Staff Onboarding and Offboarding: Getting IT Access Right as People Join and Leave
Every time someone joins or leaves your business, access to systems and data changes hands. Handled loosely, this leaves former staff with live logins and new starters over-permissioned. A simple, repeatable checklist for granting and removing access — the right accounts, MFA, and a clean exit on day one of leaving — closes one of the most common gaps small firms have.
Some links on this page are affiliate links: if you sign up or buy through them, Dacros may earn a commission, at no extra cost to you. We only recommend tools we use and rate. Full disclosure.
Access is something you hand out — and have to take back
When a new person joins your business, you give them keys: an email account, a login to your systems, access to shared files, maybe the booking software or the accounts package. When they leave, all of those keys need to come back. That sounds obvious, yet the taking-back is where small businesses slip up most often — quietly leaving former staff with live access to company systems long after their leaving do.
Getting this right isn’t about bureaucracy. It’s about making sure the right people can reach the right things while they work for you, and nothing at all the moment they don’t. The good news is that both sides of the job — onboarding and offboarding — come down to a simple, repeatable checklist. Once you’ve written it, you run it every time and the guesswork disappears.
Onboarding: give enough, and no more
The temptation with a new starter is to grant broad access ‘to save hassle later’. Resist it. The safer approach is least privilege: give people access to exactly what their role needs, and add more only when there’s a reason. If a single account is ever compromised, least privilege is what stops one breach becoming a company-wide one.
A clean onboarding runs roughly like this:
- Create individual accounts. Their own email and their own logins — never a shared one passed around the team.
- Grant role-based access. Match access to the job. A receptionist and a finance manager should not have the same reach into your systems.
- Turn on multi-factor authentication from the start. MFA should be set up on day one, not bolted on later. It’s the strongest single protection against stolen passwords.
- Set them up with a password manager. Hand over any credentials securely and get them generating strong, unique passwords from the outset. A shared tool like Proton Pass lets you provision logins to a new starter and — crucially — take them back later, without passwords ever being emailed around or written on a notepad. Our password manager guide covers how to choose one.
- Write down what you granted. A short record of who has access to what is the thing that makes offboarding painless. It’s also exactly what you’ll wish you had if something ever goes wrong.
That last step is the quiet hero of the whole process. You can’t reliably remove access you never recorded granting.
Offboarding: the day someone leaves is the day it matters
Offboarding is where good intentions go to die. Departures are busy and often awkward — handovers, final projects, sometimes hurt feelings — and IT access is the easiest thing to forget. But a forgotten login doesn’t forget you. It sits there, live, as a dormant account: nobody’s watching it, and it’s one of the tidiest ways for an attacker (or a disgruntled former employee) to get in.
A forgotten login doesn’t forget you. It sits there, live, as a dormant account.
Your offboarding checklist should mirror your onboarding one, in reverse, and ideally run on the person’s last working day:
- Disable their accounts — email, systems, any cloud apps. Disabling rather than instantly deleting lets you retain data you may need while cutting off access immediately.
- Revoke shared and third-party access — anything they were added to individually, from the accounts software to the social media logins.
- Rotate shared passwords — any login the departing person knew should be changed at once. This is why individual accounts are so much easier: fewer passwords to scramble to reset.
- Reclaim company data and devices — files, and any company hardware. If they used their own phone or laptop, make sure company data is removed or its access switched off centrally.
- Remove MFA and recovery access — so they can’t reset their way back in through a linked personal phone or email.
- Handle it faster if the exit is difficult. For a planned, friendly departure, the last day is fine. For a dismissal or a resignation that turns tense, treat access removal as a same-hour job, not a next-week one.
The role of individual accounts and central control
Everything above is dramatically easier if two things are true: everyone has their own account, and those accounts can be switched on and off from one place. Shared logins are the enemy here — you can’t remove one person from a password everyone uses without disrupting the whole team.
Centralising your accounts, typically through Microsoft 365 or Google Workspace admin controls, turns offboarding into a two-minute task: disable the user, and their access to everything connected drops away at once. For a growing team, that shift from chasing individual logins to flipping a single switch is one of the highest-value improvements you can make, and it sits naturally within managed IT support.
Make it a habit, not a heroic effort
The firms that get this right aren’t the ones with the biggest IT budgets — they’re the ones who wrote the checklist down and follow it every single time. Onboarding and offboarding shouldn’t rely on one person remembering the steps in their head. A short, shared process means it happens the same way whether you’re welcoming your busiest week’s third new hire or saying goodbye to someone in a hurry.
If you’re not confident that every past leaver has truly lost access — or that new starters are set up securely from day one — that uncertainty is itself the risk. It’s also very fixable. As part of getting your cyber-security foundations in order, we can build you a simple joiners-and-leavers checklist and the central controls to run it cleanly. Get in touch and we’ll make the whole thing routine.
Frequently asked questions
Why is offboarding such a common security weak spot?
Because leaving is usually rushed and emotional, and IT is an afterthought. Handovers, final projects and goodbyes take priority, and nobody stops to list every system the person could log into. The result is dormant accounts — live logins nobody is watching — which are a gift to attackers and a risk if the departure wasn't amicable. Having a written offboarding checklist means access is removed reliably, not just when someone remembers.
What's the danger of giving new staff too much access?
If every new starter gets broad access 'to be safe', a single compromised account can expose far more than it should. The principle of least privilege — giving people access only to what their role needs — limits the damage if an account is breached or misused. It's also easier to manage: you can see who can reach sensitive data because you granted it deliberately, rather than everyone having everything by default.
How quickly should we remove a leaver's access?
Ideally on their last working day, and immediately if the departure is sudden or difficult. The moment someone no longer needs access, that access becomes pure risk with no benefit. For planned leavers, tie the removal to their finish date; for dismissals or resignations that turn tense, treat access removal as an urgent, same-hour task rather than something to tidy up later in the week.
Do we need special software to manage this?
Not necessarily. Many small businesses run onboarding and offboarding well with a simple written checklist, a shared password manager to hand over and revoke credentials, and the built-in admin controls in Microsoft 365 or Google Workspace. As you grow, centralising accounts so access can be switched on and off from one place makes it far quicker — but the discipline of a checklist matters more than any particular tool.
What about shared accounts and passwords?
Shared logins are a real headache when people leave, because you can't remove one person's access without changing the password for everyone. Wherever possible, give each person their own account. Where a shared login is genuinely unavoidable, keep it in a password manager so you can rotate it the moment someone departs, and know exactly who had it.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
The backup password on the laptop you're backing up
Recovery controls fail in a way audits miss: the control quietly depends on the very thing it is meant to recover you from. We found five in our own systems in a week — here's the one question that finds them, and a two-hour fix.
Read → GuideIT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.