Day 0: remove the ability to act for the company
The first objective is not documentation. It is control.
Disable the departing person’s individual sign-ins for business email, cloud storage, finance tools, customer systems, social platforms, and any other service where they had a named account.
Collect company-owned devices and physical access items according to company policy.
Day 0: rotate only the logins that need it
Do not change every password in the company automatically. Identify shared credentials the person actually knew or could retrieve.
Rotate those credentials and distribute the replacements through the approved channel.
Day 0: transfer ownership
Move ownership of documents, domains, advertising accounts, automation tools, repositories, or other assets that list the departing person as the owner or sole administrator.
A service can remain inaccessible even after a password change if ownership was never transferred.
Day 1: test business continuity
The next business day, confirm that remaining staff can still sign in and perform essential work.
Check shared mailboxes, scheduled automations, customer forms, billing alerts, and any workflow that previously depended on the departing person.
Day 1: review recovery paths
Look at recovery email addresses, phone numbers, authenticator registrations, backup codes, and security keys for critical accounts.
The business should not discover months later that account recovery still points to a former employee.
Day 7: look for quiet leftovers
A week later, review active sessions, app integrations, OAuth connections, API tokens, shared folders, and unusual login notifications.
These secondary connections are easy to miss during the urgency of departure day.
Day 7: close the record
Record what was disabled, transferred, rotated, and verified. Note any account that could not be resolved so it remains visible rather than disappearing into memory.
Where a management tool fits
A password manager can help when shared credentials and access groups are already organized. The offboarding plan should still exist outside the product: the tool supports the process; it does not replace ownership decisions.
When comparing NordPass or another manager, test how quickly a real administrator can remove access and verify that remaining staff still have what they need.