The wrong first step when an employee leaves is often “delete the email account”. If the account owns contracts, customer correspondence, Drive files, calendars, social pages or recovery methods, immediate deletion can remove information the business still needs. But leaving access unchanged creates a different risk.
The safer order is: confirm authority, preserve records, block access, transfer ownership, redirect legitimate work, remove third-party access, then delete or archive according to policy.
1. Confirm the exit and who is authorised to act
Account changes should follow a documented instruction from the business owner, HR lead or another authorised person. Record the staff member’s final access time, the accounts in scope and who will receive their work.
For an involuntary or high-risk exit, access may need to be blocked immediately while data is preserved. For a routine handover, the employee may help identify files, customers and recurring tasks before access ends. Employment, privacy and retention obligations differ, so obtain appropriate professional advice for disputes, investigations or regulated records.
2. Build an access inventory
Do not stop at company email. Check:
- Google Workspace or Microsoft 365
- website and hosting accounts
- domain registrar and DNS
- social-media pages and advertising accounts
- banking, payment and accounting systems
- customer relationship and support tools
- cloud storage and shared drives
- password manager, authenticator and recovery channels
- code repositories, analytics and newsletter services
- company phone, SIM, laptop and removable storage
Shared passwords make offboarding much harder. Change them and move the organisation towards named accounts, role-based permissions and a business password manager.
3. Preserve business information before deletion
Identify the departing user’s email, documents, calendars and files. Transfer ownership to an active account controlled by the business. Do not move everything blindly into one employee’s personal area; use a shared drive, SharePoint site or defined records location where possible.
Google warns that important data should be transferred before a Workspace user is deleted. Its documentation says some deleted-user data can be restored only within 20 days, after which it may be unrecoverable. Google also notes that calendar ownership needs attention before deletion.
Microsoft’s offboarding guidance similarly places preservation and transfer before final account removal. Its workflow covers blocking sign-in, saving mailbox contents, forwarding email or converting the mailbox, transferring OneDrive access, removing licences and then deleting the account.
The exact retention window and options depend on the service, licence and configuration. Verify them in the live admin console rather than treating any article as a substitute for the product’s current documentation.
4. Block access and revoke active sessions
Reset the account password to a unique value controlled by the administrator, block sign-in and revoke active sessions or tokens. Remove the user’s registered multi-factor methods and recovery details where the platform permits.
If the staff member used a company phone or laptop, collect it and check whether remote management is enabled. A remote wipe should target business data and be authorised; it can destroy information and may affect personal data on a bring-your-own device.
Disabling the main account does not necessarily end access to third-party apps. Review connected applications, API tokens, app passwords, VPN access, SSH keys and remembered browser sessions.
5. Keep customer communication working
Decide what happens to new mail. Options may include forwarding to a replacement, converting a mailbox to a shared mailbox, adding an automatic reply or keeping an alias for a defined period.
An automatic reply should identify the new business contact without revealing unnecessary information about the employee’s departure. Forwarding should have an owner and an expiry date; forgotten forwarding rules can expose correspondence for years.
Update public contact pages, proposals, email signatures, helpdesk assignments and customer records. A secure exit that silently abandons customer messages is still an operational failure.
6. Transfer ownership, not just copies
A copied file may still depend on the former employee’s account. Confirm ownership and access for:
- Drive and Docs files
- shared folders and SharePoint content
- calendars and recurring meetings
- forms and their response sheets
- dashboards and analytics properties
- social channels and ad accounts
- developer, app-store and code assets
- domains, hosting and SSL management
Use at least two current administrators for critical business services. No single employee, contractor or external agency should be the only owner of a domain, website, payment account or social page.
7. Remove the account only after verification
Test the handover from the receiving account. Open representative documents, locate recent messages, check calendar ownership and confirm that customer mail reaches the right person. Export or retain logs required by the business.
Only then remove licences and delete, archive or retain the account according to policy. Record the date, administrator and completed checks. Schedule a follow-up review after seven days and again after 30 days to find forgotten integrations or messages.
What this means for Nigerian small businesses
Many small businesses run critical operations through personal Gmail accounts, WhatsApp numbers and an agency-controlled website login. That may feel convenient until the person leaves, a phone is lost or a relationship breaks down.
The long-term fix is organisational ownership:
- register business services with company-controlled addresses;
- keep domain and hosting ownership visible to the business;
- give each worker an individual account;
- use shared locations for customer and operational records;
- require two administrators for critical platforms;
- maintain an access register and quarterly review;
- back up information that cannot be recreated.
Offboarding should be designed before anyone leaves. A one-page checklist protects both the company and the departing worker by making the process consistent instead of personal.
Frequently asked questions
Should we delete the account on the employee’s final day?
Block access at the agreed time, but preserve and transfer required data before deletion. The correct retention choice depends on the platform, business need and legal obligations.
Can we simply change the password?
No. Existing sessions, tokens, recovery methods and third-party integrations may remain. Block sign-in, revoke sessions and review connected access.
Who should own the transferred files?
Prefer a business-controlled shared location or accountable role rather than another person’s private account. Ensure at least two authorised administrators can reach critical systems.
Continue reading on Tech Embed
- The 3-2-1 backup plan for Nigerian small businesses
- How to protect business accounts with stronger passwords
Topic hub: Explore more in Cybersecurity in Nigeria.
