Insight: Leavers are a security event, not an admin job
New starters get all the attention. Leavers are where the risk sits.
When someone joins, the process runs itself. There is a start date. A manager is asking. Often the person is standing in front of you with nothing to work on. The pressure is visible, so the work gets done.
When someone leaves, none of that applies. There is no one waiting. Nothing visibly breaks if the account stays open a few more days. No client complains. So the leaver request sits behind whatever is louder, and it is always behind something louder.
That asymmetry is the whole problem. Every day the account stays open, it belongs to somebody who no longer works for you and no longer answers to you. It still reaches your email, your files and your clients' data. You are still paying for it.
What an open account actually gives someone
Most businesses picture a leaver's account as a mailbox. It is more than that.
It is the mailbox, the calendar and everything in it. It is the file store, which for most firms now means the whole company file store, not just their own folder. It is Teams and the conversation history in it. It is any third-party application they signed into with their work identity, which is usually more applications than anybody remembers. And if they used their own phone for work, all of that is sitting on a device you do not own and cannot see.
None of this requires bad intent to become a problem. Someone forwards a document to their new employer because it seemed useful. A personal phone with company email on it is sold, or lost, or handed down to a teenager. An account nobody is watching is an account nobody notices being used.
Every certification and questionnaire asks about this
Cyber Essentials requires you to remove access promptly when someone leaves. ISO 27001 requires a documented process and evidence that you follow it. So does almost every client due diligence questionnaire and supplier security review that lands in your inbox.
Note the word evidence. Having a process is not the point. Being able to show that a named person left on a named date, that a request was raised, and that the change was made and confirmed, is the point. That is why leaver requests should be in writing and tracked, not mentioned on a phone call.
This is also why it deserves a periodic review rather than a one-off write-up. Your systems change. Your team changes. A leaver process written eighteen months ago will not mention the three applications you have adopted since.
Make it a step in the HR process, not a favour
The single change that fixes most leaver problems is structural, not technical. Notifying IT should be a fixed step in your HR leaver process, triggered the moment notice is given or the decision is made. Not an email someone remembers to send. Not a task that depends on one person being in the office.
Give IT the leaving date as soon as you have it. A known date means the work can be scheduled precisely rather than done in a rush after the event.
Decide the business questions before the last day
Removing access is the easy half. The half that causes trouble later is everything around it, and almost all of it needs a decision from a manager rather than from IT.
- Their files. A manager or colleague should go through their work, keep what the business needs and file it where the business can find it. This has to happen before access is removed, not after. Recovering files from a closed account is possible. It is also slower, more expensive and less complete than five minutes of a colleague's attention while the account is still live.
- Their mailbox. Somebody needs to read what arrives after they have gone, and somebody needs to inherit the relationships in it. Decide who, and for how long.
- Their automatic reply. Decide what it says and who it points people to. Clients notice this one.
- Their licences. Reclaim or reassign them. Firms routinely pay monthly for people who left a year ago, and it goes unnoticed because the amount is small and the line item never changes.
- Retention. Some data has to be kept, for a defined period, for legal, regulatory or client reasons. Decide what and how long before anything is deleted.
Do the personal device removal in the exit interview
This is the tip that saves the most trouble, and it costs nothing.
While the person is still in the room, have company email, Teams, SharePoint and any file-sharing app removed from their own phone, tablet or home computer, and watch it happen.
In the meeting it is a formality that takes two minutes. A week later it is a negotiation with someone who no longer has any reason to co-operate. Where the device is enrolled and managed, company data can be removed remotely, but not every personal device is enrolled, and consent is far easier to obtain face to face than by email.
Where it goes wrong quietly
The disciplinary and dismissal cases feel like the risky ones, and they need care. Tell your IT partner in confidence before the meeting. Changes can be prepared in advance and scheduled to run at a set time, so access closes at the moment the outcome is delivered rather than an hour of awkwardness later.
But the cases that cause most of the damage are ordinary. Someone leaves on good terms. The handover goes well. Everyone is busy. Three months later a licence audit finds four accounts belonging to people nobody has seen since spring.
That is not a technology failure. It is a process that was never written down.
Ratcliff IT is an IT, cybersecurity and AI partner for businesses in London. If you want help building a leaver process into your own HR procedures — or you would like our one-page leaver guide to circulate internally — see how we support London businesses, or get in touch at hello@ratcliff.it or 020 3551 6262.

