Every business eventually has the same bad afternoon. Someone resigns, and the scramble begins: which systems did they have access to? Was there a personal Dropbox with client files in it? Who knows the password to the shared vendor account they set up? Did anyone ever get the laptop back?
That afternoon is not an offboarding failure. It is an onboarding failure arriving late. If nobody recorded what someone was given, nobody can reliably take it away.
How access grows without anyone tracking it
In most small businesses, access accumulates informally. A new hire gets the standard accounts on day one. Then they cover for someone on vacation and get added to a system temporarily. Then they sign up for a free tool that makes a task easier. Then they are given a vendor portal login because they are the one who deals with that vendor now.
None of it is recorded, because each individual grant was small and sensible at the time. Two years later, the total is unknown to everybody — including the employee.
The specific things that reliably get missed on the way out: SaaS tools bought on a personal card and expensed. Vendor and supplier portals. Social media accounts. Shared mailbox delegations. Personal devices holding company data. And software-as-a-service accounts registered to a personal email address, which are effectively invisible to any audit of your directory.
Fix it at the front end
Clean offboarding is a byproduct of disciplined onboarding. Three practices do most of the work.
Define access by role, not by person. Write down what a front desk role gets, what a hygienist gets, what a bookkeeper gets. Then provisioning a new hire is applying a template rather than reconstructing a list from memory, and deprovisioning is removing the same template.
This also fixes a subtler problem: when access is granted person by person, people who change roles accumulate the permissions of every role they have ever held.
Grant access through groups, never individually. If someone is in the “Billing” group and that group has the permissions, removing them from one group removes everything at once. If permissions were assigned individually across eleven systems, you have to remember all eleven.
Keep a live record of every grant. One shared document listing each person, each system they can reach, and when it was granted. It does not need to be sophisticated. It needs to exist and be updated at the moment access is given, not reconstructed afterward.
Handle temporary access as temporary
A large share of orphaned permissions began as short-term coverage. Someone needed access for a two-week absence and it was never revoked.
Whenever temporary access is granted, put an end date on it in the record and a reminder on the calendar. Where the system supports it, use time-limited access so it expires on its own. This one habit prevents more permission sprawl than any periodic cleanup.
Stop shared accounts before they start
Shared logins are the single hardest thing to clean up after a departure, because revoking access means changing a password that several people still need — which nobody wants to do on the day someone leaves.
Where a system supports individual accounts, use them. Where it genuinely does not — and some vendor portals still do not — put the credential in a business password manager with the access controlled by group membership, so removing the person removes their access to the secret without disrupting anyone else.
What good offboarding looks like when onboarding was done right
It becomes a short, boring checklist that runs the same way every time.
Disable the account rather than deleting it, so mail and files remain accessible. Revoke active sessions and refresh tokens — disabling an account does not always terminate a session already in progress, which is a genuinely common oversight. Remove the person from every group, which removes the downstream permissions automatically. Convert the mailbox to shared and set delegation or forwarding. Collect and wipe devices. Remove them from the password manager. Transfer ownership of any files in their OneDrive.
Then check the record for anything role-based provisioning did not cover, and close it out.
Where to start if you are already behind
Run an access review now, before the next departure. List every system your business uses and who can reach it. You will find accounts belonging to people who left years ago — that is normal, and it is exactly the exposure worth closing.
If you would like help building the role templates and running that first review, we do this regularly. It is a short project with a disproportionate payoff, and it makes every future departure uneventful.