Collective

Employee Offboarding Checklist: What to Close When Someone Leaves

Photo by Brooke Cagle on Unsplash

An employee offboarding checklist lists every system a departing staff member had access to, so nothing stays open after their last shift. It covers email, point of sale, rosters, payroll, social media, building access and devices. Working through it takes about fifteen minutes per person and closes one of the most common ways small businesses get compromised.

Key Takeaways

  • Write the checklist once and reuse it. Offboarding fails because it is improvised each time, not because it is difficult.
  • Email is only the first item. POS PINs, rosters, payroll, social media, door codes and devices all need closing too.
  • The account is the risk, not the person. A login nobody watches can be used for months before anyone notices.
  • Shared logins are the harder problem. If eight people use one password, it never gets changed when one of them leaves.
  • More small businesses now have privacy duties. From 1 July 2026, anti-money laundering reforms brought conveyancers, accountants, real estate agents and lawyers under the Privacy Act.

Seasonal businesses feel this hardest. Take on eight casuals in November and lose them by March, and that is eight sets of credentials created in a hurry and rarely closed with the same urgency.

What Is Employee Offboarding?

Employee offboarding is the process of closing out someone’s employment, including returning equipment, finalising pay and removing their access to company systems.

This article covers the access part, which is the piece most small businesses skip. Payroll and equipment usually get handled because someone chases them. Logins do not, because nobody is chasing.

The Employee Offboarding Checklist

Work through every system they were given, not just their email. Write it down once, then reuse it every time.

  • Email and main account. Disable it rather than deleting it, so files are not lost, then remove the licence you pay for.
  • Point of sale. Staff PINs and manager overrides are separate from email and get forgotten most often.
  • Roster and payroll apps. Usually another separate login.
  • Social media. Check whether they were added as a user or simply given the password.
  • Building access. Alarm codes, door fobs, the key safe.
  • Shared drives and cloud storage. Including anything shared to a personal email address.
  • Devices. Company gear that went home, and any personal phone with a saved login.
  • Third-party tools. Booking systems, delivery platforms, supplier portals and anything signed up for with a work email.

Do it on their last day rather than when things quieten down. Then review access every quarter. That review usually turns up two or three accounts nobody can explain.

Why Does an Old Account Matter After Someone Leaves?

Because the risk sits with the account, not the person.

A dormant login is a door nobody watches. No one checks it. No one notices a sign-in from somewhere odd. Nothing gets spotted until something visible breaks.

Most people reuse passwords. If that staff member used the same one on a site that was later breached, their credentials are circulating now, whatever they intended.

Compromised accounts and credentials were among the three most common features of the incidents the Australian Signals Directorate responded to in 2024-25, alongside compromised infrastructure and ransomware. The average self-reported cost of a cybercrime report for a small business was AUD 56,600, up 14% on the year before.

There is a quieter version too. Human error caused 37% of the data breaches reported to the Office of the Australian Information Commissioner between January and June 2025, up from 29% in the six months before.

How Do You Handle Logins Everyone Shares?

Give people their own logins wherever the system allows it, and put any genuinely shared password in a password manager.

Plenty of small businesses run one account for the POS, the booking system or Instagram. It is quicker than setting up eight.

The catch comes at the other end. When one person leaves, the password has to change for everyone. So it never changes at all.

Individual logins fix that, because you can switch off one person without disrupting the rest. Where a shared account cannot be avoided, keep the password somewhere you can update in one place, not in a group chat or on a card taped under the till.

Is Multi-Factor Authentication Enough on Its Own?

No. It is the most useful single control you can turn on, but it does not replace closing accounts.

Multi-factor authentication means a password alone will not get someone in. A second check is needed, usually a prompt on a phone. If an old password leaks, that step is what stops it working.

The gap is whose phone. The second factor often still sits with the person who left. The account is protected, but it is protected by someone who no longer works for you. The Australian Cyber Security Centre publishes a free small business guide covering this and the other basics.

Do Small Businesses Have Privacy Obligations in Australia?

More do than a year ago, and the change caught a lot of people by surprise.

Businesses turning over AUD 3 million or less have been exempt from the Privacy Act since 2001. That exemption still stands. Removal has been recommended, and the government says it is progressing a second tranche of reforms, but no Bill has been introduced. Anyone saying the exemption has gone is wrong.

What changed is the edges. From 1 July 2026, anti-money laundering reforms brought more than 100,000 small businesses under the Privacy Act for their AML-related data, whatever their turnover. That includes conveyancers, accountants, real estate agents, lawyers and dealers in precious metals.

Older carve-outs still apply. Health service providers and businesses that trade in personal information have never been exempt. Neither has any business whose turnover has passed AUD 3 million in any year since the rule began, even if it earns less now.

If you are covered, the Notifiable Data Breaches scheme means telling both the regulator and the affected people when a breach is likely to cause serious harm. The OAIC publishes guidance on who the scheme catches.

Who Should Own Offboarding in a Small Business?

One named person, with the written checklist they complete every time.

For a team of five to fifty, that means the same person closes accounts on every departure, rather than whoever is free that week. Consistency is what stops accounts slipping through.

Businesses that would rather not run this themselves hand it to an external provider along with the rest of their systems. Firms such as Kloudify handle account setup and removal as part of ongoing IT support for small businesses, which mostly means someone whose job it is runs the checklist instead of an owner at 9pm.

The Bottom Line

An employee offboarding checklist is the cheapest security work a small business can do, and the most commonly skipped. Give one person the job, write the list down, close accounts on the last day, and review access quarterly. Then run the test: pick the last person who left and try their email login. If you cannot remember whether it was closed, you already have your answer.

FAQ

What should be on an employee offboarding checklist?

Email and the main account, point of sale PINs, roster and payroll apps, social media, building access, shared drives and cloud storage, company devices, and any third-party tool they signed up for with a work email. Close all of them on the employee’s last day.

How long should we keep a former employee’s email account?

Disable it immediately, then keep it disabled rather than deleting it for as long as you may need the files or messages inside. Disabling blocks access straight away. Deleting can take data with it and can break shared documents the account owned.

Does multi-factor authentication stop a former employee logging in?

Not by itself. If the second factor is still their phone, they can pass the check. Multi-factor authentication protects against a stolen password from outside. Closing the account is what removes access from someone who used to hold it.

Do small businesses have to report a data breach in Australia?

Only if the Privacy Act applies to them. Many businesses under AUD 3 million turnover are still exempt, but health service providers, businesses that trade in personal information, and since 1 July 2026 conveyancers, accountants, real estate agents and lawyers are covered regardless of turnover.

What is the first thing to do when a staff member finishes?

Disable their main account the same day. That single step closes email, and in most cloud systems it closes anything signed in through that account too. Then work through the rest of the checklist.

Picture of Gold Coast Magazine
Gold Coast Magazine

Our in-house team and affiliates bringing you the latest in Culture, Lifestyle and Entertainment from around the globe and the great stories of the Gold Coast