Cybersecurity

Employee Offboarding: The IT Checklist for South African Businesses When Someone Leaves

IT-Support-SA Team 11 min read
In this article
  1. 01 The Short Answer
  2. 02 Why Offboarding Is a Security Job, Not Just an HR Job
  3. 03 The Rule: Revoke First, Delete Later
  4. 04 Before They Leave: Know What They Have
  5. 05 Build Your Offboarding Checklist
  6. 06 Step by Step: What Each Part Involves
  7. 07 Resignation vs Dismissal: What Changes
  8. 08 POPIA and the Law
  9. 09 If You Think Something Was Missed
  10. 10 Make It Routine
  11. 11 How IT-Support-SA Can Help
  12. 12 Mistakes That Leave the Door Open
  13. 13 Conclusion

When someone leaves a small business, the conversation is usually about the handover of their work, and far less often about the handover of their access. Yet a former employee’s email, shared passwords, bank profile and WhatsApp groups can stay switched on for months, and every one of them is a way into your business that nobody is watching. This guide is an IT offboarding checklist for South African businesses: what to switch off, in what order, what changes when the person is dismissed rather than resigning, how POPIA fits in, and a checklist builder that produces the exact list for the person who is leaving. IT-Support-SA looks after business IT from Pietermaritzburg across KwaZulu-Natal and the rest of South Africa.

The Short Answer

Take away access before you take away the person’s things. Block their sign-in and sign them out everywhere, change the shared passwords they knew, remove them from the bank, then collect the devices, hand over the mailbox and files, and tidy up over the following month. Block first and delete later, so you do not lose anything the business needs. For a resignation, do it at the end of their last day. For a dismissal, do it as the meeting starts. Write down what was done, and keep a register of who has access to what so the next one is easier.

Why Offboarding Is a Security Job, Not Just an HR Job

A working login is a standing invitation. Even a good employee leaving on good terms creates risk, for a few reasons:

  • A live account nobody uses is easy to take over. If the former employee’s old password was weak or reused, a criminal who finds it gets into an account that nobody is watching, with a mailbox full of your customers.
  • Some leavers take things with them. Not always deliberately: customer lists exported to a personal email, files in a personal cloud account, customers on a personal WhatsApp.
  • Some leavers are unhappy. A dismissed or disgruntled employee with live access can delete, copy or change things. Continuing to use a login after the right to it has ended can be an offence under the Cybercrimes Act, but the better outcome is that the login simply no longer works.
  • Money moves through these accounts. Bank profiles, accounting software and payment approvals are the highest-stakes access a person can hold.
  • Unused licences cost money. A Microsoft 365 licence on a mailbox nobody uses is a monthly cost for nothing.

The pattern is the same as the one behind our guide to invoice fraud and fake banking details emails: a mailbox or account that someone can reach is how the money gets moved. Offboarding closes it.

The Rule: Revoke First, Delete Later

Two habits prevent most offboarding mistakes:

  1. Block, then transfer, then delete. Block the sign-in and end the sessions immediately, so no one can use the account. Then give a manager access to the mailbox and files and transfer anything the person owned. Only after your retention period should the account be archived or removed. If you delete it first, the mail and documents go with it.
  2. Remove access in a fixed order. Money and administrator access first, then email and business apps, then devices and physical access, then the tidy-up. The checklist builder below sorts this for you.

Before They Leave: Know What They Have

The hardest part of offboarding is not removing access; it is knowing what there was. Before the last day, build a list:

  • Accounts in your own systems. Your email admin shows the person’s sign-ins, the apps they have authorised and any shared mailboxes or groups they belong to.
  • Shared logins. Anything the whole team uses with one password: social media, supplier portals, the domain and hosting account, the Wi-Fi.
  • Money. Bank profiles, cards, payment approval limits, accounting and payroll software.
  • Devices and data. Laptop, phone, external drives, and anything only stored locally. Take a backup before the day. Our guide to cloud backup for South African businesses explains how to make sure important files do not live on one machine.
  • Customers. Which customers have their number, and which conversations exist only on their phone.
  • Public profiles. Admin rights on Facebook, Instagram, your Google Business Profile and your website. If you rely on reviews, our guide to getting more Google reviews covers why that profile matters, and why it must never depend on one person.

Build Your Offboarding Checklist

Say how the person is leaving and tick what they had access to. The checklist updates as you go, puts things in order and marks the steps that take away access. Use the copy button to paste it into an email or document.

INTERACTIVE CHECKLIST
Build your offboarding checklist
Say how they are leaving and what they had access to. You get a checklist in the right order, ready to copy.
How are they leaving?
What did they have access to?
21 steps · 6 take away access
DURING THE NOTICE PERIOD
  • List what is tied to their mailbox: shared folders, mailing-list admin, calendar invites and any accounts registered to their email address.
  • Back up their files so nothing important lives only on that machine.
  • Tell whoever manages your IT the exact date and time, so access is removed when it should be.
  • Remind them in writing that company and customer information stays with the business, and agree what must be returned.
ON THEIR LAST DAY
  • Block their email sign-in and sign them out of every device and session. Do not delete the account yet. REMOVES ACCESS
  • Reset their password and remove their multi-factor sign-in methods. REMOVES ACCESS
  • Give their manager access to the mailbox, or set an automatic reply that points customers to a named person.
  • Change every shared password they knew, starting with email, banking, domain and admin accounts. REMOVES ACCESS
  • Collect the laptop, charger and accessories, and tick them off against your asset register.
  • Remove company email and apps from their phone, or remote-wipe the work profile if you manage it. REMOVES ACCESS
  • Remove them from business WhatsApp groups and make sure each group has another admin. REMOVES ACCESS
  • Remove their access to shared drives and folders, and stop any personal-link sharing they set up. REMOVES ACCESS
  • Write down what was closed, when and by whom, so you have a record if you ever need it.
IN THE WEEK AFTER
  • Check sign-in logs and mail forwarding rules for anything unusual, such as mail being forwarded to a personal address.
  • Remove them from your password manager and check which accounts they could reach.
  • Wipe and reinstall the machine before it is reissued. Deleting the user profile is not enough.
  • Collect the phone and SIM if they are company-owned, and move any business number or airtime contract that was in their name.
  • Move any customer conversations held on a personal WhatsApp to your business number, and tell those customers who their new contact is.
  • Transfer ownership of files they own, so nothing disappears when the account is later deleted.
WITHIN 30 DAYS
  • Convert the mailbox to a shared mailbox or archive it, and release the licence once your retention period has passed.
  • Update your list of who has access to what, including who can reach customers’ personal information.

The start-up selection describes a typical resignation: someone with company email, shared passwords, a laptop, a phone, WhatsApp groups and cloud files. Switch the first option to a dismissal and watch the access-removal steps jump to the front, and tick the bank and accounting boxes to see how much heavier the list becomes when money is involved.

Step by Step: What Each Part Involves

Email (Microsoft 365 or Google)

Email is the key to most other accounts, because password resets are sent to it, so it comes first. Block sign-in, sign the person out of all sessions and devices, reset their password and remove their multi-factor methods. Then give their manager access, or set an automatic reply that points customers to a named person. A week later, check the sign-in log and look for forwarding rules that send a copy of mail to a personal address, which is a common way for a leaver to keep seeing business email. After your retention period, convert the mailbox to a shared mailbox or archive it, and release the licence. The licence you choose affects what you can do here, which our comparison of Microsoft 365 Business Premium and Standard explains.

Shared passwords

Anything they could log into with a password they were told is now a password they know. Change every one, starting with email, banking, domain and admin accounts. If the answer to “which passwords did they know?” is “all of them”, that is the real finding: a team that shares one login cannot offboard anyone cleanly. The fix is a password manager and a login per person, so removing someone means removing one account, not changing everything.

Devices

Collect the laptop, charger and accessories and tick them off against your asset register. Do not hand the machine to the next person as it is: wipe and reinstall it, because deleting a user profile leaves software, saved passwords and files behind. Our guide to OS reinstall and storage upgrades explains what a clean reinstall involves. If they used a personal phone for work, remove company email and apps, or wipe the work profile if you manage it.

WhatsApp and customer chats

This is a gap many South African businesses overlook. Customers save a person’s number, not the business’s, so when the person leaves, the relationship can leave with them. Remove them from business groups, make sure every group has another admin, move customer conversations to a number the company controls and tell those customers who their new contact is. If conversations are on a personal phone, work with the employee and agree in writing which chats are business records. You cannot remove chats from a phone you do not control, which is the argument for running customer chats on a business number from the start.

Money: bank, accounting and payments

Phone your bank to remove the person from your online profile and cancel their cards and approval limits. Telling the person is not enough, because the bank needs its own instruction. Disable their accounting and payroll logins, and look back over the last 30 days for new suppliers, changed banking details and unusual payments. This is where an unhappy leaver can do the most damage, and where a criminal with a stolen login will head first.

Public profiles, remote access and the building

Before you remove anyone as an admin on Facebook, Instagram, Google Business Profile, your website or your hosting and domain, make sure two other people are admins. Disable their VPN and remote access. Collect keys, access cards and tags and change the alarm code.

Resignation vs Dismissal: What Changes

The steps are the same; the timing is not.

  • Resignation or contract ending. You have notice. Use it to audit access, back up their files and arrange the handover of customers. Switch access off at the end of the last day.
  • Dismissal or immediate exit. Prepare in advance, then remove access as the meeting starts, before the person is told. If they walk out and still have a working login, that is the window you are trying to avoid. Follow your disciplinary process and take labour-law advice before acting; the checklist covers the IT side only.

In both cases, tell whoever manages your IT the exact date and time in advance, so the change happens when it should and not whenever someone remembers.

POPIA and the Law

Your obligations under POPIA do not end when someone leaves. Section 19 requires a responsible party to take appropriate, reasonable measures to secure the integrity and confidentiality of the personal information it holds, and a former employee with a live login to customer data is hard to defend as reasonable. If you discover that a former employee has accessed personal information they had no right to, treat it as a possible security compromise and follow the notification steps in Section 22. Our POPIA IT compliance checklist covers the wider duties, including keeping a record of who can reach personal information, which is exactly what an access register is.

Offboarding is also a good moment to confirm in writing, as part of the exit conversation, that company and customer information stays with the business. It is a reminder, not a substitute for the technical steps.

If You Think Something Was Missed

If you find an account still open, or something unusual after the person left:

  1. Block and secure it first. Change the password, end sessions, remove multi-factor methods you did not set up.
  2. Check the logs. Look at recent sign-ins, new forwarding rules, newly authorised apps and files shared outside the business.
  3. Check the money. Review recent payments and any beneficiaries added.
  4. Decide whether it is a data incident. If personal information may have been accessed, see Section 22 and our POPIA checklist.
  5. Keep a record of what you found and what you did.

If you suspect the account has been used by someone else, our guide to ransomware protection explains the wider signs that an attacker is already in.

Make It Routine

An offboarding that works is one you never have to improvise. Four habits make it routine:

  • One login per person. Never share a login, and then removing someone is one account.
  • An access register. One row per person: what they can reach and who approved it. A spreadsheet is enough.
  • A checklist you use every time, kept next to the HR paperwork, including for contractors and interns.
  • Use the same discipline when people join or change roles. Giving the right access on day one, and removing the old access when someone moves jobs, keeps the register honest.

How IT-Support-SA Can Help

We can run the technical side of offboarding for you: blocking and securing accounts at the agreed time, handing over mailboxes and files, changing shared passwords, wiping and reissuing devices, and setting up a password manager and an access register so the next departure is a ten-minute job. If you are not sure what a leaver could still reach, we can audit your accounts and tell you. Contact IT-Support-SA for support across Pietermaritzburg, the KZN Midlands, Durban, Ladysmith, Johannesburg, Cape Town and all 9 provinces of South Africa.

Mistakes That Leave the Door Open

  • Offboarding at the end of the month instead of on the day the person leaves.
  • Deleting the account first and losing the mail and files.
  • Telling the person instead of telling the bank.
  • Forgetting forwarding rules, so mail keeps going to a personal address.
  • Sharing one login, so removing a person means changing everything.
  • Customer chats on a personal phone and no plan for them.
  • Being the only admin, or the person leaving being the only admin, on a social page or the domain.
  • Having no record of who had access, so nobody can say what was closed.

Conclusion

Offboarding is one of the cheapest security wins a business has: a short, ordered list, done on the right day, with a record of what was done. Block access before you collect the laptop, change the shared passwords, tell the bank, hand over the mailbox and customers, and keep an access register so you are never guessing. Do it the same way for every leaver, and a person walking out the door stops being a risk to your systems.

If you would like help with an offboarding today, or want your accounts set up so future ones are simple, get in touch with IT-Support-SA or WhatsApp us.

Frequently Asked Questions

What is an IT offboarding checklist?
It is the list of things to switch off, collect and hand over when someone leaves your business: their email and sign-ins, shared passwords, devices, access to files and business apps, bank and payment access, social media and website admin rights, and physical keys and cards. Done in the right order, it stops a former employee keeping a way into your systems and keeps the business's information with the business.
When should I remove a departing employee's access?
It depends on how they are leaving. For a resignation, remove access at the end of their last working day and prepare during the notice period. For a dismissal or an abrupt exit, remove access as the meeting starts, before the person is told, so there is no window to copy files or change anything. Whichever applies, tell whoever manages your IT the exact date and time in advance.
Should I delete a former employee's Microsoft 365 account?
Not straight away. First block sign-in and sign them out of all devices, then give a manager access to their mailbox and files, then convert or archive the mailbox once your retention period has passed. Deleting the account too early can lose email and documents the business needs, although by default a deleted Microsoft 365 account can usually be restored for around 30 days, so check your own settings.
What happens to a former employee's email?
Decide before they leave. The usual choices are to give their manager access to the mailbox, set an automatic reply pointing customers to a named person, or convert it into a shared mailbox that the team can use. The mailbox is a business record, so keep it for as long as your retention rules require, and check for mail forwarding rules that send copies to a personal address.
Is a former employee still having access to customer data a POPIA problem?
It can be. POPIA requires a responsible party to secure the personal information it holds, and a departed employee with a working login is a gap in that security. If you find that a former employee has accessed customer information they should not have, treat it as a possible security compromise and follow the notification steps in Section 22 of POPIA. Prompt offboarding is the simplest way to avoid reaching that point.
What should I do about WhatsApp chats when an employee leaves with customer conversations on their phone?
Prevention is best: run customer conversations on a business number the company controls, not on a personal phone. If conversations are already on a personal phone, agree in writing which chats are business records, move the relationships to your business number, tell the customers who their new contact is, and remove the person from business groups. Work with the employee, because you cannot remove chats from a phone you do not control.
What if I do not know every account an employee had?
Start with what you can see: your email admin's list of apps and sign-ins, your password manager, your accounting and bank profiles, and the accounts registered to their company email address. Then ask the employee and their manager. Going forward, keep a simple access register with one row per person, so you are never guessing. A short audit of the mailbox's recent sign-ins and the apps it has authorised often reveals accounts you forgot about.

Need help with your IT?

Get a free IT audit from South Africa's trusted IT partner — no obligation, no jargon, just straight answers.

Related Articles