Security · Offboarding

Why offboarding matters, a timed checklist, how to handle contractors and bad leavers, an access inventory and a template.

Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.

Quick answer

Offboarding should remove a leaver’s access to every system on or before their last day: email, identity provider, client portal, practice and accounting software, shared drives and messaging. Revoke multi-factor devices and sessions, change shared passwords and keys, retrieve equipment, transfer files and clients, review audit logs, send a written confidentiality reminder and run a 30-day check. Treat contractors and developers the same, keep an access inventory and keep ownership of apps and accounts with the firm.

Key takeaways

  • Remove access to every system on or before the last day, not just email.
  • Change shared credentials and revoke multi-factor devices and sessions.
  • Keep an access inventory so offboarding is a checklist, not memory.
  • Treat contractors and developers the same, and keep ownership of apps and accounts.
  • Review logs and run a 30-day check.

Why does offboarding matter for security?

When people leave, they take knowledge with them and sometimes access they should no longer have. Former staff and contractors with live accounts are a common source of data exposure, whether through malice, carelessness or a stolen password. For firms that hold client information, a disciplined offboarding process is as important as onboarding.

The offboarding checklist

WhenAction
Before the last dayConfirm the leaving date and who needs to know. Plan handover of work, files and client relationships.
Before the last dayList every system and account the person uses, including shared logins and API keys.
Last dayDisable or remove access to email, the identity provider, the client portal, practice and accounting software, shared drives, messaging and collaboration tools.
Last dayRemove the person’s multi-factor authentication devices and sessions, and revoke tokens.
Last dayChange shared passwords and rotate any keys or credentials they knew.
Last dayRetrieve equipment: laptop, phone, keys, access cards and tokens.
Last dayCheck personal devices or accounts for firm data, per your policy and the law.
Last dayTransfer ownership of files, mailboxes and client records to named colleagues.
Last daySet an out-of-office or forwarding arrangement for email, per policy.
AfterReview audit logs for unusual access in the weeks before and after departure.
AfterRemind the person of ongoing confidentiality duties, in writing.
AfterUpdate records, access lists, and the supplier and system registers.
30 days laterCheck that no active accounts or devices remain.

Contractors and external advisers

Contractors, freelancers and suppliers need the same treatment, and they are easier to forget. Keep a list of everyone outside your staff who has access, including developers with access to your apps and databases. Remove their access when the work ends, and make sure ownership of your apps, accounts and domains stays with you. See how to choose a development partner.

An access inventory makes it work

ColumnWhy
System or accountKnow everything that exists
Who has access and what roleSee access at a glance
Owner of the accountSomeone is responsible
Date access was grantedSpot stale access
Date last reviewedProve regular review
Authentication methodSee where multi-factor is missing

Without an inventory, offboarding relies on memory. With one, it is a checklist.

Offboarding checklist template

Leaver record

Name: ________ Role: ________ Leaving date: ________ Manager: ________

Systems and accounts to remove: ________

Shared credentials to change: ________

Equipment returned (date): ________

Files and clients transferred to: ________

Logs reviewed by (date): ________

Confidentiality reminder sent (date): ________

30-day check completed (date): ________

What about leavers who leave on bad terms?

  • Remove access before they are told, where the situation requires it, and with advice on employment law.
  • Check logs for unusual downloads or exports.
  • Rotate credentials immediately.
  • Restrict physical access.
  • Take advice before accessing personal devices or accounts.

What mistakes should you avoid?

  • Removing email but forgetting other systems.
  • Shared passwords that never change.
  • Developers or contractors retaining access after a project ends.
  • No account ownership, so nobody can disable a departed person’s account.
  • No review of logs.
  • Leaving client files in personal storage.
  • No 30-day check.

How can systems help?

Role-based access, central sign-on and an audit trail make offboarding faster and verifiable, and internal tools can turn the checklist into tasks with owners and deadlines. Simple Automation Solutions builds these on Bubble.io, starting at $3,500, with a $345 Discovery Sprint credited toward the build. See our security guide, what to cut before you build and our guide to staff onboarding checklists.

Frequently asked questions

What should be in an offboarding checklist?

Handover planning, removing access to every system, revoking multi-factor devices and sessions, changing shared credentials, returning equipment, transferring files and clients, reviewing logs, a confidentiality reminder and a 30-day check.

How quickly should access be removed when someone leaves?

On the last day at the latest, and immediately where the situation requires it.

Do contractors need offboarding too?

Yes. Keep a list of everyone external with access, including developers, and remove access when the work ends.

What is an access inventory?

A list of every system and account, who has access and what role, who owns it and when it was last reviewed.

What if a leaver has firm data on a personal device?

Follow your policy, take advice on employment and data protection law and ask for removal and confirmation in writing.

Want offboarding and access control that runs from a checklist?

Email us how access is managed in your firm today. We will outline a simple internal system.

Email info@sasolutionspk.com

Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions

About Simple Automation Solutions (SA Solutions)

Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.

Simple Automation Solutions

Business Process Automation, Technology Consulting for Businesses, IT Solutions for Digital Transformation and Enterprise System Modernization, Web Applications Development, Mobile Applications Development, MVP Development