the agreed shared location and explain any folder structures, customer records or documents that need attention. This is not about checking every file they have ever touched. It is about ensuring active work is not left in a personal area that nobody else uses.
If your business uses shared cloud storage, it is usually straightforward to move or grant access to business documents before the account is closed. For locally saved files, it may be worth confirming that anything needed has been copied to the right place.
Think in terms of business records, not personal belongings. Customer proposals, project notes, supplier information and working templates need to remain available. Personal documents should be handled respectfully and in line with your normal employment policies.
Remove access at the right point
On the final working day, access should be removed or disabled in a controlled way. Disabling an account is often preferable to deleting it immediately. It prevents new sign-ins while giving the business a short window to check that email, files and system ownership have been dealt with properly.
The exact timing depends on the role and circumstances. Someone leaving at the end of a normal day may retain access until their finish time. If duties change during the notice period, or the person is placed on leave, access may need to change earlier. There is no single rule that fits every situation, which is why a conversation before the final day matters.
As well as their main work account, remember practical access routes: company laptop and phone, remote access, authenticator apps, shared tablets, office Wi-Fi, door entry systems and any company cards or keys. These are easy to overlook because they sit outside the usual list of software accounts.
For businesses using Microsoft 365, an IT partner can normally help preserve the mailbox and files for an agreed period, remove sign-in access, and reassign licences when appropriate. That avoids paying for unused accounts longer than necessary while still keeping the information the business needs.
Avoid making a permanent archive by accident
Businesses often hold onto former staff accounts “just in case”. That is understandable, particularly when someone was with the company for years. But accounts kept open without a plan can gradually become an untidy archive of old access, unused licences and unanswered email.
Set a retention decision when the person leaves. You may need to retain certain records for operational, contractual or legal reasons. Other material may no longer have a purpose once work has been handed over. The right period depends on the type of information and your own policies.
What matters is being deliberate. Record where the former employee’s essential files are held, who now owns the relevant services, and when the mailbox or account will be reviewed again. A short note is enough. It gives the next manager a clear answer when an old customer message or missing document appears months later.
Make the next departure easier
Each staff departure is also a useful reminder to reduce dependence on individual accounts while people are still in post. Shared mailboxes for team enquiries, central storage for customer work and business-owned administrator accounts make ordinary changes much less disruptive.
You do not need to rebuild everything at once. Start with the systems that would cause the most frustration if the person who knows them became unavailable tomorrow. Often, that means email, shared documents, customer systems and the handful of subscriptions quietly paid for by a company card.
A dependable process should feel fairly boring. The right people know what is happening, access changes at the agreed time, customers can still reach the business, and the team gets on with its work. That is exactly how it should be.
If departures are handled differently each time, a straightforward conversation with your IT support provider can help create a simple checklist that suits your business. It is one small piece of planning that makes future changes calmer for everyone involved.
