Home/Blog/What IT Access Should Be Revoked Immediately When an Employee Leaves?
Cybersecurity Tips

What IT Access Should Be Revoked Immediately When an Employee Leaves?

Informal offboarding is one of the most common, quietly dangerous security gaps in small businesses — here's exactly what to revoke, and in what order.

Hardik Patel
Hardik PatelOct 5, 2026 · 6 min
Cover image: What IT Access Should Be Revoked Immediately When an Employee Leaves?

💡 In Simple Terms (For Beginners)

When someone leaves your company, every login and access they had should be shut off the same day — email, shared drives, admin tools, physical access — not "whenever someone remembers to get around to it."

Summary
  • Informal, undocumented offboarding is a common and quietly dangerous gap, especially in small teams.
  • Email and admin-level access should be revoked first — they carry the highest risk if left active.
  • A simple written checklist, used every time, closes this gap without needing new software.

CYBERSECURITY TIPS · October 5, 2026 · 6 min read · By Hardik Patel

What IT access should be revoked immediately when an employee leaves? Email, shared drive access, admin-level system logins, and any remote access tools should be revoked the same day an employee departs — these carry the highest risk if left active even briefly.

Why This Gap Is So Common

Offboarding access revocation is often informal in small businesses precisely because it isn't tied to a single owned process — it depends on someone remembering to tell IT, or IT remembering to act on it, rather than being a defined, triggered step in an exit process.

This is especially risky for departures on bad terms, where the gap between "last day" and "access actually revoked" is exactly the window where a disgruntled former employee could cause real damage.

The Priority Order for Revocation

  1. Email access — often the account that can reset passwords for everything else, making it the highest-priority single revocation.
  2. Admin-level system access — anything with elevated privileges across shared systems.
  3. Remote access tools — VPN credentials, RDP, TeamViewer/AnyDesk sessions.
  4. Shared drives and cloud storage — including any personal-device sync that may have pulled a local copy of company files.
  5. Physical access — building keys, access cards, and any hardware that needs to be returned.

Building a Simple Checklist That Actually Gets Used

A one-page offboarding checklist, triggered automatically by HR the moment a departure is confirmed rather than left to memory, closes most of this gap without requiring any new software or process overhead.

This connects directly to the vendor and third-party access review covered in our vendor risk checklist — access that accumulates and is never revisited is the same underlying pattern, whether the person leaving is an employee or a vendor's staff member.

Key Takeaways

  • Email and admin access carry the highest risk and should be revoked first, same day.
  • Informal offboarding is a common gap precisely because it's not tied to a defined, owned trigger.
  • A simple, HR-triggered checklist closes this gap without new software.

Frequently Asked Questions

Q: Should access be revoked even for an employee leaving on good terms?

A: Yes — same-day revocation should be a standard step regardless of how the departure went, since the risk isn't about the person's intentions, it's about an active credential existing after it's no longer needed.

Q: Who should own the offboarding checklist trigger?

A: HR is usually best positioned to trigger it, since they always know the exact departure date — IT or an external partner then executes the actual revocation steps.

How iTechFixr Can Help

We help businesses build a simple, triggered offboarding checklist as part of a broader access control review during a VAPT audit.

Share this post:
Hardik Patel
Hardik Patel
CEH v12 onwards certified cybersecurity trainer & consultant, iTechFixr Infotech LLP. 7+ years in offensive security and VAPT.

Need Help With This?

Talk to Hardik directly about your organisation's cybersecurity needs — get a tailored response within 24 hours.