Offboarding as a Security Event
Companies obsess over onboarding — get the new hire a laptop, accounts, and access on day one. Offboarding gets a fraction of the attention, usually a hurried scramble on someone’s last day, often handled by HR with no real involvement from IT. That asymmetry is a genuine security hole, because a departing employee’s lingering access is one of the most common and most overlooked ways businesses get hurt.
The risk isn’t only the disgruntled employee taking data on the way out, though that happens. It’s the dozens of forgotten access points that simply never get closed: the SaaS app HR didn’t know about, the personal device still synced to company email, the shared password never rotated, the cloud account that stays active for months because no one owned shutting it down. Every one of those is an open door that long outlives the employment.
An account you forgot to close doesn’t resign when the employee does. It just sits there, valid, waiting.
Where offboarding quietly fails
The failures share a root cause: nobody has a complete, current list of what access exists. So offboarding covers the obvious accounts — email, the main login — and misses the long tail. The marketing tool. The shipping portal. The financial system with a standalone login. The admin rights on a system nobody documented. Multiply that across every departure and you accumulate a growing population of orphaned, still-valid credentials that attackers love precisely because no one is watching them.
Personal devices add another layer. If an employee’s phone had company email and it’s never wiped or de-provisioned, your data walks out with them — not maliciously, just unmanaged. And shared credentials are the silent killer: if a team shared a password the departing person knew, that password is now compromised the moment they leave, whether or not they ever intend to use it.
What good offboarding looks like
Tight offboarding is a defined, repeatable process, not a last-day scramble. It starts with an inventory — a maintained list of every system and the access each role holds — so there’s a checklist to work from. On departure, accounts are disabled promptly and on a known timeline, ideally the moment access should end. Devices are wiped or de-provisioned. Shared credentials the person knew are rotated. Mailbox and file access is transitioned so the business keeps the data and the person loses the access. And it’s all logged, so you can prove what was done.
This is squarely managed services work, because it depends on the same things a good provider already maintains: a complete picture of your environment, centralized identity control, and a documented process that runs the same way every time regardless of who’s leaving or how busy that week is. The outcome you want is unambiguous: when someone leaves, their access leaves with them, completely and verifiably, the same day.
The goal of offboarding isn’t to revoke an account. It’s to be able to prove, with confidence, that there’s nothing left open.
Departures are routine; the security exposure they create shouldn’t be. The difference between a clean offboarding and a risky one is rarely effort in the moment — it’s whether the process and the inventory existed before you needed them. Build that once, and every future departure becomes a checklist instead of a gamble. That’s the quiet, unglamorous, outcome-focused work that separates a real IT partner from a help desk.
WPG builds offboarding into a repeatable, documented process so no access ever slips through. Let’s lock down your departures before the next one.