Scenario Analysis: What Happens When a Departed Employee's Accounts Stay Open?

TL;DR: Closing accounts on departure is not an HR courtesy step but a security operation: email, VPN, CRM, cloud files, SaaS subscriptions and shared passwords belong on one list, handled the same day. In this representative case, a single account left open for three months returned as a data-leak suspicion, legal proceedings and customer-trust repair. The lasting fix is a written offboarding checklist triggered by HR, plus an access inventory.
This account is a composite, anonymised blend of cases we have met repeatedly in the field.
At a twenty-five-person distribution firm, a sales representative leaves in early March; the parting is civil, the paperwork complete, the laptop returned. In the second week of June, a long-standing customer's purchasing manager says something odd: "Your former rep called from his new company — he had our entire purchase list from last year." The same week, the CRM's sign-in logs are checked — the departed rep's account has logged in seventeen times in three months. Most recently, two days ago.
Discovery: Not One Account — a Missing Arrangement
The first anxious review shows the picture is bigger than one account:
- The CRM account was never closed — because the CRM was a SaaS subscription the sales manager had "set up himself"; IT's leaver list never contained it.
- The email account was closed, but the corporate mail profile on the personal phone was not; in the three days before closure, the mailbox kept syncing.
- The shared "sales@" account password was known to him, like everyone else — and was never rotated after he left.
- In the file-sharing app, a never-expiring share link to the folder of customer price lists was still active.
So the question is not "who forgot this account?" but "which arrangement would have caught it?" — and there is no answer, because two foundation stones are missing: an access inventory (who can reach what) and a written offboarding checklist (what closes on departure).
Cleanup Week: the Retroactive Cost
The following week is a textbook on how cheap prevention is: accounts are swept across every system (and two former interns' active accounts surface), all shared passwords rotate, non-expiring share links close, SaaS subscriptions are consolidated onto a single list through a shadow-IT sweep. On the legal side, the matter proceeds with counsel and its possible data-protection dimension — customer data carried off by a former employee runs on two tracks, trade secrets and personal data, and the evidence for both is the sign-in logs being assembled that week. The good news: the CRM kept logs. The bad news: nobody had looked at them for three months.
The Lasting Fix: an Arrangement That Closes Same-Day
| Piece | Content | What it would have prevented here |
|---|---|---|
| Access inventory | A person × system matrix: email, VPN, CRM, files, SaaS, physical access | "Where did he have accounts?" taking three months to answer |
| Offboarding checklist | Written steps triggered by HR, closed by IT the same day | The CRM missing from the list |
| Shared-account discipline | Shared passwords in a vault, auto-rotated on departure | The sales@ password living on outside |
The checklist's core: close the central identity account (how much one closure switches off is the maturity measure of your identity management), close or transfer SaaS accounts one by one, define mail forwarding and delegation, collect devices and MFA keys, remotely remove corporate profiles from personal devices, rotate shared passwords, strike the person from the access inventory.
Four Points That Usually Slip Through
- The corporate profile on the personal phone: even with the account closed, cached data remains on the device; mobile device management (MDM) must be able to remove the corporate profile remotely.
- Never-expiring share links: "anyone with the link" shares are not bound to a person; they do not close on departure. Make time-limited sharing the default.
- Contact details saved by customers: the departed rep's mobile number lives in the customer's phone book as "your company". A handover email and a new-contact notice are the offboarding of customer ownership, if not of security.
- Critical single-person access (domain, hosting): admin access bound to one person breeds crises on departure; critical accounts always run the second-administrator rule.
Onboarding's Mirror Twin
The elegant side of the arrangement: once the access inventory exists, joining speeds up too — a new hire receives the standard access set for their role within minutes, and on departure the same list closes in reverse. The investment does not just shut a risk; it saves time at every entry and exit.
How Yamanlar Bilişim Builds This
For customers under a maintenance agreement, the access inventory is drawn up at onboarding, and offboarding is a service step triggered by a single notice from HR: accounts close the same day, shared passwords rotate, a report goes to management. Where a departure is contentious, closure is scheduled before the notification — security precedes courtesy.
FAQ
Frequently Asked Questions
Should we delete a departed employee's email immediately?
Not delete — close immediately: the account is blocked from access, the mailbox stays available to a delegate or forwarding for a period (for work in flight), and it is archived at the end of the retention policy. Deletion is the last step, for both business continuity and possible legal needs.
We are a small team and everyone can reach everything — what does an inventory solve?
The "everyone everything" arrangement is itself the finding: everyone who leaves takes everything. The inventory makes that visible in step one; step two is narrowing access to roles at least on critical systems (finance, customer data). A small team means a short list — a convenience, not an excuse.
What can we possibly do if a former employee remembers passwords?
Exactly why the leaver list does not end with "close their account" — it continues with "rotate the shared passwords they knew". Personal accounts are protected by MFA, shared accounts by rotation; remembering is rendered useless.
Is routinely reviewing logs a privacy problem?
Security-purpose monitoring of access records, proportionate and disclosed, is a legitimate security measure; it belongs in the employee privacy notice and stays purpose-bound. The problem is not monitoring — it is covert, boundless monitoring. Put the framework in writing in your personnel policy.
How does the sequence change in a contentious departure?
Only the timing: access closure happens before or simultaneously with the termination meeting; the device is collected in the meeting room. The rest of the list is identical — the arrangement's value is that even on a tense day, nobody has to wonder "what were we supposed to close?"
Author
Serdar YAMAN
Yamanlar Bilişim Expert
Writes content on IT infrastructure, cybersecurity, and digital transformation at Yamanlar Bilişim. Get in touch for any questions.
Professional Support
Get help on this topic
Let's design the Cybersecurity solution you need together. Our experts get back to you within 1 business day.
support@yamanlarbilisim.com · Response time: 1 business day
Keep Reading
Related Articles

SSL Certificate Lifetimes Are Shrinking: the Manual-Renewal Era Is Over
By joint decision of the browser makers, maximum SSL/TLS certificate lifetimes started stepping down in March 2026, heading for 47 days by 2029. What awaits businesses that still renew by hand, and the path to ACME-based automation — inventory, patterns, monitoring.

AI-Powered Phishing and Deepfake Voice Fraud: Defending Against the New Generation of Scams
Phishing emails you could spot by their broken grammar are history; AI now writes flawless, personalised lures, and voice cloning produces a familiar boss on the phone. The process rules and technical layers that defeat "urgent transfer" calls and tailored phishing.

Bitwarden for Business: Organisations, Collections and Policies Done Right
You have chosen your password manager; now the work is building it correctly. Bitwarden's organisation structure, department-based collection design, the mandatory policies, and the safe migration off the passwords spreadsheet — step by step.