Starting and ending.
WHEN SOMEONE JOINS
Create individual accounts Give the minimum access needed Require two-factor authentication Record what they were given
WHEN SOMEONE LEAVES
Remove every account, the same day Change any shared credentials they knew Reset two-factor on shared accounts Remove their access from third-party services Recover devices
THE SAME DAY POINT
The most commonly neglected security action in any business.
WHAT PEOPLE FORGET
Social account access Payment service access Third-party tools FTP accounts SSH keys Access granted for a one-off task
THE CHECKLIST APPROACH
Write down every system a person is given access to.
That list is what you work through when they leave.
WITHOUT THAT LIST
You cannot be confident you removed everything.
FOR A DIFFICULT DEPARTURE
Remove access before the conversation, where warranted.
WHAT TO REVIEW AFTERWARDS
That nothing remains.