Let me ask you something: when an employee or contractor walks out the door, do you know exactly what happens to your business data?
You may collect the laptop, shake hands, and send a polite farewell email. But what about the personal Google Drive account, the forwarded mailbox, the downloaded client list, or the Microsoft 365 session still open on a phone?
Here’s the simplest way to think about it: when someone leaves your office, you lock the door, collect the keys, and close the windows. Offboarding your technology should work the same way.
Most data loss during offboarding is not malicious. It is the accidental leaving-open of windows.
What can walk out the door with an employee?
Imagine a former employee sitting at home two weeks after leaving your company. Their personal laptop still has a synced folder containing client contracts. Their phone still receives work email. A browser session still opens Microsoft 365 without asking for a password.
Nothing dramatic happened. No alarm went off.
But your business data is still accessible.
This is why data protection for small business St. Louis owners needs to include employee and contractor offboarding, not just firewalls, backups, and antivirus software.
Here are the most common access points you need to close:
- Personal cloud storage such as Dropbox, Google Drive, or iCloud
- Forwarded business email sent to a personal address
- Downloaded client lists, pricing files, contracts, or financial records
- Shared passwords for accounting, social media, CRM, or vendor portals
- Unreturned laptops, phones, tablets, badges, and security keys
- Active Microsoft 365 or Google Workspace sessions
- VPN, remote desktop, payroll, project management, and file-sharing access
- Hidden administrator permissions in software your team rarely reviews
The Federal Trade Commission recommends that businesses know what sensitive information they have, where it lives, and who can access it. That includes information stored on laptops, home computers, mobile devices, flash drives, and cloud services.
Why small businesses feel this risk so quickly
Businesses in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, and the Metro East often hire quickly. That flexibility helps you grow, but it can also create an account problem.
A new employee may receive access to ten systems in one afternoon. Six months later, nobody remembers every system they can reach.
Then the employee leaves.
The company disables the main email account but forgets the CRM. It changes one shared password but not the social media login. It collects the laptop but never checks whether a personal cloud folder contains company files.
Here’s the problem: your employee roster may be current while your access list is not.

Your 24-hour employee offboarding checklist
You can hand this checklist to your manager, HR lead, office administrator, or IT provider. The exact order may change based on the situation, especially for an involuntary termination, but the goal is the same: close access quickly, preserve what you need, and document what happened.
Within the first 15 minutes: assign responsibility
Do not let offboarding become a group assumption.
Choose one person to coordinate the process and one person to verify completion. That may be your office manager and managed IT provider, or your HR lead and internal administrator.
Record:
- Employee or contractor name
- Departure date and time
- Manager and department
- Systems the person used
- Devices assigned to them
- Person responsible for each offboarding task
If the departure is unexpected, begin this step immediately. Do not wait until the end of the day.
Within the first hour: disable accounts and active sessions
Start with the accounts that open the most doors.
For Microsoft 365, block sign-in, sign the user out of all sessions, and revoke access tokens where your administrator tools support it. Then review Exchange, Teams, SharePoint, OneDrive, and security groups.
For Google Workspace, suspend the user, revoke security keys and application-specific passwords, and review connected applications.
Also disable or remove access to:
- VPN and remote desktop
- CRM and customer portals
- Accounting and payroll platforms
- Project management tools
- File-sharing services
- HR systems
- Website, hosting, and social media accounts
- Vendor and payment portals
Do not assume disabling email disables everything else.
For detailed platform guidance, review Microsoft’s former employee offboarding documentation and Google’s guidance for suspending a Workspace user.
Within two hours: secure email and transfer ownership
Email is often the most valuable account to control because it can reset passwords for other services.
Check for:
- Automatic forwarding to personal addresses
- Inbox rules that redirect or delete messages
- Delegated mailbox access
- Mobile devices still connected to the mailbox
- Shared mailbox permissions
- Email signatures and auto-replies that need updating
If your business needs access to historic email, preserve it according to your retention policy. If new messages must reach a manager, use an internal, time-limited forwarding arrangement or shared mailbox, not a personal email address.
Then transfer ownership of business files, calendars, forms, workflows, and shared folders to an active employee.
For Google Workspace, see Google’s instructions for transferring Drive files to a new owner. In Microsoft 365, preserve and transfer OneDrive and SharePoint content before deleting the account.
Within four hours: rotate shared passwords
Shared passwords create a separate offboarding risk.
Even if you disable the departing user’s individual account, they may still know the password for:
- Social media
- Scheduling software
- Shared inboxes
- Vendor portals
- Wi-Fi administration
- Website management
- Banking or payment services
- Password vaults
- Building access systems
Change those credentials and confirm that multi-factor authentication is tied to a current employee or company-controlled device.
Most importantly, never send replacement passwords through ordinary email or text. Use your password manager or another secure administrative process.
Before the end of the day: recover and protect devices
Collect every company-owned device, including equipment kept at home.
Your list should include:
- Laptop or desktop computer
- Smartphone and tablet
- Docking station and monitors
- USB drives and external hard drives
- Security keys and access cards
- Company credit cards or equipment
- Physical files and printed client information
If a device cannot be recovered immediately, use your device-management tools to lock it, remove business access, or remotely wipe it when appropriate.
Do not simply delete a few files and hand the computer to someone else. A proper reimage or secure wipe helps remove cached credentials, synced cloud files, browser sessions, and local client data.

By the 24-hour mark: check for data movement
This step is easy to skip. It is also one of the most important.
Review available audit logs for:
- Large downloads
- Bulk exports from a CRM
- New external file shares
- Unusual sign-ins
- Access from unfamiliar locations
- Personal email forwarding
- Downloads shortly before departure
- New administrator permissions
- Mass file deletions
A downloaded client list does not automatically prove wrongdoing. Most importantly, do not make accusations based on one log entry.
Instead, document anything unusual and involve qualified legal or security professionals when necessary. If you see evidence of unauthorized access, preserve the logs before deleting accounts or wiping devices.
What about personal cloud drives?
This is where many owners feel uncomfortable.
An employee may have used a personal Google Drive or Dropbox account because it was convenient. A contractor may have saved project files to a personal computer to work from home. Most people do not break the rules on purpose. They are trying to get work done.
It still creates risk.
Your offboarding process should ask directly:
- Did you store company files in a personal cloud account?
- Did you forward business email to a personal address?
- Did you download client lists, contracts, or financial files?
- Did you copy data to a personal computer, phone, or USB drive?
- Did you connect any outside applications to company accounts?
Ask the departing worker to identify and delete company data from personal locations when appropriate, and document the response. Your written policies and legal agreements should clearly explain how company information must be handled.
Make offboarding easier before someone leaves
The best time to build this process is before you need it.
Start by maintaining a simple access inventory that lists each employee, contractor, system, role, and administrator. Review it whenever someone changes roles, not only when they leave.
Then strengthen your process with:
- Single sign-on where practical
- Multi-factor authentication on critical systems
- Role-based access instead of broad permissions
- Company-managed devices
- Centralized password management
- Regular access reviews
- Tested backups and documented retention rules
- Security awareness training
- A written incident response plan
Your data protection guide for St. Louis small businesses provides a broader framework for protecting business information.
You can also review backup testing best practices and our guide to ransomware protection for St. Louis small businesses. Why connect those topics to offboarding? Because an employee account, device, or cloud folder can become an entry point for ransomware or accidental deletion.
Close the windows before you lock the door
Employee offboarding is not about blame. It is about awareness, consistency, and protecting the business you worked hard to build.
When someone leaves, you need to know which doors they can still open, where your data may have traveled, and who now owns the work they created.
Platinum Web Services helps small businesses in St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, the Metro East, and across Missouri build practical data protection programs. Our cybersecurity solutions for small business, managed IT services Missouri organizations rely on, ransomware protection, backup planning, and 24/7 IT support help you stay protected before a small oversight becomes a major incident.
If you would like help reviewing your offboarding process, contact Platinum Web Services.
You can reach us at support@platinumwebservices.net or visit us at:
Platinum Web Services
7827 Town Square Ave, 104-1184
O'Fallon, MO 63368
Business hours: 24/7
Accuracy note: This checklist is practical technology guidance, not legal advice. Employee privacy, records retention, employment, contractual, and breach-notification obligations can vary by situation. Consult qualified legal counsel when those issues apply.


0 Comments