Security · Offboarding
Why offboarding matters, a timed checklist, how to handle contractors and bad leavers, an access inventory and a template.
Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.
Quick answer
Offboarding should remove a leaver’s access to every system on or before their last day: email, identity provider, client portal, practice and accounting software, shared drives and messaging. Revoke multi-factor devices and sessions, change shared passwords and keys, retrieve equipment, transfer files and clients, review audit logs, send a written confidentiality reminder and run a 30-day check. Treat contractors and developers the same, keep an access inventory and keep ownership of apps and accounts with the firm.
Key takeaways
- Remove access to every system on or before the last day, not just email.
- Change shared credentials and revoke multi-factor devices and sessions.
- Keep an access inventory so offboarding is a checklist, not memory.
- Treat contractors and developers the same, and keep ownership of apps and accounts.
- Review logs and run a 30-day check.
In this guide
Why does offboarding matter for security?
When people leave, they take knowledge with them and sometimes access they should no longer have. Former staff and contractors with live accounts are a common source of data exposure, whether through malice, carelessness or a stolen password. For firms that hold client information, a disciplined offboarding process is as important as onboarding.
The offboarding checklist
| When | Action |
|---|---|
| Before the last day | Confirm the leaving date and who needs to know. Plan handover of work, files and client relationships. |
| Before the last day | List every system and account the person uses, including shared logins and API keys. |
| Last day | Disable or remove access to email, the identity provider, the client portal, practice and accounting software, shared drives, messaging and collaboration tools. |
| Last day | Remove the person’s multi-factor authentication devices and sessions, and revoke tokens. |
| Last day | Change shared passwords and rotate any keys or credentials they knew. |
| Last day | Retrieve equipment: laptop, phone, keys, access cards and tokens. |
| Last day | Check personal devices or accounts for firm data, per your policy and the law. |
| Last day | Transfer ownership of files, mailboxes and client records to named colleagues. |
| Last day | Set an out-of-office or forwarding arrangement for email, per policy. |
| After | Review audit logs for unusual access in the weeks before and after departure. |
| After | Remind the person of ongoing confidentiality duties, in writing. |
| After | Update records, access lists, and the supplier and system registers. |
| 30 days later | Check that no active accounts or devices remain. |
Contractors and external advisers
Contractors, freelancers and suppliers need the same treatment, and they are easier to forget. Keep a list of everyone outside your staff who has access, including developers with access to your apps and databases. Remove their access when the work ends, and make sure ownership of your apps, accounts and domains stays with you. See how to choose a development partner.
An access inventory makes it work
| Column | Why |
|---|---|
| System or account | Know everything that exists |
| Who has access and what role | See access at a glance |
| Owner of the account | Someone is responsible |
| Date access was granted | Spot stale access |
| Date last reviewed | Prove regular review |
| Authentication method | See where multi-factor is missing |
Without an inventory, offboarding relies on memory. With one, it is a checklist.
Offboarding checklist template
Leaver record
Name: ________ Role: ________ Leaving date: ________ Manager: ________
Systems and accounts to remove: ________
Shared credentials to change: ________
Equipment returned (date): ________
Files and clients transferred to: ________
Logs reviewed by (date): ________
Confidentiality reminder sent (date): ________
30-day check completed (date): ________
What about leavers who leave on bad terms?
- Remove access before they are told, where the situation requires it, and with advice on employment law.
- Check logs for unusual downloads or exports.
- Rotate credentials immediately.
- Restrict physical access.
- Take advice before accessing personal devices or accounts.
What mistakes should you avoid?
- Removing email but forgetting other systems.
- Shared passwords that never change.
- Developers or contractors retaining access after a project ends.
- No account ownership, so nobody can disable a departed person’s account.
- No review of logs.
- Leaving client files in personal storage.
- No 30-day check.
How can systems help?
Role-based access, central sign-on and an audit trail make offboarding faster and verifiable, and internal tools can turn the checklist into tasks with owners and deadlines. Simple Automation Solutions builds these on Bubble.io, starting at $3,500, with a $345 Discovery Sprint credited toward the build. See our security guide, what to cut before you build and our guide to staff onboarding checklists.
Frequently asked questions
What should be in an offboarding checklist?
Handover planning, removing access to every system, revoking multi-factor devices and sessions, changing shared credentials, returning equipment, transferring files and clients, reviewing logs, a confidentiality reminder and a 30-day check.
How quickly should access be removed when someone leaves?
On the last day at the latest, and immediately where the situation requires it.
Do contractors need offboarding too?
Yes. Keep a list of everyone external with access, including developers, and remove access when the work ends.
What is an access inventory?
A list of every system and account, who has access and what role, who owns it and when it was last reviewed.
What if a leaver has firm data on a personal device?
Follow your policy, take advice on employment and data protection law and ask for removal and confirmation in writing.
Want offboarding and access control that runs from a checklist?
Email us how access is managed in your firm today. We will outline a simple internal system.
Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions
About Simple Automation Solutions (SA Solutions)
Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.