What to switch off when someone leaves

Published 2026-09-14 by Woodruff Training

When somebody leaves a small business, the laptop comes back and the keys go on the hook. The logins tend to stay live. Nobody decides to leave them open. Access just builds up over a few years across a dozen different systems, nobody writes it down, and on the leaver's last day there is no list to work from.

Why a forgotten account matters months later

The risk here is rarely the person who left. It is the account they left behind.

A dormant account still works, still has the same password, and that password may already be sitting in a breach list somewhere for anyone to buy. Worse, nobody is watching it. If a stranger logs into the mailbox of someone who left in March, there is no colleague to notice odd behaviour and no reason for anyone to question it. We wrote about how stolen logins get traded if you want the background.

There are duller reasons too. Company email still arriving on a personal phone. A subscription you are paying for every month because it was set up on somebody's own card. An old admin account on the website that no longer has a person attached to it.

The ones people forget

Email and the laptop are easy to remember. These are the accounts that slip through:

  • Mail forwarding and shared mailboxes. Check whether a forwarding rule was ever set up, and whether the leaver still has delegated access to the info@ or accounts@ inbox.
  • The website. WordPress and similar systems accumulate admin users. Look at the full list, not just the obvious one.
  • Social media. Often linked to a personal Facebook or LinkedIn profile rather than a company account.
  • Accounting, payroll and banking. Including read-only access and anyone named as a payment approver.
  • File storage. Dropbox, Google Drive, OneDrive, and any folder shared to a personal address.
  • Mobile devices. A phone that still holds company email needs the account removed from it, not just a promise that it was deleted.
  • Shared logins. If several people used one password, that password has now walked out of the door. Change it.
  • Doors and alarms. Key fobs, door codes and the alarm panel code, if it was one everybody knew.

A list you write on day one

The trick is to stop treating this as a leaving job. Every time you give a new starter access to something, add it to a short list kept with their file. Then leaving day is twenty minutes of working down that list instead of an afternoon of guessing.

Two other habits help. Disable accounts before you delete them, so the email and files stay available while you work out what you need. And move away from shared passwords where you can, because a login with one name on it can be switched off cleanly, whereas a login four people know has to be changed and redistributed every time anyone moves on.

If you are working towards Cyber Essentials, this is already part of it: the scheme asks you to remove access promptly when someone no longer needs it, and to be able to show how. Our free checklist covers what that looks like in practice.

The short version is that leaving day should be boring. If you cannot say today which systems your last leaver still has access to, that is the thing worth an hour this week. Get in touch if you would like help putting the list together.