Security steps when a person leaves.
THE SAME DAY
Disable every account, working from the list made when they joined Change every shared credential they knew Reset any shared second factor Remove them from the password manager
DO NOT FORGET
Social accounts Payment and banking access Third-party tools and integrations Remote access API keys they held Email forwarding and delegated access
DEVICES
Recover business devices Remove business access from personal devices Wipe recovered devices before reissuing
DATA
Establish what they held and where Ensure anything only they had is retained
HANDOVER
Ask for documentation and anything undocumented, before they go
FOR A DIFFICULT DEPARTURE
Remove access before the conversation, where warranted
VERIFY
Check each system afterwards to confirm removal took effect
RECORD
What was removed and when.
WHAT TO REVIEW
The process itself, after each departure.