Keep this part in mind

Day 0: remove the ability to act for the company

Team discussing work around a laptop

The first objective is not documentation. It is control.

Disable the departing person’s individual sign-ins for business email, cloud storage, finance tools, customer systems, social platforms, and any other service where they had a named account.

Collect company-owned devices and physical access items according to company policy.

Day 0: rotate only the logins that need it

Do not change every password in the company automatically. Identify shared credentials the person actually knew or could retrieve.

Rotate those credentials and distribute the replacements through the approved channel.

Check this next

Day 0: transfer ownership

Account inventory for departing employee
List services before changing access.

Move ownership of documents, domains, advertising accounts, automation tools, repositories, or other assets that list the departing person as the owner or sole administrator.

A service can remain inaccessible even after a password change if ownership was never transferred.

Day 1: test business continuity

The next business day, confirm that remaining staff can still sign in and perform essential work.

Check shared mailboxes, scheduled automations, customer forms, billing alerts, and any workflow that previously depended on the departing person.

This order keeps it simple

Day 1: review recovery paths

Laptop and smartphone on a home-office desk

Look at recovery email addresses, phone numbers, authenticator registrations, backup codes, and security keys for critical accounts.

The business should not discover months later that account recovery still points to a former employee.

Day 7: look for quiet leftovers

A week later, review active sessions, app integrations, OAuth connections, API tokens, shared folders, and unusual login notifications.

These secondary connections are easy to miss during the urgency of departure day.

Keep this part in mind

Day 7: close the record

Record what was disabled, transferred, rotated, and verified. Note any account that could not be resolved so it remains visible rather than disappearing into memory.

Where a management tool fits

A password manager can help when shared credentials and access groups are already organized. The offboarding plan should still exist outside the product: the tool supports the process; it does not replace ownership decisions.

When comparing NordPass or another manager, test how quickly a real administrator can remove access and verify that remaining staff still have what they need.