By the time an employee hands in their notice, the decisions that will make their departure clean or complicated, at least as far as IT goes, have probably already been made. They were made when the person started and there were a dozen things going on. A few weeks pass and that's that - the planned cleanup never happens.
A clean offboarding takes about 90 minutes for IT, even less with good automation and processes. It starts with the users account getting disabled and sessions revoked, then their devices are wiped or collected, email is either forwarded or mailbox access is provided to the replacement. Projects and client accounts get reassigned, and the work continues.
The messy version of that same process can take three weeks. It starts with a compiling a list of all the tools that users might have had access to by either asking the departing employee to name things off or asking their teammates after they're gone. Hopefully nothing is forgotten and left open to a disgruntled employee logging back in afterwards. If they connected a personal device at some point, they might have forgotten they still have access there.
When someone signs up for a tool on their own using their work email and password, that account is functionally theirs. It can't be reset without notifying them, it might get charged quietly to a company card, others might not even know about it until the account goes dark after they leave and something breaks.
Personal devices used for work rarely stay temporary. Apps get installed and files start syncing, and the temporary fix becomes the permanent setup. When that employee leaves, there's no way to wipe company data from a device the business doesn't own and can't get their hands on. The business ends up relying on the honor system, which hopefully holds up.
Shared credentials cause the most damage at offboarding. When several people use the same login for a tool, nobody can remove one person's access without changing the password for everyone. This usually surfaces at the worst possible time, when the person leaving is the one who originally set up the account and nobody else remembers the password at all.
This shows up most often in firms where staff manage ongoing client relationships. When the person managing that relationship leaves, the email history and the half-finished threads go with them. From the client's side, the business no longer seems to know who they are. The fix is a shared inbox or even better, a CRM platform where client communication gets logged, so the relationship belongs to the business, not the employee.
Most businesses don't need to re-onboard everyone, but a great start to solving this issue is auditing what's in place and closing the gaps before the next departure.
Pull three months of statements from every card used for business expenses and list every recurring charge. For each one, note who set it up, who has the login, whether it uses a personal or company email, and whether anyone else could access it if that person left tomorrow. This usually turns up tools nobody remembers signing up for, and subscriptions still being paid for an employee who's already gone.
Build a simple list of who has what, when each device was issued, whether it's enrolled in a management system, and what company data it can reach. Ask each staff member to confirm what they actually use for work, including personal devices. For any personal device already used for company access, the minimum step is routing company email and files through managed apps that can be disconnected remotely.
Move client-facing communication into a CRM where contact history gets logged. Even a shared mailbox, with multiple sets of eyes on it, is a meaningful improvement over what many small businesses have in place today.
IT providers are always involved at onboarding. Someone has to create the account and get a new hire's tools working before their first day. The real opportunity is leaning on them for more than simple setup. Loop IT in while the role itself is still being defined, and they can help the organization make better decisions instead of simply executing whatever gets decided elsewhere.
The best access decisions come from treating IT as an advisor rather than only as an executor afterward. A brief conversation before day one is what lets that expertise actually shape the outcome instead of getting applied only after something goes wrong.
You don't need an exact date for the next departure to start this work. It's more manageable when nothing about it is urgent.
Start with the SaaS audit - pull statements and list every recurring charge, flagging any tool where access would be lost or complicated if the account owner left this week.
Move to the device register next - confirm what everyone actually uses for work and get personal devices routed through managed access at minimum.
Last (for now) - take a look at client coms and identify any relationships in risky territory.
Finish by writing the onboarding process you wish you'd had, using everything found in the first three steps as the input and apply it to the next hire right out of the gate!