August 19, 2026

What Should Happen to Company Technology When an Employee Leaves?

A practical employee technology offboarding process for protecting access, information, and business continuity

When an employee leaves, the request sent to technology support is often simple: shut off the email account.

The actual work is rarely that simple.

That employee may have access to company files, customer records, software, vendor portals, shared passwords, mobile apps, remote systems, and automated reports. They may also control accounts or processes that other employees depend on.

A complete technology offboarding process must accomplish four things:

  1. Disable access at the correct time.
  2. Preserve the information the business still needs.
  3. Transfer ownership of the employee’s work.
  4. Verify and document what was completed.

Missing any one of these can create a security problem or interrupt the business.

Why Is Disabling Email Not Enough?

Email is only one part of an employee’s technology access.

Depending on the person’s role, access may include:

  • Microsoft 365 or Google Workspace
  • Company computers, phones, and tablets
  • Cloud storage and shared files
  • Accounting, payroll, CRM, or industry software
  • Remote network or server access
  • Password managers and shared credentials
  • Vendor and customer portals
  • Website and social media accounts
  • Building and door-access systems

The easiest accounts to remove are usually those managed through the company’s main system. The harder ones are accounts created directly by the employee, purchased by a department, protected by a personal phone, or shared among several people.

Those accounts may not appear in the company’s main user directory. They are often discovered only when a report stops running, a customer email goes unanswered, or no one can access a vendor portal.

That is why offboarding should begin with a complete record of the technology people use, not a last-minute request to disable one account.

Should Every Employee Departure Follow the Same Process?

The same areas should be reviewed for every departing employee, but the timing may change.

A planned retirement may allow several weeks to document responsibilities, transfer files, update vendor contacts, and prepare equipment for another employee.

An immediate separation may require email, active sessions, remote access, administrative permissions, mobile access, and building credentials to be disabled at one agreed-upon time.

HR, the employee’s manager, and whoever manages technology should confirm:

  • The employee’s final working date and time
  • When each type of access should end
  • Which equipment must be returned
  • Who will take over the employee’s work
  • Which information must be retained
  • Whether legal, insurance, or compliance requirements apply
  • Who must approve retention or deletion decisions

The business should define both planned and immediate offboarding procedures before either situation occurs.

What Should Be Disabled First?

The first technical priority is preventing unauthorized access without deleting information the business still needs.

This may include:

  • Blocking the employee’s primary account
  • Ending active sign-in sessions
  • Revoking authentication tokens
  • Removing remote network access
  • Removing access from personal devices
  • Disabling administrative permissions
  • Reviewing MFA methods
  • Removing building credentials

Changing one password may not end an existing session on a phone, computer, or cloud application. Removing a Microsoft 365 license also does not address every outside system the employee used.

Shared passwords require separate attention. If a departing employee knew the password for a vendor portal, website, firewall, application, or social media account, that credential may need to be changed.

The practical rule is straightforward: disable access first, but do not delete the account until the business has addressed its information and ownership.

What Information Should the Business Preserve?

Access removal and information deletion are separate decisions.

Before removing licenses or deleting an account, determine whether the business needs to retain:

  • Customer, project, or vendor email
  • Files stored in the employee’s cloud drive
  • Documents or folders owned by the employee
  • Calendars, contacts, and scheduled meetings
  • Project notes and written procedures
  • Automated reports, forms, or workflows
  • Records covered by retention requirements

Someone must also decide who receives that information and how long it should remain available.

An employee may own a report, workflow, shared folder, or calendar that continues to operate after the account is disabled. Deleting that account without transferring ownership can interrupt a process that no one realized depended on it.

Technology support can preserve and transfer the information, but the employee’s manager must identify what the business still needs.

What Should Happen to Devices and Software?

Every company-owned computer, phone, tablet, security key, and storage device should be returned and recorded.

Before a device is reassigned, technology support should protect any business information stored on it, remove the former employee’s profile, install current security updates, and update the device inventory.

Personal devices also require attention when employees use them for company email, files, or applications. Device-management controls may allow business access or company information to be removed without erasing personal content. Without those controls, the company may have fewer options after the employee leaves.

Software licenses should be reviewed after needed data has been protected. Unused licenses can then be reassigned or removed.

When Is Offboarding Actually Complete?

Offboarding is not complete because someone submitted a ticket or checked a box. It is complete when the business can confirm the work was done.

The final record should show:

  • When access was disabled
  • Which systems and devices were reviewed
  • Whether active sessions and remote access ended
  • Who received the employee’s files or mailbox
  • Which devices were returned
  • Which licenses were recovered
  • Which shared credentials were changed
  • Whether any unresolved access remains
  • Who approved retention or deletion decisions

This record gives the business a clear answer if leadership, an auditor, an insurer, or a customer later asks how access was handled.

Who Should Own Employee Technology Offboarding?

HR knows when the employment relationship changes. The employee’s manager knows which information and responsibilities must continue. Technology support knows where access exists and how to remove it safely.

A reliable process connects all three and gives one party responsibility for verifying the technical work.

Links Technology helps Schaumburg and Chicagoland businesses coordinate employee changes across Microsoft 365, computers and mobile devices, remote access, security controls, software licensing, and outside vendors.

For more than 25 years, Links has helped local businesses bring their people and technology together under clearer technical ownership. If your current offboarding process depends on a last-minute email and someone remembering every account, Links can help document, manage, and verify a more complete process.