Preventing data leaks when an employee leaves requires a coordinated offboarding process that removes access, preserves company information, recovers company assets, and verifies that no unnecessary access remains.
A secure offboarding process should account for the employee's primary identity, email, cloud applications, shared files, remote access, administrative privileges, company devices, vendor portals, physical access, and any shared credentials or delegated permissions.
The timing of access removal should be coordinated with HR and management based on the circumstances of the departure and the organization's risk.
Businesses should also preserve and transfer company-owned information before accounts are deleted, review appropriate security activity when risk warrants it, and document that required offboarding steps were completed.
The objective is not simply to disable one user account. It is to make sure access, data, devices, ownership, and responsibilities are handled consistently across the employee's entire technology footprint.
- 1. Why Can Employee Offboarding Create Data-Leak Risk?
- 2. What Access Should Be Removed When an Employee Leaves?
- 3. How Should Company Data Be Preserved During Offboarding?
- 4. What Security Activity May Warrant Review Around a Departure?
- 5. What Should an Employee IT Offboarding Checklist Include?
- 6. Secure Offboarding Is Part of the Access Lifecycle
- 7. Build a More Consistent Employee Access Process
- 8. Frequently Asked Questions About Secure Employee Offboarding
- 9. Related Articles
Why Can Employee Offboarding Create Data-Leak Risk?
Employees often accumulate access across multiple systems during their time with an organization. That may include email, cloud storage, line-of-business applications, shared folders, remote-access tools, vendor portals, mobile devices, administrative systems, and physical facilities.
When an employee leaves, risk can remain if any part of that access or data footprint is overlooked.
Common offboarding gaps include:
- Lingering accounts or sessions: Access remains active in an application, cloud service, VPN, or device after the employee leaves.
- Unmanaged company data: Files, email, records, or intellectual property remain tied to an employee account without clear ownership or retention.
- Excessive or shared access: Administrative privileges, shared credentials, delegated mailboxes, API tokens, or service accounts are not reviewed.
- Cloud sharing and synchronization: Company information remains accessible through external sharing, personal devices, synchronized folders, or authorized third-party applications.
- Unreturned assets: Laptops, mobile devices, security tokens, keys, badges, or other company property are not accounted for.
- Missed applications or vendors: IT disables the primary account but overlooks separate SaaS platforms, vendor portals, communication tools, or specialized business applications.
A structured offboarding process reduces these gaps by treating employee departure as an access-lifecycle event rather than a single account-deactivation task.

What Access Should Be Removed When an Employee Leaves?
Offboarding should cover the employee's entire access footprint rather than only the primary email or computer account.
Review and address, as applicable:
- Primary identity accounts such as Microsoft Entra ID, Active Directory, or Google Workspace
- Email, active sessions, delegated mailbox access, forwarding rules, and application passwords
- Multi-factor authentication methods and account-recovery options
- VPN, remote desktop, remote support, and other remote-access services
- Single sign-on and connected SaaS applications
- Administrative and privileged accounts
- Shared folders, cloud storage, collaboration platforms, and external file-sharing permissions
- CRM, ERP, EHR, accounting, practice-management, and other line-of-business applications
- Vendor, partner, and customer portals
- Phone, messaging, and unified-communications platforms
- Company-owned computers and mobile devices
- API tokens, OAuth grants, service accounts, or integrations associated with the user
- Shared passwords or secrets the departing employee knew
- Physical badges, keys, security tokens, and facility access
The timing of access removal should be defined by the organization and coordinated with HR and management. For some departures, access may be disabled at the effective time of separation; higher-risk situations may warrant tighter coordination before the employee is notified.
NIST SP 800-53 personnel-termination guidance provides a useful reference point for disabling system access, revoking credentials, retrieving organizational property, and preserving access to company information after employment ends.
Is employee access being managed consistently from onboarding through offboarding?
Managed IT creates ongoing ownership for user access, devices, documentation, vendor coordination, support, and the technology changes that occur throughout the employee lifecycle.
How Should Company Data Be Preserved During Offboarding?
Access should not be removed without first considering what company-owned information the employee controls or has created.
Before permanently deleting accounts or data, identify what needs to be preserved, transferred, retained, or reassigned. This may include:
- Business email and calendars
- OneDrive, Google Drive, SharePoint, or other cloud files
- Shared-folder ownership and permissions
- CRM or customer records
- Project documentation
- Financial or operational records
- Intellectual property and work product
- Voicemail, messaging, or collaboration content where appropriate
- Application data owned by or assigned to the departing user
Ownership should be transferred to the appropriate manager, department, shared workspace, or organizational account before the former employee's account is permanently removed.
Retention requirements depend on the organization's legal, contractual, regulatory, operational, and records-management obligations. IT should follow the organization's approved retention requirements rather than setting arbitrary retention periods.
Backup and recovery also matter, but they serve a different purpose: they help the organization recover information if data is accidentally or intentionally deleted or altered. They should complement, not replace, proper access control and offboarding procedures.

What Security Activity May Warrant Review Around a Departure?
When circumstances indicate elevated risk, organizations may review authorized security telemetry for activity that could affect company data or systems.
Depending on the organization's tools, policies, environment, and legal requirements, relevant indicators may include:
- Unusual bulk downloads or exports
- Large numbers of files copied, moved, deleted, or externally shared
- New external sharing links or unusual permission changes
- New mailbox forwarding or delegation rules
- Unexpected OAuth application grants or connected cloud applications
- Privileged-role or administrative-access changes
- Unusual remote-access or authentication activity
- Attempts to disable security controls
- Use of removable storage where monitoring is authorized and supported
- Significant changes to sensitive data outside the employee's normal work pattern
These indicators do not automatically prove malicious activity. They provide context that may warrant review by the appropriate IT, security, HR, management, or legal resources.
Monitoring should be authorized, documented, proportionate to the risk, and consistent with applicable law and organizational policy. CISA's insider-threat guidance similarly emphasizes a multidisciplinary approach that can involve security, HR, management, legal, and other organizational functions rather than treating insider risk solely as a technical monitoring problem.
Need stronger visibility into identity, endpoint, and security activity?
See how thirtyone3 technology combines layered safeguards, identity protection, managed detection, and ongoing security oversight to reduce cyber risk.
What Should an Employee IT Offboarding Checklist Include?
A repeatable checklist helps HR, management, and IT coordinate the departure and reduces the chance that an account, device, application, or data responsibility is missed.
Offboarding Checklist:
1. Confirm the separation details.
Establish the employee's effective departure time, manager, circumstances requiring special handling, and who is authorized to initiate the offboarding process.
2. Inventory access and company assets.
Identify accounts, applications, administrative privileges, remote access, devices, security tokens, keys, badges, vendor portals, and other resources assigned to the employee.
3. Preserve and transfer company information.
Determine which email, files, records, application data, ownership, and business communications need to be retained or reassigned before accounts are deleted.
4. Disable identity and remote access.
Disable the appropriate primary accounts and sessions according to the approved timing. Revoke VPN, remote access, authentication methods, and other access paths.
5. Remove application and third-party access.
Address SaaS platforms, cloud services, vendor portals, shared folders, delegated permissions, external sharing, OAuth applications, and other access not automatically removed through the primary identity system.
6. Recover and secure company assets.
Retrieve company-owned devices, tokens, keys, badges, and other property. Devices should be secured, preserved, reassigned, or wiped according to organizational policy and business requirements.
7. Review shared access and integrations.
Change shared credentials where necessary and review service accounts, API tokens, mailbox delegation, forwarding rules, application ownership, and integrations associated with the departing employee.
8. Verify and document completion.
Confirm required actions were completed, record exceptions or follow-up work, and ensure the appropriate people retain access to necessary company records.
Who Should Own Employee Offboarding?
Secure offboarding is a shared business process rather than an IT-only task.
- HR or management should communicate the authorized departure details and timing.
- IT should address accounts, applications, devices, access, data ownership, and technical documentation.
- Managers should identify business records, application ownership, project responsibilities, and access that needs to be transferred.
- Security, compliance, or legal resources may need to participate when risk, contractual obligations, regulated information, litigation holds, investigations, or other special circumstances apply.
The most important control is a defined handoff: IT should not have to discover an employee has left after the departure has already occurred.

Secure Offboarding Is Part of the Access Lifecycle
Preventing data leaks when employees leave is not accomplished by disabling one account or purchasing one security tool. It requires a repeatable process that connects people, access, applications, devices, data ownership, and documentation.
The strongest approach begins before an employee departs. Organizations should maintain accurate access records, apply appropriate privileges, know where important business information resides, and define how HR, management, and IT will coordinate when a workforce change occurs.
When offboarding is treated as part of the full employee access lifecycle, from onboarding through role changes and eventual departure, businesses are better positioned to reduce lingering access, preserve company information, and maintain operational continuity.
Build a More Consistent Employee Access Process
If your organization is unsure whether onboarding, role changes, and employee departures are being handled consistently across accounts, devices, applications, and company data, thirtyone3 technology can help evaluate the current process and identify practical next steps.

