When someone leaves a small business, the conversation is usually about the handover of their work, and far less often about the handover of their access. Yet a former employee’s email, shared passwords, bank profile and WhatsApp groups can stay switched on for months, and every one of them is a way into your business that nobody is watching. This guide is an IT offboarding checklist for South African businesses: what to switch off, in what order, what changes when the person is dismissed rather than resigning, how POPIA fits in, and a checklist builder that produces the exact list for the person who is leaving. IT-Support-SA looks after business IT from Pietermaritzburg across KwaZulu-Natal and the rest of South Africa.
The Short Answer
Take away access before you take away the person’s things. Block their sign-in and sign them out everywhere, change the shared passwords they knew, remove them from the bank, then collect the devices, hand over the mailbox and files, and tidy up over the following month. Block first and delete later, so you do not lose anything the business needs. For a resignation, do it at the end of their last day. For a dismissal, do it as the meeting starts. Write down what was done, and keep a register of who has access to what so the next one is easier.
Why Offboarding Is a Security Job, Not Just an HR Job
A working login is a standing invitation. Even a good employee leaving on good terms creates risk, for a few reasons:
- A live account nobody uses is easy to take over. If the former employee’s old password was weak or reused, a criminal who finds it gets into an account that nobody is watching, with a mailbox full of your customers.
- Some leavers take things with them. Not always deliberately: customer lists exported to a personal email, files in a personal cloud account, customers on a personal WhatsApp.
- Some leavers are unhappy. A dismissed or disgruntled employee with live access can delete, copy or change things. Continuing to use a login after the right to it has ended can be an offence under the Cybercrimes Act, but the better outcome is that the login simply no longer works.
- Money moves through these accounts. Bank profiles, accounting software and payment approvals are the highest-stakes access a person can hold.
- Unused licences cost money. A Microsoft 365 licence on a mailbox nobody uses is a monthly cost for nothing.
The pattern is the same as the one behind our guide to invoice fraud and fake banking details emails: a mailbox or account that someone can reach is how the money gets moved. Offboarding closes it.
The Rule: Revoke First, Delete Later
Two habits prevent most offboarding mistakes:
- Block, then transfer, then delete. Block the sign-in and end the sessions immediately, so no one can use the account. Then give a manager access to the mailbox and files and transfer anything the person owned. Only after your retention period should the account be archived or removed. If you delete it first, the mail and documents go with it.
- Remove access in a fixed order. Money and administrator access first, then email and business apps, then devices and physical access, then the tidy-up. The checklist builder below sorts this for you.
Before They Leave: Know What They Have
The hardest part of offboarding is not removing access; it is knowing what there was. Before the last day, build a list:
- Accounts in your own systems. Your email admin shows the person’s sign-ins, the apps they have authorised and any shared mailboxes or groups they belong to.
- Shared logins. Anything the whole team uses with one password: social media, supplier portals, the domain and hosting account, the Wi-Fi.
- Money. Bank profiles, cards, payment approval limits, accounting and payroll software.
- Devices and data. Laptop, phone, external drives, and anything only stored locally. Take a backup before the day. Our guide to cloud backup for South African businesses explains how to make sure important files do not live on one machine.
- Customers. Which customers have their number, and which conversations exist only on their phone.
- Public profiles. Admin rights on Facebook, Instagram, your Google Business Profile and your website. If you rely on reviews, our guide to getting more Google reviews covers why that profile matters, and why it must never depend on one person.
Build Your Offboarding Checklist
Say how the person is leaving and tick what they had access to. The checklist updates as you go, puts things in order and marks the steps that take away access. Use the copy button to paste it into an email or document.
The start-up selection describes a typical resignation: someone with company email, shared passwords, a laptop, a phone, WhatsApp groups and cloud files. Switch the first option to a dismissal and watch the access-removal steps jump to the front, and tick the bank and accounting boxes to see how much heavier the list becomes when money is involved.
Step by Step: What Each Part Involves
Email (Microsoft 365 or Google)
Email is the key to most other accounts, because password resets are sent to it, so it comes first. Block sign-in, sign the person out of all sessions and devices, reset their password and remove their multi-factor methods. Then give their manager access, or set an automatic reply that points customers to a named person. A week later, check the sign-in log and look for forwarding rules that send a copy of mail to a personal address, which is a common way for a leaver to keep seeing business email. After your retention period, convert the mailbox to a shared mailbox or archive it, and release the licence. The licence you choose affects what you can do here, which our comparison of Microsoft 365 Business Premium and Standard explains.
Shared passwords
Anything they could log into with a password they were told is now a password they know. Change every one, starting with email, banking, domain and admin accounts. If the answer to “which passwords did they know?” is “all of them”, that is the real finding: a team that shares one login cannot offboard anyone cleanly. The fix is a password manager and a login per person, so removing someone means removing one account, not changing everything.
Devices
Collect the laptop, charger and accessories and tick them off against your asset register. Do not hand the machine to the next person as it is: wipe and reinstall it, because deleting a user profile leaves software, saved passwords and files behind. Our guide to OS reinstall and storage upgrades explains what a clean reinstall involves. If they used a personal phone for work, remove company email and apps, or wipe the work profile if you manage it.
WhatsApp and customer chats
This is a gap many South African businesses overlook. Customers save a person’s number, not the business’s, so when the person leaves, the relationship can leave with them. Remove them from business groups, make sure every group has another admin, move customer conversations to a number the company controls and tell those customers who their new contact is. If conversations are on a personal phone, work with the employee and agree in writing which chats are business records. You cannot remove chats from a phone you do not control, which is the argument for running customer chats on a business number from the start.
Money: bank, accounting and payments
Phone your bank to remove the person from your online profile and cancel their cards and approval limits. Telling the person is not enough, because the bank needs its own instruction. Disable their accounting and payroll logins, and look back over the last 30 days for new suppliers, changed banking details and unusual payments. This is where an unhappy leaver can do the most damage, and where a criminal with a stolen login will head first.
Public profiles, remote access and the building
Before you remove anyone as an admin on Facebook, Instagram, Google Business Profile, your website or your hosting and domain, make sure two other people are admins. Disable their VPN and remote access. Collect keys, access cards and tags and change the alarm code.
Resignation vs Dismissal: What Changes
The steps are the same; the timing is not.
- Resignation or contract ending. You have notice. Use it to audit access, back up their files and arrange the handover of customers. Switch access off at the end of the last day.
- Dismissal or immediate exit. Prepare in advance, then remove access as the meeting starts, before the person is told. If they walk out and still have a working login, that is the window you are trying to avoid. Follow your disciplinary process and take labour-law advice before acting; the checklist covers the IT side only.
In both cases, tell whoever manages your IT the exact date and time in advance, so the change happens when it should and not whenever someone remembers.
POPIA and the Law
Your obligations under POPIA do not end when someone leaves. Section 19 requires a responsible party to take appropriate, reasonable measures to secure the integrity and confidentiality of the personal information it holds, and a former employee with a live login to customer data is hard to defend as reasonable. If you discover that a former employee has accessed personal information they had no right to, treat it as a possible security compromise and follow the notification steps in Section 22. Our POPIA IT compliance checklist covers the wider duties, including keeping a record of who can reach personal information, which is exactly what an access register is.
Offboarding is also a good moment to confirm in writing, as part of the exit conversation, that company and customer information stays with the business. It is a reminder, not a substitute for the technical steps.
If You Think Something Was Missed
If you find an account still open, or something unusual after the person left:
- Block and secure it first. Change the password, end sessions, remove multi-factor methods you did not set up.
- Check the logs. Look at recent sign-ins, new forwarding rules, newly authorised apps and files shared outside the business.
- Check the money. Review recent payments and any beneficiaries added.
- Decide whether it is a data incident. If personal information may have been accessed, see Section 22 and our POPIA checklist.
- Keep a record of what you found and what you did.
If you suspect the account has been used by someone else, our guide to ransomware protection explains the wider signs that an attacker is already in.
Make It Routine
An offboarding that works is one you never have to improvise. Four habits make it routine:
- One login per person. Never share a login, and then removing someone is one account.
- An access register. One row per person: what they can reach and who approved it. A spreadsheet is enough.
- A checklist you use every time, kept next to the HR paperwork, including for contractors and interns.
- Use the same discipline when people join or change roles. Giving the right access on day one, and removing the old access when someone moves jobs, keeps the register honest.
How IT-Support-SA Can Help
We can run the technical side of offboarding for you: blocking and securing accounts at the agreed time, handing over mailboxes and files, changing shared passwords, wiping and reissuing devices, and setting up a password manager and an access register so the next departure is a ten-minute job. If you are not sure what a leaver could still reach, we can audit your accounts and tell you. Contact IT-Support-SA for support across Pietermaritzburg, the KZN Midlands, Durban, Ladysmith, Johannesburg, Cape Town and all 9 provinces of South Africa.
Mistakes That Leave the Door Open
- Offboarding at the end of the month instead of on the day the person leaves.
- Deleting the account first and losing the mail and files.
- Telling the person instead of telling the bank.
- Forgetting forwarding rules, so mail keeps going to a personal address.
- Sharing one login, so removing a person means changing everything.
- Customer chats on a personal phone and no plan for them.
- Being the only admin, or the person leaving being the only admin, on a social page or the domain.
- Having no record of who had access, so nobody can say what was closed.
Conclusion
Offboarding is one of the cheapest security wins a business has: a short, ordered list, done on the right day, with a record of what was done. Block access before you collect the laptop, change the shared passwords, tell the bank, hand over the mailbox and customers, and keep an access register so you are never guessing. Do it the same way for every leaver, and a person walking out the door stops being a risk to your systems.
If you would like help with an offboarding today, or want your accounts set up so future ones are simple, get in touch with IT-Support-SA or WhatsApp us.