How to do secure password offboarding when someone leaves your team

The day an employee, freelancer or external agency stops working with you is the highest-risk moment for your credentials. And yet, 70% of SMBs have no formal offboarding process. Here's the checklist you should follow.

Why is bad offboarding so dangerous?

A former collaborator with live access can:

The average financial damage from an ex-employee breach exceeds €600,000 according to recent reports. Almost always preventable by revoking access in time.

What must I revoke on day one?

  1. Password manager access: remove the user from every shared vault.
  2. SSO / Google Workspace / Microsoft 365: suspend the account and revoke active sessions.
  3. Corporate email: forward messages to their manager.
  4. VPN and server access: revoke SSH keys and certificates.
  5. Code repos: GitHub, GitLab, Bitbucket; revoke personal tokens.
  6. Devices: remotely lock and wipe if corporate.

Do I have to rotate shared passwords?

Yes, whenever the person has seen the password in plaintext at any point. Even if your manager revokes their access, that password is already "in their head" or could have been copied. Rotating is the only way to close the vector.

Good news: with a well-designed zero-knowledge manager, this is just:

Which passwords are top priority?

How do I avoid missing steps?

Create an offboarding template inside your password manager or HR tool and assign it as a task to the manager on the leave day. Include:

What about freelancers or agencies?

Same process, plus define in the contract that credentials are shared via vault, never by email or chat. That way, ending the engagement is just revoking access to that vault.

Secure offboarding with Lock Down Keys

At Lock Down Keys, offboarding is one click: remove the member, every shared vault instantly stops decrypting on their device, and you can flag credentials worth rotating. Fully logged for audit and built on a zero-knowledge architecture.