Offboarding checklist for shared passwords and access
The offboarding security gap
Most organisations have a reasonable process for revoking formal access when someone leaves — disabling their Active Directory account, revoking their email, returning hardware. But this formal offboarding often misses the credentials that were shared informally: the shared admin login that was passed via email three months ago, the social media account that the whole team uses, the cloud console password that was sent via Slack.
These credentials don't appear in any system. They can't be revoked by disabling an account. The only way to secure them is to find them and change them — ideally before the person's last day.
Why this matters
A former employee who retains access to your systems is a security and compliance problem, regardless of whether you believe they have any intention of misusing it. For regulated industries, it may be a requirement to demonstrate that access was promptly revoked. More practically, the circumstances of a departure can be unpredictable. Access that seemed harmless in the context of employment becomes a liability if the relationship ends badly.
The offboarding credentials checklist
Use this as a starting point and adapt it to your organisation's systems:
Formal accounts (usually handled by IT)
- [ ] Disable corporate email account
- [ ] Revoke VPN access
- [ ] Disable SSO/Active Directory account
- [ ] Revoke access to cloud platforms (AWS, Azure, GCP)
- [ ] Remove from code repositories (GitHub, GitLab, Bitbucket)
- [ ] Revoke API tokens and personal access tokens they may have generated
- [ ] Remove from project management tools (Jira, Asana, Notion)
- [ ] Remove from communication platforms (Slack, Teams)
Shared credentials (often missed)
- [ ] Change passwords for any shared admin accounts they had access to
- [ ] Rotate API keys they used or had access to
- [ ] Change shared email account passwords (info@, support@)
- [ ] Change shared social media account passwords
- [ ] Change hosting and domain management passwords they knew
- [ ] Rotate credentials for any client systems they managed
- [ ] Change any shared Wi-Fi passwords if they had access to router credentials
Documentation
- [ ] Update your credential inventory to reflect changes made
- [ ] Record the date of each change for audit purposes
- [ ] Confirm completion with the relevant manager or security officer
Timing is everything
The checklist above should ideally be completed on or before the last working day. For involuntary departures — redundancies, dismissals — this should happen on the day itself, potentially before the employee is informed if the situation is sensitive.
For planned departures where the relationship remains positive, it's still good practice to complete credential rotation before the last day. It's not personal; it's process.
Using one-time links in offboarding
If the outgoing employee managed credentials that need to be transferred to their successor, use PassTransfer to handle that transfer securely. The new holder gets the credentials via an encrypted one-time link, the outgoing employee's knowledge of the credentials is superseded by a rotation, and there's a clean record of the transfer.
Building this into your process
Offboarding checklists are only useful if they're actually followed. Make credential rotation a mandatory step in your HR or IT offboarding workflow, not an optional extra. Assign clear ownership — someone specific is responsible for completing the shared credential section within a defined timeframe.
Conclusion
The credentials that slip through formal offboarding processes are often the most sensitive ones — shared admin logins, client system access, infrastructure credentials. A dedicated offboarding checklist and a consistent credential rotation practice close this gap before it becomes a problem.