September 24, 2026 · admin@credentialbase.com
How to Securely Revoke Access & Credentials
Unless you’re living under a rock, you must have an idea that employee offboarding is not at all a simple process. There is a lot to take care of. HR handles the paperwork, managers wrap up projects, the IT department collects devices, and someone sends the inevitable farewell message.
But there is one part of employee offboarding that can easily get overlooked: access.
An employee may have access to dozens of applications, shared accounts, cloud platforms, internal tools, documents, and company credentials. Simply deactivating their email account does not necessarily remove all of that access.
A secure employee offboarding process should make sure that former employees can no longer access company systems, sensitive information, or shared credentials after they leave.
This is where having a clear employee offboarding checklist becomes important.
In this guide, we'll walk through eight essential steps for secure employee offboarding, from identifying accounts and revoking access to managing shared credentials and documenting the entire process.
What Is Employee Offboarding?
Employee offboarding is the process of managing an employee's departure from an organization. It typically includes administrative tasks, knowledge transfer, equipment recovery, account closure, and access removal.
However, modern offboarding goes beyond HR paperwork.
Employees today work across a large number of SaaS applications and digital platforms. They may have access to email, project management software, CRMs, cloud storage, communication tools, financial systems, and other business applications.
That makes employee access management an important part of the offboarding process.
A well-designed process should answer a simple question:
When an employee leaves, can we confidently say that they no longer have access to anything they shouldn't?
If the answer is unclear, your offboarding process probably needs a security review.
8-Step Employee Offboarding Checklist
1. Start With a Clear Employee Offboarding Checklist
The first step is to have a documented employee offboarding checklist that everyone involved can follow.
Without a standard process, offboarding often becomes a collection of individual tasks handled by different people. HR may know that someone has left, but IT may not know which applications they used. A manager may remember the company's CRM but forget about a smaller SaaS tool that the employee used every day.
A checklist creates a consistent employee offboarding procedure as follows:
Notifying IT and relevant managers
Reviewing the employee's access
Disabling accounts
Revoking permissions
Removing SaaS access
Managing shared credentials
Recovering company devices
Transferring ownership of files and accounts
Documenting completed actions
The purpose of a detailed checklist is not to maintain redundant paperwork, instead it ensures that all the steps are religiously followed.
2. Identify Every Account & System the Employee Can Access
One can think of obvious and directly related accounts of an employee, but we literally have to think outside the box.
An employee might have access to:
Company email
CRM software
Project management tools
Cloud storage
Communication platforms
HR systems
Accounting software
Marketing platforms
Social media accounts
Development environments
VPNs
Internal applications
Shared company accounts
This is why an employee access audit should be part of the process.
Before removing access, create an accurate picture of what needs to be removed.
For companies using dozens or even hundreds of SaaS applications, this can become difficult to manage manually. An employee may have accumulated access over months or years without anyone maintaining a complete record.
A good SaaS access offboarding process helps prevent these forgotten accounts from becoming security gaps.
3. Revoke Employee Access as Soon as the Employee Leaves
Once you know what the employee can access, the next step is employee access revocation.
This means disabling or removing access to company systems according to the organization's offboarding policy.
Depending on the employee's role and the circumstances of their departure, this may include:
Disabling user accounts
Removing group memberships
Revoking application permissions
Disabling VPN access
Removing access to cloud platforms
Terminating active sessions
Removing administrative privileges
The timing matters! If access revocation is being delayed from the employer’s side, the former employee will get an image that he or she can still access company information and misuse it.
For organizations with a formal employee offboarding security checklist, access revocation should be one of the first steps rather than something handled at the end.
4. Revoke Shared Credentials
This is one of the most commonly overlooked areas of employee offboarding.
Imagine a marketing team using a shared advertising account. Five employees know the login credentials. One of them leaves the company.
Disabling that person's individual work account doesn't change the fact that they may still know the shared password.
This is why employee offboarding password management requires special attention.
Companies should identify credentials that were shared with the departing employee and determine whether they need to be revoked or rotated.
This can include:
Shared account passwords
Administrative credentials
API keys
Recovery credentials
Service account credentials
Shared access codes
Instead of sending passwords through email, chat, or spreadsheets, organizations can use secure credential management solutions that allow authorized employees to access shared credentials without unnecessarily exposing the underlying password.
5. Remove Access to SaaS Applications
The average employee can use a surprising number of SaaS applications. The SaaS management team should access or have an idea of every application they use during their stay in the company or in a particular assignment or project.
Look for:
Active user accounts
Admin permissions
Shared workspaces
Cloud storage access
Application integrations
Project ownership
Billing permissions
This is particularly important for employees who work across multiple departments or have administrative responsibilities. The more applications an organization uses, the more important it becomes to have a centralized view of employee access.
6. Revoke Sessions, MFA Devices, & Connected Credentials
Account deactivation is only one part of secure offboarding.
Employees may also have active sessions, registered authentication devices, security keys, recovery methods, or connected applications.
As part of employee deprovisioning, organizations should review the authentication methods associated with the departing employee.
Depending on the system, this can include active login sessions, MFA authenticators, security keys, API tokens, recovery email addresses and phone numbers. In short, consider all the ways an employee could still be associated with company resources.
7. Transfer Ownership & Recover Company Assets
Access isn't the only thing that needs attention when an employee leaves. Sometimes, employees become ad hoc owners or managers of certain business resources. So, review whether the employee owns or manages:
Shared documents
Cloud folders
Customer accounts
Projects
Calendars
Social media accounts
Marketing platforms
Software subscriptions
Internal documentation
Team workspaces
At the same time, companies should recover physical and digital assets such as laptops, phones, security keys, access cards, and other company equipment.
This part of the employee departure checklist helps prevent operational problems after the employee is gone.
The objective isn't simply to remove someone from the organization. It's to make sure their responsibilities, information, and access have been safely handed over.
8. Verify & Document the Access Revocation
The final step is one that is often skipped. You should verify and document employee offboarding checklists yourself.
A complete employee offboarding audit should provide evidence that the required access has actually been removed.
This could include documenting:
Accounts that were disabled
Applications where access was revoked
Shared credentials that were rotated
Devices that were recovered
Ownership that was transferred
Sessions that were terminated
Outstanding access that still requires attention
Common Employee Offboarding Mistakes That Create Security Risks
Even organizations with an established employee offboarding process can make mistakes.
One common mistake is assuming that disabling an email account automatically removes all access.
Another is forgetting about shared credentials. If an employee knows the password to a shared account, removing their individual user account won't necessarily solve the problem.
Other common issues include:
Forgetting SaaS applications
Leaving former employees in shared workspaces
Failing to revoke active sessions
Forgetting API keys or integrations
Not transferring account ownership
Keeping unnecessary administrator privileges
Failing to document access removal
Relying on spreadsheets to track credentials
Not reviewing access after the employee has left
These gaps may seem small individually, but they can create significant security and operational problems over time.
How CredentialBase Fits Into Employee Offboarding?
Secure offboarding starts long before an employee hands in their laptop.
Organizations need a reliable way to know who has access to what, particularly when employees use shared credentials or multiple SaaS platforms.
This is where CredentialBase can make a difference.
Rather than keeping passwords in spreadsheets or sending credentials through email and messaging apps, businesses can manage access through a controlled system.
With a solution such as CredentialBase, organizations can build a more structured approach to employee password management and secure account sharing.
CredentialBase encrypts everything on your device first. It does not even read your data. A secure password management service you can fully trust while managing employee offboarding and revoking. One less thing off your shoulders!
If you’re looking to take control of shared credentials and employee access, CredentialBase can be part of that broader approach to secure credential and access management. Sign in NOW!
Keep reading
How to Secure Shared Accounts Without Sharing Passwords?
As common as it is, sharing passwords is vulnerable at many stages. If sent through unsecure means, it can stay in emails, chats, archives and even on servers. There is also a chance that the recipient’s device is not compliant with security protocols. Whatever reasons could there be, having shared credentials does not mean that you have to compromise on password security.
ReadPremium Business Password Manager for Small Businesses
In a world of growing cyber threats, small businesses cannot afford to overlook password security. That’s because they deal with multiple accounts everyday, from managing emails and social media to cloud storage, communication tools among employees and clients. Keeping all these accounts secure can be challenging. That’s why a password manager with a robust security track record is inevitable for businesses of all sizes.
ReadWhat Is a Password Manager? How It Works and Why You Need One
Have you ever juggled remembering dozens of unique passwords for work, shopping, and socials? It’s indeed a brain-racking task. So, people either reuse the same password across multiple accounts or create weak passwords that are easy to remember. Unfortunately, these habits also make it easier for cybercriminals to gain unauthorized access to sensitive data.
ReadWhat Is a Zero-Knowledge Password Manager? | CredentialBase
Most password managers can read your passwords. Zero-knowledge ones can't. Learn what it means, why it matters, and how CredentialBase keeps your data truly private. Estimated Read Time: 6 minutes Target Word Count: 1,400 words
Read