Chykalophia Docs
Risk & resilience

Offboarding a staff member across all your systems

A complete checklist for safely removing a departing team member's access to WordPress, Google Workspace, Microsoft 365, hosting, passwords, and more.

Difficulty
Beginner

When someone leaves your team — whether on good terms or not — their access to your systems must be removed promptly and completely. An overlooked account is an open door.

This guide gives you a complete, system-by-system checklist. It's the reverse of the onboarding checklist — and if you documented access when they joined, this becomes much easier.

Quick summary

Start with email and hosting — those are the highest-risk accounts. Work through every other system using your access record from onboarding. Transfer any files or data before deleting accounts. If the departure is not on good terms, act on the same day you learn about it.

Departures on bad terms — act today

If the departure is hostile, contentious, or you have any reason to believe the person may misuse access, complete this checklist on the same day. Do not wait. Change any shared passwords immediately. Contact us if you need help moving quickly.

Before you start

  • Retrieve the access record you kept from their onboarding. (If you didn't keep one, work through this checklist system by system.)
  • Decide whether their email address needs to stay active to catch incoming messages. You can usually redirect it to a colleague without keeping the account alive.
  • Confirm who is taking over any tasks, projects, or ongoing work in each system.
  • Allow adequate time — rushing leads to missed accounts.

Email & productivity suite

Google Workspace

Transfer their files first. Before removing the account, transfer their Google Drive files to a colleague or to a shared drive. Go to the Admin console, find the user, and use the data transfer option. See transferring files when someone leaves.

Set up an out-of-office or redirect on their Gmail if business emails will still arrive at their address. You can set a vacation responder or create a forwarding rule before disabling the account. See setting a vacation responder.

Remove them from Groups and Shared Drives. Go to Directory > Groups and remove them from all mailing lists. Then go to each Shared Drive they had access to and remove them as a member. See shared drives explained.

Suspend or delete the account. Suspending preserves their data and email; deleting removes the account permanently. Suspend first if you're not sure — you can delete later. Go to Users, find the account, and choose Suspend user or Delete user. See removing a user safely.


WordPress

Remove or downgrade their account. Log in to WordPress and go to Users. If they were an Editor or lower, delete the account and reassign their posts to another user when prompted. If they were an Administrator, first remove the Administrator role before deleting, to confirm you're not accidentally locking yourself out. See how to remove a user safely.

Check for application passwords. In WordPress, application passwords (used for API access) are separate from the main login. Go to Users, click their name, scroll to Application Passwords, and revoke any that exist.

Rotate the admin password if any shared WordPress admin credentials were in use. It's better practice to use individual accounts, but if sharing happened, change the shared password now.


Hosting

Remove their collaborator access in your hosting dashboard. The steps vary by host:

  • Flywheel: manage users in your Flywheel dashboard under the site settings.
  • WP Engine: remove them in the WP Engine User Portal under your account's user management.
  • Kinsta: remove them from MyKinsta under your company's team settings.

Revoke any SSH/SFTP keys they may have added. Check your hosting dashboard's SSH key management section and remove any keys linked to them.

Change FTP/SFTP passwords if any shared credentials were in use.


Password manager

Remove them from the organization vault. In your password manager's admin settings, revoke their membership. This immediately prevents access to all shared vault entries.

Rotate any passwords they had access to. Once removed from the vault, they no longer see new updates — but they may remember passwords from before. Rotate the passwords for any critical systems they could access. Prioritize: hosting, domain registrar, billing accounts, WordPress admin.


Two-factor authentication (2FA) devices

Revoke their trusted devices from every platform that allows it. In Google Workspace, go to the Admin console, find their account, and look for enrolled security keys or trusted devices to remove.

Remove them from any shared authenticator setups. If any 2FA was set up on a shared phone or device, remove those codes from the device.


Domain registrar

Remove their delegate access from your registrar account. Log in to your registrar (GoDaddy, Namecheap, etc.) and go to account settings or access management to revoke their permissions.

Verify the primary account email is not theirs. If the registrar account uses their email address as the contact, update it to a shared business email (like admin@yourbusiness.com) now. This is critical — if the contact email belongs to a former employee, they could receive renewal notices and account recovery emails.


Other systems

Work through every system on your access record. Common examples:

SystemSteps
ClickUpGo to your workspace settings and remove or deactivate their member account.
Google AnalyticsRemove them from the GA4 property's user management.
Google Search ConsoleRemove them from property user management.
Meta Business ManagerRemove them from Business Settings > People.
Mailchimp / KlaviyoRemove them from the account's user or team settings.
StripeRemove from Stripe Dashboard > Team.
ShopifyRemove staff from Shopify Settings > Users and permissions.
CloudflareRemove from your Cloudflare account's Members section.
GitHubRemove from your organization's team in GitHub.
FigmaRemove from the team or project settings in Figma.

After the checklist

When you're done

Confirm these are complete:

  • Email account suspended or deleted, files transferred
  • WordPress account removed and posts reassigned
  • Hosting access revoked
  • Password manager membership removed, critical passwords rotated
  • Domain registrar access revoked, contact email updated
  • All other systems cleared from your access record
  • Any shared passwords changed

Update your access record. Note the date of removal for each system. This is useful for audits and for confirming the offboarding is complete.

Keep their email address active for 30 days (as a suspended account or redirect) to catch any business correspondence that arrives.

Run a quick security check after the offboarding. See the business security checklist for a post-offboarding review.


Common questions

How quickly should I remove access?

For planned departures on good terms, completing the checklist on the last working day is fine. For unplanned or difficult departures, complete it on the same day you learn of the departure. Do not wait.

Do I need to delete their accounts, or is suspending enough?

Suspending is usually the right first step — it blocks access while preserving data. Delete after 30 days or once you've confirmed there's no data or correspondence to retrieve.

What if I didn't document what access they had?

Work through this checklist system by system. In Google Workspace and Microsoft 365, you can search for the person's email in each system's user or access management area. For WordPress, check the Users list. For password manager vaults, check the shared items. It takes longer, but it's completable.

Should I change all our passwords, not just theirs?

You should rotate passwords for any accounts where credentials were shared directly (not through individual named accounts). For accounts with individual named logins, removing their account is sufficient — you don't need to change your own password.

What about their personal device?

If they used a personal device for work (Bring Your Own Device), ask your IT administrator or us to review mobile device management settings. Work email on a personal device can be remotely wiped from the admin console in both Google Workspace and Microsoft 365 without wiping personal data. See managing company devices.


Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Last updated

On this page