What Happens When You Forget to Offboard an Employee?
Download our free Employee Offboarding Checklist for Startups to securely remove access to Google Workspace, Slack, GitHub, devices, and SaaS applications. Help protect your business, reduce security risks, and ensure every employee offboarding is completed consistently.
An employee leaving a modern office building, representing the importance of securely offboarding departing team members and revoking access to company systems.
Six months after a contractor finished their project, someone on your team notices something strange.
A file in a shared Drive was edited. Not by anyone currently on the team.
You check the permissions. The contractor's Google account is still active. Still has edit access to three shared folders. Still logged into Slack, technically, if they wanted to be. Nobody removed it, because nobody was assigned to remove it. It just... stayed.
This isn't a rare story. It's closer to the default outcome of startup offboarding done informally which is to say, not really done at all.
Two weeks ago, we covered the employee onboarding checklist every startup needs, the process that gets someone access to everything on day one. Offboarding is the mirror image of that problem and it's the one with real teeth. Forgetting to onboard someone properly slows your business down. Forgetting to offboard someone properly leaves the door open.
Why Offboarding Gets Forgotten
Onboarding has a built in deadline. Someone starts Monday, so the setup has to happen before then.
Offboarding doesn't have that same forcing function. An employee gives notice, works their last day, says goodbye and then everyone moves on to the next thing. There's no calendar reminder that says "revoke this person's Google Workspace account in 30 days." There's just an assumption that it happened or that it'll happen eventually, or that it doesn't matter that much because they left on good terms.
That assumption is exactly how startup offboarding quietly fails:
Did we actually remove them from every Google Group?
Is their Slack account deactivated or just... not being used?
Did anyone recover the laptop?
Who has admin rights to the SaaS tools they set up?
Is their email still forwarding somewhere?
None of these questions get asked in the moment, because there's no moment where they're supposed to be asked. Without a documented offboarding process, employee access removal becomes something that happens eventually, inconsistently or not at all.
What Actually Happens When Offboarding Gets Skipped
This isn't a hypothetical risk. According to a Beyond Identity study, roughly one in four former employees say they can still access accounts and emails from a past job. A separate research from OneLogin found that half of former employee accounts remain active for more than a day after departure, with nearly a third of organizations taking over a week to fully deprovision someone. For a startup running lean, "over a week" often means "we never actually finished."
That gap creates three real problems.
Dormant accounts become an open door. A former employee's login is a working set of credentials that nobody is actively watching. It doesn't matter whether they left on good terms. A dormant account with unrevoked access is a risk regardless of intent. It can be compromised, guessed or simply forgotten and left dangling for anyone who finds it.
You keep paying for licenses nobody's using. Every SaaS seat tied to a former employee Slack, Notion, Zoom, GitHub or whatever your stack includes is a subscription cost that should have ended the day they left. For a lean startup watching every dollar, this adds up faster than most founders expect.
You lose track of who has access to what. This is the compounding version of the problem. Every skipped offboarding makes the next one harder, because there's no clean record of who was ever granted access in the first place. Startup IT support that's reactive instead of structured tends to spiral here, each new hire and each departure adds a little more uncertainty about who actually has the keys to what.
What Founders Are Actually Searching For
Founders don't usually type "employee lifecycle management" into Google when this problem shows up. They search for something closer to the actual moment they're in: an employee offboarding checklist, or specifically how to revoke employee access before it becomes a liability.
That's the real search intent behind this topic not a theoretical framework, but a concrete, repeatable list for the exact moment someone leaves the company, so nothing depends on someone remembering to do it later.
What a Real Offboarding Checklist Includes
A strong offboarding process mirrors your onboarding process almost exactly, it just runs in reverse. If your onboarding checklist documents every account and every piece of access a new hire receives, offboarding becomes a matter of working through that same list and removing it.
Google Workspace offboarding. This is usually the highest priority step, since Workspace access often unlocks everything else. Remove the Google Workspace account or convert it to a shared/suspended state depending on what data needs to be preserved. Pull them from every Google Group. Transfer ownership of any files or Shared Drives they controlled before their account is disabled, not after.
Revoke SaaS access. Slack, Zoom, GitHub, Notion, Figma, HubSpot, Linear & every tool from the original onboarding checklist gets a corresponding offboarding step. This is where having documented onboarding pays off: you already know exactly what to check, instead of guessing which tools someone might have had access to.
Recover and wipe the device. The laptop should be returned, wiped and reset before it's reissued or retired. This also closes the loop on any locally cached credentials or files that live outside cloud based systems entirely.
Reset shared credentials. If the employee ever had access to a shared password manager entry, a shared login, or an admin account, those credentials should be rotated & not just their personal account disabled.
Disable MFA and remove device trust. Any devices or authentication methods tied to their identity should be removed so old hardware or old phone numbers can't be used to slip back in later.
Check for forwarding rules and integrations. A departing employee's email account, once compromised or left active, can be used to quietly forward messages elsewhere. It's a small step that's easy to skip and easy to check.
Here's the same list laid out as an actual checklist:
Startup Employee Offboarding Checklist
☐ Disable Google Workspace account
☐ Remove from all Google Groups
☐ Transfer file and Shared Drive ownership
☐ Revoke Slack access
☐ Revoke Zoom, GitHub, Notion, Figma, HubSpot access
☐ Recover company device
☐ Wipe and reset device
☐ Rotate any shared credentials
☐ Disable MFA / remove device trust
☐ Check for email forwarding rules
☐ Cancel unused SaaS licenses
☐ Confirm removal against original onboarding record
Twelve boxes. Run through in reverse of your onboarding list, and there's no guessing involved.
The Principle Behind It: Least Privilege, Applied Consistently
There's a concept in Cyber security called least privilege access, the idea that people should only have access to exactly what they need, for exactly as long as they need it. Most founders apply this instinctively while someone's employed. Access requests get reviewed. Permissions get scoped to the role.
The same principle has to apply on the way out and it usually doesn't, because there's no equivalent moment forcing the review. Account deprovisioning is least privilege's other half, it's what keeps "access someone needed" from quietly turning into "access someone still has for no reason, indefinitely."
Your goal isn't to remember every account someone ever touched. It's to build a process where that memory isn't required, where offboarding is a checklist run against a record. Not a founder trying to recall six months of SaaS sign-ups from memory.
Frequently Asked Questions(FAQ)
What should be included in an employee offboarding checklist?
At minimum: disabling the Google Workspace account, removing access to every SaaS tool the employee used, recovering and wiping their device, rotating any shared credentials and confirming nothing was missed against the original onboarding record.
How quickly should employee access be revoked after someone leaves?
Ideally, on their last day not days or weeks later. Immediate access removal is the single biggest factor in closing the security gap that dormant accounts create.
What are dormant accounts, and why are they risky?
Dormant accounts are logins that still technically work but aren't being actively used or monitored by anyone. They're risky because they sit outside normal usage patterns, nobody notices if a dormant account is compromised, because nobody's watching it in the first place.
Does a small startup really need a formal offboarding process?
Yes, arguably more than larger companies. Startups tend to have fewer people managing more systems, which means access is often broader and less segmented. A missed offboarding step at a 10 person company can expose a much larger share of the business than the same mistake would at a 500 person company.
Download the Employee Offboarding Checklist
If you'd rather not reconstruct this list from memory every time someone leaves, we've already built it.
Our free Employee Offboarding Checklist for Startups covers every step in this article Google Workspace, SaaS access removal, device recovery, credential rotation and confirmation against your original onboarding record. So nothing depends on anyone remembering it later.
Every offboarding should follow the same process, not because every departure is the same, but because consistency is what keeps a former employee's exit from turning into a security gap. If your startup has been offboarding people from memory, the fix isn't complicated it just has to be written down once and followed every time.
👉 [Download the Employee Offboarding Checklist]
👉 [Book Your 15-Minute Startup IT Assessment]
What's Coming Next in the Startup IT Playbook
Next up: Google Workspace Best Practices for Startups, how to structure Groups, Shared Drives, and admin roles so onboarding and offboarding both stay simple as your team grows.
Related reading:
Why Founders Should Stop Being the IT Department
The Employee Onboarding Checklist Every Startup Needs
Google Workspace Best Practices for Startups (coming soon)