How do you account for company data after somebody leaves?
Executive Summary (TL;DR)
Employee departures are a normal part of business, but hybrid working has made the employee offboarding process harder to see, manage and prove. Disabling an email account may be straightforward. The real challenge is knowing which systems, shared spaces, permissions and devices a person could access, and whether company data remains on equipment outside the office.
A reliable process needs two things: clear visibility of access and devices, and a repeatable handover between HR, managers and IT. Technology can make these controls easier to apply, but it needs to support a process the business understands.
Every organisation has leavers.
Not every organisation knows what they leave behind.
An employee hands in their notice. HR completes the paperwork, their manager arranges a handover and IT is asked to close the account. On their final day, the laptop is returned and their email access is disabled.
The process appears complete. But the account may still contain important customer correspondence, project history or working documents, which can make the business reluctant to delete it. At the same time, keeping an account indefinitely because nobody knows what it contains leaves another loose end. Could anyone confidently answer all of these questions?
Who could confidently answer all of these questions?
These are rarely signs of deliberate wrongdoing. More often, they reveal that access has grown gradually while the person has worked for the organisation. When someone leaves, a business can often discover that no single person has a complete view of their digital footprint.
Why remote working changed the employee offboarding process
When most work happened in one office, on company equipment and within a defined network, the boundaries were easier to understand. Hybrid working has stretched those boundaries across home networks, cloud services, mobile apps, personal devices and third-party platforms.
Employees can now work productively without being physically close to the systems or people supporting them. That flexibility is valuable, but it also means company access may exist in more places than the formal offboarding checklist covers.
The same issue applies beyond permanent employees. Contractors may retain access after a project ends. Someone moving departments may keep permissions from a previous role. A temporary exception may remain in place long after the urgent task has passed. A shared account may continue to give access even when an individual account has been disabled.
This is why joiners, movers and leavers should be treated as one continuous access-management process. Access should change as a person’s relationship with the business changes, rather than being reviewed only when they leave.

Why manual employee offboarding processes break down
Offboarding failures usually arise from gaps between teams rather than obvious negligence. HR may assume IT has received the leaving date, while IT may be waiting for a manager to confirm which files, mailboxes or systems must be transferred. The manager may not know every application the employee used, particularly where teams have adopted tools independently. Temporary permissions and shared credentials can be missed because they sit outside the formal user account. A checklist helps, but it only works when ownership, deadlines and evidence are clear. Each departure should trigger one coordinated process that states who informs whom, what must be reviewed, when access will end and how completion will be recorded.
What well-governed organisations do differently
Well-governed organisations connect access to individual identities, review permissions regularly and use the same documented process for every departure. They include role changes and contractors, rather than treating permanent leavers as the only concern. They also consider devices alongside accounts, with an agreed approach for collecting company equipment, removing business information from managed personal devices and preparing returned devices for reuse. Just as importantly, they keep a record of each change and completed action. This creates a reliable trail of what happened, when and by whom, rather than leaving teams to reconstruct events later without the necessary information. The process is repeatable, auditable and understood by HR, managers and IT, which reduces its dependence on memory or one knowledgeable employee.
Technology helps, but governance comes first
Tools such as Entra ID and Intune can help organisations see who has access to what, apply consistent changes when someone leaves and manage company data on enrolled devices. Automation can reduce missed steps, but only once the business has agreed who owns the process and what should happen to accounts, files, permissions and equipment.
If defining, configuring and administering those controls feels unrealistic alongside day-to-day responsibilities, Vissensa can help assess the current setup and manage the technical elements on the organisation’s behalf.
The key question is whether the organisation can explain its offboarding process from notification through to verified closure. Once that process is understood, the right technology can reduce manual effort, create evidence and make missed steps less likely.
A quick self-assessment
Consider your current approach:
Could you identify every system a departing employee can access?
Do role changes trigger a review of old permissions?
Can you identify every device used to access company information?
Can company data be removed remotely from managed devices where required?
Can you produce evidence that each offboarding action was completed?
If any answers depend on someone’s memory, an informal message or a spreadsheet that is not routinely maintained, the process may be less reliable than it appears.
Vissensa can help you review the gaps, strengthen the process and put practical controls in place through our Onboarding and Offboarding Services.
FAQs business leaders ask about offboarding and onboarding processes
It is an important step, but it may not cover independent cloud applications, shared credentials, local files, personal devices or accounts that were created using a work email address. The wider digital footprint still needs to be checked.
That decision should follow the organisation’s retention, legal and operational requirements. In some cases, access needs to be blocked immediately while business data, mailbox responsibilities or device actions are handled before final deletion. The sequence matters because removing an identity too early may affect the organisation’s ability to complete some management actions.
Personal devices can be supported securely when the organisation has a clear policy and appropriate management controls. The risk grows when the business cannot identify which devices are being used or remove its data when access should end. For organisations using Microsoft 365, Intune can help manage enrolled devices and protect business data, while app protection policies can apply controls for accessing corporate data without requiring full management of the personal device.
There is no single schedule for every organisation. Reviews should reflect the sensitivity of the systems involved, the rate at which people change roles and the organisation’s compliance requirements. High-risk or privileged access should be reviewed more frequently than ordinary access.
How can you prove access has ended?
People will continue to join, move around and leave organisations. Hybrid working means those changes now affect a wider web of identities, applications, permissions and devices.
A sound offboarding process does not need to be dramatic or burdensome. It needs to be visible, repeatable and shared across the business. HR should know how to start it. Managers should know what information they must provide. IT should know which actions to complete. The organisation should be able to show that access and company data have been addressed.
If you cannot yet identify every relevant account, permission and device, begin by mapping them. That exercise will show where informal practices have developed, where responsibilities are unclear and where technology could remove unnecessary manual work. Vissensa can help you carry out that initial review.
Vissensa helps organisations review the way people, devices and data are managed across hybrid working environments, then configure practical controls around the way the business actually operates. For organisations using Microsoft 365, that may include reviewing identity, device management, access controls and the joiners, movers and leavers process already in place.
Want to understand what stronger offboarding could look like in your organisation? Explore how Microsoft 365 controls like Entra ID can help you manage identities, devices and company data more consistently.






