Join our Newsletter — 33% off our NHI Course

How should employees handle work accounts before leaving a job?

Employees should inventory every work related account, then decide which ones to transfer, close, or retain with employer approval. Start with SSO or password manager records if available, because they usually provide the clearest view of access. Where accounts stay active, remove access from personal devices and confirm the plan with a manager or IT contact before the last day.

What should happen to work accounts before a job change?

Leaving a job is not just an HR event, it is an access transition. The practical question is which accounts are employer-owned, which are tied to business operations, and which still create risk after departure. The right handling depends on whether the account contains company data, controls a business system, or can still authenticate from a personal device.

Start by separating accounts into three buckets: accounts that should be transferred, accounts that should be closed, and accounts that must remain active for a short period with explicit employer approval. That classification step is more important than the order of cleanup, because it determines whether the account needs handover, revocation, or monitoring before the last day.

Where possible, use NIST SP 800-63 Digital Identity Guidelines and access records from an SSO or password manager to build the inventory, then confirm the status of any account that is not visible in those systems. A complete inventory should include SaaS apps, cloud consoles, finance tools, support tools, and any service logins that were used for day-to-day work or approval workflows.

Which accounts should be transferred, closed, or retained?

Transfer accounts when the employer needs continuity, such as shared business profiles, admin roles, or vendor relationships that must stay under company control. Close accounts that were created for the employee alone and no longer serve a business purpose. Retain only the accounts that are intentionally needed after departure, and only with a named owner, an end date, and an approval trail.

Accounts that stay active should not keep broad personal access. If the account was reachable from a personal laptop or phone, remove that access path, invalidate saved sessions, and ensure the employee can no longer use personal devices to sign in after the departure date. That matters because account access can outlive the employment relationship even when the person no longer has company hardware.

One useful control is to confirm the handoff with the manager or IT contact before the final day, not after the employee has already left. That gives the business time to resolve ownership questions, reset shared credentials where necessary, and make sure no account is left active simply because it was overlooked in a long list of tools.

What should employees verify before their last day?

Employees should verify that every account has a clear disposition: transferred, closed, or retained with approval. They should also confirm that the employer knows where sensitive records, billing contacts, admin invitations, and recovery methods are stored, because those details often determine whether the account can still be managed after exit.

A good final check is to review any password manager, browser-saved login, or mobile authenticator entry that might still point to work systems. Even when the account itself is closed, residual sign-in methods, remembered sessions, or backup recovery routes can leave an avoidable access path behind if they are not explicitly removed.

If the role involved privileged or shared access, the exit review should be stricter than a simple password reset. The key question is whether the account can still affect business systems, customer data, or approvals after the employee leaves. If it can, the account should be treated as a governance item, not a convenience item.

Risk and Threat Considerations

The main risk is orphaned access: accounts, sessions, and recovery paths that remain valid after the employee is gone. That can create unauthorized access, make investigations harder, and leave the employer dependent on the former employee to remember to hand back access.

Failure mechanism: Offboarding breaks when account ownership is unclear, when access is spread across multiple tools, or when personal devices still hold active sign-in state. In that case, an account can remain usable even after payroll, badge, or laptop access has ended.

Impact: The result can be data exposure, unintended transactions, missed revocation, or continued access to systems that should already have been reassigned or closed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Exit handling depends on authenticators, sessions, and recovery paths tied to a person's work identity.
Recommendation — Review authenticators and recovery routes before departure, then revoke any sign-in path no longer needed.
NIST SP 800-53 Rev 5 AC-2 — Account Management Account disposition, transfer, and termination are central to offboarding work accounts.
IA-5 — Authenticator Management Saved credentials and authenticators can keep work access alive after departure.
Recommendation — Discontinue, transfer, or retain accounts only with documented ownership and approval. Rotate or revoke authenticators and stored credentials tied to departing employees.
ISO/IEC 27001:2022 A.5.16 — Identity Management The question is about governing account ownership and lifecycle during employee exit.
Recommendation — Ensure each work account has a named owner and a defined offboarding disposition.
CIS Controls v8 CIS-5 — Account Management Offboarding requires removing or reassigning accounts and access paths promptly.
Recommendation — Remove or reassign accounts promptly and confirm inactive accounts are disabled.

Practitioner Guidance

What to prioritise: Treat business continuity and access removal as one workflow. The first priority is to identify any account that can still reach production systems, finance tools, customer data, or admin functions, because those are the accounts that create the largest residual risk if they are missed.

What to verify: Do not trust a verbal handoff alone. Verify that each account has an owner, a disposition, and a removal or transfer action completed, and confirm that personal devices no longer have a live sign-in path or remembered session for work services.

Practitioner takeaway: The safest exit is not “close everything immediately,” it is “make every work account accountable before the employee departs, then remove any access that no longer has a business owner or business need.”