How to Onboard and Offboard Employees
Without Creating Security Gaps

Two of the riskiest moments in your business's security life happen every time someone joins your team — and every time someone leaves. Most small businesses handle both badly. Here's how to fix that.

Picture this: your new marketing manager shows up on Monday morning, excited to get started. By 10am they're sitting at a desk with no computer login, no email access, and no idea who to call. Their manager is in back-to-back meetings. IT — which in your business means you or a part-timer — didn't know the start date until Friday afternoon. Nothing was prepared.

Now flip the scenario: a sales rep left three months ago on bad terms. They still have their company email login. It's still forwarding to their personal Gmail. And your Salesforce account — with every customer relationship and deal in progress — is still accessible with the credentials they memorized before they walked out the door.

Both of these happen constantly in small businesses. Not because the owners are careless — they're not. It's because employee onboarding and offboarding tend to be handled ad hoc, by whoever has a spare hour, with no checklist and no clear owner. That's a problem that goes beyond inconvenience. It's a real security risk.

After 30+ years working with small businesses, these are two of the most common preventable problems we see. The good news: they're also two of the easiest to fix once you have a system.

This Isn't Just About Convenience — It's About Security

A chaotic onboarding is frustrating and expensive. But a sloppy offboarding is a genuine security incident waiting to happen.

We've audited small businesses where former employees still had active Microsoft 365 accounts six months after leaving. Still had VPN access. Still had login credentials to the company's cloud storage, project management software, and in one alarming case, their banking portal. These weren't malicious oversights — they were just forgotten. Nobody had a checklist. Nobody was responsible.

The problem with "forgotten" access is that it doesn't stay forgotten forever. Disgruntled ex-employees sometimes use it intentionally. More often, their accounts get compromised because they're no longer being monitored, their passwords never get changed, and they become the path of least resistance for an attacker. Either way, your business pays the price.

Consider: most modern breaches don't involve sophisticated hacking — they involve attackers using valid credentials. An ex-employee's account sitting open is exactly the kind of invitation that makes their job easy.

Onboarding matters too, beyond the productivity hit. When new employees don't have proper access set up from day one, they improvise. They ask a coworker to log in for them. They use their personal email for work communication. They take shortcuts with file sharing. Every one of those workarounds creates a security problem that's hard to undo later.

Getting Onboarding Right

The goal of IT onboarding is simple: your new employee has everything they need to do their job on day one, with no more access than their role requires, using credentials that belong only to them.

That last part is more important than it sounds. Shared accounts are a lazy shortcut that creates lasting problems — you can't audit who did what, you can't revoke access without affecting other people, and you can't enforce individual accountability. Every person gets their own login. No exceptions.

What Should Be Ready Before Day One

The key is starting the process before the employee arrives — ideally a week out. Here's what should be in place the morning they walk in:

Hardware ready. Computer set up, logged in, and tested. If they're remote, it should be shipped ahead and they should be able to reach IT support before their first day to confirm everything works.

Accounts created. Company email, Microsoft 365 or Google Workspace, any line-of-business applications they'll use. Don't wait until they arrive to start creating accounts — provisioning can take time and will eat their whole first morning if it's done reactively.

Multi-factor authentication enrolled. This should be mandatory from account creation, not something you add later. If you're not already requiring MFA on all accounts, this is the time to fix that.

Access scoped to their role. A new bookkeeper doesn't need admin access to your cloud file server. A new front-desk employee doesn't need access to HR files. Give people what they need to do their job — no more. This is called the principle of least privilege, and it dramatically limits the damage if an account gets compromised.

Password manager setup. If your business uses a password manager, enroll the new hire and share only the credentials they need. If you don't have one yet, this is a good reason to start.

Security training scheduled. Even a short 30-minute session on phishing awareness and safe password habits matters. New employees are actually more receptive to this kind of training than long-timers, because they don't have established bad habits yet.

A Quick Onboarding Checklist

We have a more detailed version of this checklist available in our free onboarding and offboarding guide if you want to use it as a starting point.

Getting Offboarding Right — This Is the High-Stakes One

Offboarding is where most businesses really drop the ball — and where the consequences are most serious. The window between when an employee gives notice (or is let go) and when their access is fully revoked is when your business is most exposed.

Here's the uncomfortable reality: the most dangerous time is the day someone leaves. Not a month later when you finally get around to disabling their account. The day they leave. If the offboarding process isn't immediate and systematic, you have a window where a person who is no longer your employee still has full access to your business systems.

The Two Scenarios Require Different Approaches

Planned departures (resignations with notice): You have time to prepare a proper handoff. Work with the departing employee to document what they own, transfer credentials and responsibilities, and ensure nothing is lost. Start the access review before their last day — you don't have to wait until they walk out the door to begin the process.

Immediate terminations: These are handled differently. Speed is the priority. Access gets revoked the moment the employment ends — ideally before they've even left the building. This isn't about distrust; it's about having a process that's consistent and doesn't depend on someone's emotional state in a difficult moment.

What Needs to Happen on Departure Day

The order matters. Do the access revocation first, then have the conversation, or simultaneously. Here's what should happen immediately:

Disable or delete the Microsoft 365 / Google Workspace account. Don't delete it right away — you may need access to their email or files. Disable the login and set up email forwarding to a manager, then delete after 30-90 days once you've confirmed nothing important was missed.

Change any shared passwords they knew. This is the one that gets overlooked. If they had the WiFi password, the admin password to any shared systems, or access to any accounts that weren't individual logins, those need to change. This is also why we advocate for individual accounts rather than shared ones — it makes offboarding far cleaner.

Revoke VPN access and remote desktop access. If they were working remotely, their access path into your network needs to close immediately.

Deactivate in all line-of-business applications. Every app you use: CRM, accounting software, project management, HR system, scheduling tools. Make a list of every application and go through it systematically. This is where a managed IT approach pays dividends — your provider should maintain a current application inventory so nothing gets missed.

Recover company hardware. Laptop, phone, security token, anything else issued. If it can't be returned immediately, remote-wipe it.

Audit what they had access to. After the immediate steps are done, go back through their access log to confirm everything is covered. Were they an admin on anything? Did they have access to any external services in the company's name?

A Quick Offboarding Checklist

Turn This Into a System, Not a Scramble

The businesses that handle onboarding and offboarding well share one thing in common: they have a written process that doesn't depend on anyone remembering the steps under pressure.

That's it. It's not fancy technology. It's not a big investment. It's a checklist that lives somewhere reliable — your IT documentation, your HR system, a shared folder — and a clear owner for each step. HR owns the HR parts. IT owns the access parts. The manager owns the equipment and key-handoff parts. Nobody is waiting for someone else to take the lead.

Here's what makes this easy to implement:

Maintain a current application inventory. Every application your company uses, with the admin contact and access management process for each. This sounds tedious, but it doesn't have to be elaborate — a simple spreadsheet works. When someone leaves, you run through the list. Nothing gets missed because you forgot you subscribed to something two years ago.

HR notifies IT as early as possible. For planned departures, the moment a resignation is accepted, IT should know the last working day. That lead time makes everything smoother. For terminations, IT should be notified at the same time as the conversation happens — not an hour later.

Use individual accounts, not shared logins. We've said this before but it bears repeating. Shared accounts are the enemy of clean offboarding. When everyone has their own login, offboarding is a defined list of steps. When access is tangled up in shared passwords and group logins, it's a mess every time.

Review access quarterly. Even with a good offboarding process, accounts accumulate. A quarterly review of active accounts against your current employee list will catch anything that slipped through. It takes an hour. It's worth it. This is also a great time to check that your Microsoft 365 settings are properly configured — guest access, external sharing, and admin accounts deserve regular attention.

If you want to get more rigorous about this, consider running a broader security review as part of your annual IT planning. Identity and access management — knowing who has access to what and making sure it's appropriate — is one of the highest-impact things a small business can invest time in.

The Mistakes That Keep Coming Up

After doing hundreds of IT assessments with small businesses, here are the specific failures we see over and over:

The "we'll get to it" offboarding. Someone leaves on a Friday. The plan is to deal with their accounts Monday. Monday becomes two weeks later. Two weeks becomes never. The account sits open indefinitely because nobody ever had a specific task to close it. This is the most dangerous scenario because it's so ordinary — there's no emergency, so there's no urgency.

The admin-on-everything new hire. A new employee joins, and to avoid friction someone gives them admin access "just to get them started." Admin access never gets reviewed or reduced after that. They now have elevated privileges they don't need and might not even know they have. This is how small businesses end up with five people who can all reset everyone else's passwords.

The service account nobody remembers. Old employees sometimes set up service accounts — automated connections between tools, integrations, API keys — that are tied to their personal credentials. When they leave, those integrations break, or worse, stay running under credentials that should be dead. This is hard to find unless you're maintaining proper documentation.

No notification to IT until after the fact. The manager has the tough conversation, the employee packs up and leaves, and IT finds out three hours later when someone asks why the person's email still works. By then, the former employee has had unmonitored access for hours.

None of these require expensive software to fix. They require a process, clear ownership, and the discipline to follow through consistently. That's achievable for any business.

Two Checklists. One Less Security Risk.

Employee onboarding and offboarding are two sides of the same coin. Do them well and your new hires hit the ground running, your ex-employees can't do any harm, and your business stays secure through normal turnover. Do them poorly and you're accumulating security debt with every hire and every departure.

The fix isn't complicated. Build the checklists. Assign ownership. Make IT a part of the conversation on both ends. And review your active accounts regularly so nothing lingers that shouldn't.

If you want a head start, our free onboarding and offboarding checklist walks through both processes in detail, formatted for real use. Download it, adapt it to your business, and start using it with your next hire or departure.

And if you're not sure what former employees still have access to right now — you probably should be. That audit is a good place to start.

Not Sure Who Has Access to What in Your Business?

We can audit your current user accounts and access controls, identify anything that shouldn't still be open, and help you build a simple process so future transitions go smoothly. No jargon, no upsells — just a clear picture of where you stand.

Get a Free IT Assessment