A departing employee who still holds a working login after their last day is one of the quietest security failures an Australian business can have. This guide gives managers a same-day offboarding sequence that closes every door — email, finance systems, shared vaults, devices — and the dated record that proves it happened.
Key takeaways
- Run the checklist on the leaver's final day, not the following week.
- Rotate every shared credential the person could see, not just their own login.
- Kill active sessions and revoke multi-factor enrolment, not only the password.
- Recover devices and company data before the last pay clears.
- Keep a dated record: insurers and auditors ask for offboarding evidence in 2026.
Who this is for
This is for owners, HR and office managers at Australian organisations between roughly 5 and 200 staff, and for MSPs who run offboarding on behalf of clients. You do not need an IT department — every step here uses an admin console you already pay for, and the whole sequence fits inside about 60 minutes.
Why this matters
When someone leaves, the instinct is to focus on handovers and final pay. The accounts they hold are the last thing anyone touches, and that gap is exactly what attackers and departing grudges exploit. An active mailbox on a departed employee's name keeps receiving company mail; an unrecovered laptop holds client files; a shared vault password the leaver memorised still opens the Xero login.
The broader habit that makes offboarding work is training. If staff already know how to report a suspicious email and why security awareness matters day to day, closing their access is a short, low-drama conversation. If not, offboarding becomes the only security ritual the company performs, and it shows.
The 60-minute offboarding sequence
Step 1: Disable the account — do not delete it
In your email or directory console, suspend the account rather than deleting it. Deletion destroys mail, files and audit history you may legally need to keep; suspension closes the door while preserving everything. Set a calendar reminder to review deletion against your record-keeping obligations after 12 months.
Step 2: End active sessions and revoke MFA enrolment
Changing a password does not log the person out of mail apps, phone mail clients or saved sessions. In the admin console, force sign-out of all sessions and revoke the account's multi-factor authentication enrolment. The Australian Signals Directorate describes MFA as one of the most effective protections against unauthorised account access — and the same is true in reverse: an enrolled device a leaver still holds is an open door even after a password change. The relevant guidance lives at cyber.gov.au's MFA advice.
Step 3: Rotate shared credentials
List every shared login the person could reach: the Xero or MYOB account, the courier portal, social media, the subscription tools, the team password vault. Rotate each of those passwords during offboarding and confirm the new credentials landed with the people who now own them. If you keep a shared vault, this step is one revoke-and-rotate action; if shared logins live in a spreadsheet, this is the week to fix that.
Step 4: Transfer ownership
Reassign what the leaver owned before their access dies: file ownership in cloud drives, email delegation and auto-replies to a real colleague, calendar ownership, and any integrations or API tokens tied to their account. An integration that authenticates as a departed employee is an outage waiting for three weeks' time.
Step 5: Recover devices and company data
Collect the laptop, phone, tokens and keys on or before the final day. Confirm backups and cloud sync are current first, then wipe devices as part of your standard cyber security gap assessment process rather than shelving them unwiped in a cupboard.
Step 6: Update forwarding, mailing lists and door lists
Check for email forwarding rules the leaver may have set — an auto-forward to a personal address that survived into offboarding is a data leak running quietly in the background. Remove them from distribution lists, client mailing aliases, building access and after-hours door codes the same day.
Step 7: Close third-party seats
Count the software subscriptions that bill per seat. Revoke or reassign the leaver's seat in each within 24 hours; most vendors charge for an open seat whether or not anyone uses it, and a paid but unused seat is a dangling account too.
Step 8: Log the record
Write one dated line per action: what was closed, by whom, when, and any exception that could not be completed. When a cyber insurer, an auditor or an acquiring party asks for offboarding evidence in 2026, this log is the document they mean.
What to rotate — the quick table
| Credential type | Action | Owner |
|---|---|---|
| Personal login | Disable, preserve, review in 12 months | IT or office manager |
| Shared logins and vault entries | Rotate password, confirm handover | Department lead |
| MFA enrolment | Revoke enrolled devices | IT or office manager |
| Email forwarding rules | Audit and remove | IT or office manager |
| Per-seat software | Revoke or reassign within 24 hours | Budget holder |
| Physical devices and keys | Recover, back up, then wipe | Office manager |
Special cases
- Contractors and seasonal staff. Use the same sequence on the engagement's last day, not at annual review. Named access, revoked same day.
- Acrimonious exits. Run steps 1 to 4 before the exit conversation where the risk assessment justifies it, and let HR lead the sequencing.
- Long-term leave. Treat extended unpaid leave as a soft offboard: suspend, keep data, revisit on return.
- The owner's own accounts. Founders are the worst-offboarded people in most small businesses. Document your own access list so someone else can close it.
What to avoid
- Deleting the account on the spot. You lose mail, files and the audit trail, and Australian record-keeping rules may still require the history.
- Password-only offboarding. Saved sessions and enrolled MFA devices survive a password change.
- The 4pm Friday offboard. Nobody is left to rotate shared credentials. Schedule closures for a morning when colleagues are online.
- Assuming the payroll system is the only place that matters. The dangerous doors are usually the SaaS logins nobody wrote down.
FAQ
What is a secure employee offboarding checklist? A dated sequence that disables the account, kills sessions and MFA enrolment, rotates shared credentials, transfers ownership, recovers devices and records each action on the employee's final day.
How fast should a departing employee lose access? Within 24 hours of their last day — ideally during it. The 60-minute sequence above fits a normal business morning.
Should we delete or disable a departed employee's mailbox? Disable first, delete later. Suspension closes access while preserving mail and history your record-keeping obligations may require.
Do we need to change passwords the employee knew? Yes — every shared credential they could reach, not just their own login. Session tokens and remembered passwords outlive the account itself.
What about personal devices used for work? Remove work data and app access from personal devices the same day, and record what was removed. Do not factory-reset a personal device without the owner's consent.
Who should own offboarding in a small business? One named person — usually the office manager or an MSP — with HR triggering the checklist. Offboarding fails when everyone assumes someone else did it.
What evidence should we keep? A dated log of each closure action and any exception. Insurers, auditors and procurement checks increasingly ask for it, and it costs nothing to maintain.
One last thing
The cheapest audit of your offboarding process costs nothing: pick a staff member who left in the last six months and try their email address in your systems. What happens next tells you more than any policy document.