The ex-employee who still has the Wi-Fi password
Picture a retail shop where an employee left six months ago. The owner changed nothing. The employee still has the Wi-Fi password, still has their login to the store's Facebook Page, still has the alarm code, and still has an email forward that sends a copy of every invoice to their personal address. The owner assumed the employee would not do anything malicious, and so far that assumption has held. But the employee's personal laptop, the one that has the Wi-Fi password saved, was stolen last month. Now someone else has that password. The owner does not know.
That is the version where nothing bad has happened yet. The worse version is the employee who left angry, logged into the Facebook Page at midnight, changed the password, and locked the owner out. Or the employee whose email forward kept running for a year, collecting customer credit card receipts, until someone noticed during an unrelated audit. Or the door code that was shared with a string of employees over five years and never changed, so now twelve people who no longer work there can still unlock the building.
Offboarding does not happen automatically. If you do not have a checklist, things get missed. The day someone leaves, you are thinking about coverage, about finding a replacement, about whether the departure was voluntary or not. You are not thinking about the third-party app they set up two years ago that still sends order notifications to their phone. A checklist fixes that.
What to revoke immediately
Some things cannot wait until Monday. If an employee leaves on Friday, or if the departure is not friendly, you need to revoke access the same day.
Change the Wi-Fi password. Yes, that means every device that connects to the network needs the new password entered. Do it anyway. If the employee had the password, their devices have it saved, and if they wrote it down or stored it in a password manager, they still have it. Change it.
Remove their admin access to social media accounts. Facebook, Instagram, Google Business Profile, anywhere they could post or delete content on behalf of the business. If you are the only remaining admin on a Facebook Page and you remove the last other admin, you will still be able to manage the Page. Do not leave someone on the admin list because you are worried about losing access yourself.
Disable their email account, or at least change the password and check for forwards. If the account was firstname@yourdomain.com, log in as an admin and look at the forwarding rules. It is common for an employee to set up a forward to their personal email so they can check work messages from their phone. That forward does not turn itself off when they leave. If the email account is hosted through Google Workspace or Microsoft 365, you can convert the mailbox to a shared mailbox or delegate access to someone else without keeping the original login active.
Change the alarm code and any door codes. If your building has a keypad entry or an alarm system that uses a code, and the employee knew that code, change it. If the system allows individual user codes, delete theirs. If it is a shared code, pick a new one.
What to audit within a week
Some access does not need to be revoked the same day, but it should be reviewed within a few days while you still remember what the employee had access to.
Check for saved passwords in shared browsers or devices. If the employee used a computer that stays in the shop, open the browser and look at saved passwords. Remove any that are for business accounts. If the computer was theirs and they took it with them, change the passwords for anything they logged into.
Review third-party app permissions. Look at your payment processor, your scheduling software, your e-commerce platform, anywhere an employee might have created a login. If they had an account, disable it. If the app sends notifications or reports by email, make sure those are going to someone who still works there.
Check for shared credentials that need rotation. If the employee knew the password to the router admin interface, the NAS, the security camera system, or any other piece of infrastructure, change it. These are easy to forget because they are not used every day.
Where this sits
This is part of what a managed network engagement includes. We keep a list of who has access to what, and when someone leaves, we run the list. For clients on a Care plan, we handle the technical revocations: email, network credentials, app access, anything that touches a system we manage. The client handles the physical items: keys, codes, devices. If you do not have someone managing your network, print a checklist and keep it somewhere you will remember to use it. The time to think about offboarding is before someone leaves, not after.
Need this kind of thinking applied to your own setup? Get in touch →