Back to blog

September 24, 2026 · admin@credentialbase.com

How to Securely Revoke Access & Credentials

Unless you’re living under a rock, you must have an idea that employee offboarding is not at all a simple process. There is a lot to take care of. HR handles the paperwork, managers wrap up projects, the IT department collects devices, and someone sends the inevitable farewell message.

But there is one part of employee offboarding that can easily get overlooked: access.

An employee may have access to dozens of applications, shared accounts, cloud platforms, internal tools, documents, and company credentials. Simply deactivating their email account does not necessarily remove all of that access.

A secure employee offboarding process should make sure that former employees can no longer access company systems, sensitive information, or shared credentials after they leave.

This is where having a clear employee offboarding checklist becomes important.

In this guide, we'll walk through eight essential steps for secure employee offboarding, from identifying accounts and revoking access to managing shared credentials and documenting the entire process.

What Is Employee Offboarding?

Employee offboarding is the process of managing an employee's departure from an organization. It typically includes administrative tasks, knowledge transfer, equipment recovery, account closure, and access removal.

However, modern offboarding goes beyond HR paperwork.

Employees today work across a large number of SaaS applications and digital platforms. They may have access to email, project management software, CRMs, cloud storage, communication tools, financial systems, and other business applications.

That makes employee access management an important part of the offboarding process.

A well-designed process should answer a simple question:

When an employee leaves, can we confidently say that they no longer have access to anything they shouldn't?

If the answer is unclear, your offboarding process probably needs a security review.

8-Step Employee Offboarding Checklist

1. Start With a Clear Employee Offboarding Checklist

The first step is to have a documented employee offboarding checklist that everyone involved can follow.

Without a standard process, offboarding often becomes a collection of individual tasks handled by different people. HR may know that someone has left, but IT may not know which applications they used. A manager may remember the company's CRM but forget about a smaller SaaS tool that the employee used every day.

A checklist creates a consistent employee offboarding procedure as follows:

  • Notifying IT and relevant managers

  • Reviewing the employee's access

  • Disabling accounts

  • Revoking permissions

  • Removing SaaS access

  • Managing shared credentials

  • Recovering company devices

  • Transferring ownership of files and accounts

  • Documenting completed actions

The purpose of a detailed checklist is not to maintain redundant paperwork, instead it ensures that all the steps are religiously followed. 

2. Identify Every Account & System the Employee Can Access

One can think of obvious and directly related accounts of an employee, but we literally have to think outside the box. 

An employee might have access to:

  • Company email

  • CRM software

  • Project management tools

  • Cloud storage

  • Communication platforms

  • HR systems

  • Accounting software

  • Marketing platforms

  • Social media accounts

  • Development environments

  • VPNs

  • Internal applications

  • Shared company accounts

This is why an employee access audit should be part of the process.

Before removing access, create an accurate picture of what needs to be removed.

For companies using dozens or even hundreds of SaaS applications, this can become difficult to manage manually. An employee may have accumulated access over months or years without anyone maintaining a complete record.

A good SaaS access offboarding process helps prevent these forgotten accounts from becoming security gaps.

3. Revoke Employee Access as Soon as the Employee Leaves

Once you know what the employee can access, the next step is employee access revocation.

This means disabling or removing access to company systems according to the organization's offboarding policy.

Depending on the employee's role and the circumstances of their departure, this may include:

  • Disabling user accounts

  • Removing group memberships

  • Revoking application permissions

  • Disabling VPN access

  • Removing access to cloud platforms

  • Terminating active sessions

  • Removing administrative privileges

The timing matters! If access revocation is being delayed from the employer’s side, the former employee will get an image that he or she can still access company information and misuse it. 

For organizations with a formal employee offboarding security checklist, access revocation should be one of the first steps rather than something handled at the end.

4. Revoke Shared Credentials

This is one of the most commonly overlooked areas of employee offboarding.

Imagine a marketing team using a shared advertising account. Five employees know the login credentials. One of them leaves the company.

Disabling that person's individual work account doesn't change the fact that they may still know the shared password.

This is why employee offboarding password management requires special attention.

Companies should identify credentials that were shared with the departing employee and determine whether they need to be revoked or rotated.

This can include:

  • Shared account passwords

  • Administrative credentials

  • API keys

  • Recovery credentials

  • Service account credentials

  • Shared access codes

Instead of sending passwords through email, chat, or spreadsheets, organizations can use secure credential management solutions that allow authorized employees to access shared credentials without unnecessarily exposing the underlying password.

5. Remove Access to SaaS Applications

The average employee can use a surprising number of SaaS applications. The SaaS management team should access or have an idea of every application they use during their stay in the company or in a particular assignment or project. 

Look for:

  • Active user accounts

  • Admin permissions

  • Shared workspaces

  • Cloud storage access

  • Application integrations

  • Project ownership

  • Billing permissions

This is particularly important for employees who work across multiple departments or have administrative responsibilities. The more applications an organization uses, the more important it becomes to have a centralized view of employee access.

6. Revoke Sessions, MFA Devices, & Connected Credentials

Account deactivation is only one part of secure offboarding.

Employees may also have active sessions, registered authentication devices, security keys, recovery methods, or connected applications.

As part of employee deprovisioning, organizations should review the authentication methods associated with the departing employee.

Depending on the system, this can include active login sessions, MFA authenticators, security keys, API tokens, recovery email addresses and phone numbers. In short, consider all the ways an employee could still be associated with company resources.

7. Transfer Ownership & Recover Company Assets

Access isn't the only thing that needs attention when an employee leaves. Sometimes, employees become ad hoc owners or managers of certain business resources. So, review whether the employee owns or manages:

  • Shared documents

  • Cloud folders

  • Customer accounts

  • Projects

  • Calendars

  • Social media accounts

  • Marketing platforms

  • Software subscriptions

  • Internal documentation

  • Team workspaces

At the same time, companies should recover physical and digital assets such as laptops, phones, security keys, access cards, and other company equipment.

This part of the employee departure checklist helps prevent operational problems after the employee is gone.

The objective isn't simply to remove someone from the organization. It's to make sure their responsibilities, information, and access have been safely handed over.

8. Verify & Document the Access Revocation

The final step is one that is often skipped. You should verify and document employee offboarding checklists yourself. 

A complete employee offboarding audit should provide evidence that the required access has actually been removed.

This could include documenting:

  • Accounts that were disabled

  • Applications where access was revoked

  • Shared credentials that were rotated

  • Devices that were recovered

  • Ownership that was transferred

  • Sessions that were terminated

  • Outstanding access that still requires attention

Common Employee Offboarding Mistakes That Create Security Risks

Even organizations with an established employee offboarding process can make mistakes.

One common mistake is assuming that disabling an email account automatically removes all access.

Another is forgetting about shared credentials. If an employee knows the password to a shared account, removing their individual user account won't necessarily solve the problem.

Other common issues include:

  • Forgetting SaaS applications

  • Leaving former employees in shared workspaces

  • Failing to revoke active sessions

  • Forgetting API keys or integrations

  • Not transferring account ownership

  • Keeping unnecessary administrator privileges

  • Failing to document access removal

  • Relying on spreadsheets to track credentials

  • Not reviewing access after the employee has left

These gaps may seem small individually, but they can create significant security and operational problems over time.

How CredentialBase Fits Into Employee Offboarding?

Secure offboarding starts long before an employee hands in their laptop.

Organizations need a reliable way to know who has access to what, particularly when employees use shared credentials or multiple SaaS platforms.

This is where CredentialBase can make a difference.

Rather than keeping passwords in spreadsheets or sending credentials through email and messaging apps, businesses can manage access through a controlled system.

With a solution such as CredentialBase, organizations can build a more structured approach to employee password management and secure account sharing. 

CredentialBase encrypts everything on your device first. It does not even read your data. A secure password management service you can fully trust while managing employee offboarding and revoking. One less thing off your shoulders!

If you’re looking to take control of shared credentials and employee access, CredentialBase can be part of that broader approach to secure credential and access management. Sign in NOW!

Keep reading

How to Secure Shared Accounts Without Sharing Passwords?

As common as it is, sharing passwords is vulnerable at many stages. If sent through unsecure means, it can stay in emails, chats, archives and even on servers. There is also a chance that the recipient’s device is not compliant with security protocols. Whatever reasons could there be, having shared credentials does not mean that you have to compromise on password security.

Read

Premium Business Password Manager for Small Businesses

In a world of growing cyber threats, small businesses cannot afford to overlook password security. That’s because they deal with multiple accounts everyday, from managing emails and social media to cloud storage, communication tools among employees and clients. Keeping all these accounts secure can be challenging. That’s why a password manager with a robust security track record is inevitable for businesses of all sizes.

Read

What Is a Password Manager? How It Works and Why You Need One

Have you ever juggled remembering dozens of unique passwords for work, shopping, and socials? It’s indeed a brain-racking task. So, people either reuse the same password across multiple accounts or create weak passwords that are easy to remember. Unfortunately, these habits also make it easier for cybercriminals to gain unauthorized access to sensitive data.

Read

What Is a Zero-Knowledge Password Manager? | CredentialBase

Most password managers can read your passwords. Zero-knowledge ones can't. Learn what it means, why it matters, and how CredentialBase keeps your data truly private. Estimated Read Time: 6 minutes Target Word Count: 1,400 words

Read