Why Bad Onboarding Is the Real Cause of Messy Offboarding

Free Business professionals completing a successful deal with a handshake in a modern office setting. Stock Photo

By the time an employee gives notice, the hard part of offboarding has often already been decided.

It was decided in the first few weeks of that person’s job. A shared login was used because it was faster. A SaaS account was created outside the normal process. A personal laptop filled the gap until company hardware arrived. A client relationship stayed in one person’s inbox because everyone was busy.

At the time, these choices may have seemed harmless. By month six, they no longer feel like choices at all. They feel like the way the business works.

Then someone leaves.

Suddenly, your team has to find every login, every device, every client thread, every subscription, and every account tied to that person. What should take 90 minutes turns into three weeks of cleanup.

Messy offboarding is usually not an offboarding problem. It is an onboarding problem that has finally become visible.

What Clean Offboarding Should Look Like

A clean offboarding process is simple and controlled.

Your IT provider disables the employee’s account in your identity provider. That action removes access to every tool connected through single sign-on. The company device is collected or wiped. Email is forwarded to a manager or converted to a shared mailbox. CRM records and project work are reassigned. A handover note is completed and filed.

That kind of offboarding may take about 60 to 90 minutes of IT time.

The messy version looks very different.

Someone starts building a list of tools from memory. Nobody knows if the list is complete. The departing employee has to help reconstruct what they used. A Figma account appears. Then a Loom workspace. Then Notion. Then an Airtable base. Some passwords are in the employee’s personal password manager. The laptop is at their house. A client receives a strange message from a personal address. Weeks later, a vendor charges the company card for a seat that should have been cancelled.

That is not a technology failure at the end. It is a lifecycle failure at the beginning.

In identity management, this is called the joiner, mover, leaver lifecycle. The joiner phase is when a person starts. The mover phase is when their role changes. The leaver phase is when they exit. If the joiner phase is rushed, the leaver phase becomes cleanup.

Four Onboarding Shortcuts That Cause Pain Later

Letting New Hires Create Their Own SaaS Accounts

When a new employee signs up for a SaaS tool on their own, the business loses control from the start.

They may use their work email, but the password is theirs. You may not know the account exists. You may not be able to reset it without sending a notification to them. You may only discover it when an invoice appears or when a client project breaks after the employee leaves.

This is one of the main reasons businesses cannot find all the logins during offboarding.

The fix is to provision tools through a central identity system. New SaaS tools should connect to single sign-on before the first user logs in. That way, access belongs to the business, not to one person’s private setup.

Allowing Personal Devices as a Temporary Fix

Personal devices rarely stay temporary.

An employee uses a personal laptop while waiting for company hardware. They install apps. They open client files. They save credentials in the browser. They connect to company systems. Soon, that temporary setup becomes part of their daily work.

When they leave, you cannot safely wipe a device you do not own and never managed. You are relying on the employee to remove company data. Most people will try to do the right thing. But goodwill is not a security control.

The better approach is to issue company-owned devices on day one and enroll them in mobile device management. If personal devices are allowed, company email and files should be accessed through managed apps. That gives the business a way to remove company data without touching personal data.

Using Shared Logins to Save Money

Shared logins create some of the worst offboarding problems.

When five people use the same account, you cannot remove one person without changing the password for everyone. You may also lose track of who used the account, what they changed, and whether the departing employee still knows the password.

This often happens when a business does not want to pay per seat. But the savings come back as risk later. During offboarding, shared logins create wasted time, exposed access, and confusion.

Per-seat access is the cost of doing this properly. Each person should have their own account. When they leave, their access should be removed without disrupting everyone else.

Keeping Client Relationships in One Person’s Inbox

This is a common risk for agencies and professional services firms.

A senior account manager, consultant, or client lead owns the relationship. The email history lives in their inbox. Client preferences live in their head. Open questions sit in private threads. Half-finished work is hard for anyone else to see.

When that person leaves, the client relationship leaves with them in practical terms. From the client’s point of view, your business no longer seems to know who they are or what has been promised.

The fix is to keep client communication in shared places. Use a CRM. Set up shared inboxes or aliases for client-facing work. At minimum, use a Microsoft 365 shared mailbox and require client threads to be copied there.

The goal is not surveillance. The goal is continuity.

How to Clean Up the Team You Already Have

You cannot go back and re-onboard every current employee. But you can audit what exists now and close the biggest gaps before the next departure.

Start with the team you already have. The cleanup does not need to be complex. Most of it is operational. A spreadsheet, a few direct questions, and help from your IT provider can uncover a lot.

Run a SaaS Audit

Pull three months of credit card statements for every card used for business expenses. List every recurring SaaS charge.

For each tool, answer a few basic questions. Who set it up? Who owns the login? Is the account tied to a personal email or company email? Can someone else access it if that person leaves tomorrow?

You will likely find tools nobody remembers approving. You may find accounts used by one person with no backup access. You may also find subscriptions owned by former employees that the company is still paying for.

This does not require a major technical project. It requires a clear list and an honest review.

Build a Device Register

Next, build a simple device register. List who has each device, when it was issued, whether it is enrolled in a management system, and what company data it can access.

If you do not have this list, create it now. Ask each staff member to confirm what devices they use for work, including personal devices.

This does not need to be punitive. The goal is to understand the real environment. Most employees will answer plainly if they know the purpose is cleanup, not blame.

For any personal device that accesses company systems, use managed app access at minimum. Company email, files, and credentials should be removable when employment ends.

Move Client Communication Into Shared Systems

Client communication should belong to the business, not to one inbox.

Set up shared inboxes, aliases, or CRM logging for client-facing work. Start with the highest-risk accounts first. These may be large clients, active projects, sensitive matters, or accounts managed by only one person.

Even a simple shared Microsoft 365 mailbox is better than having the full client history locked inside one employee’s inbox.

What Your IT Provider Should Do During Onboarding

Many IT providers are called only when someone leaves. They disable the account, try to collect the laptop, and work from whatever notes exist.

That is the wrong end of the process.

Your IT provider should be involved when someone starts. They should create the user account in your identity provider. They should enroll the device in mobile device management. They should provision access through single sign-on. They should make sure the new employee’s tools are connected to a central identity that can be disabled later.

They should also help maintain a handover record. That record should list the systems the person uses, the client relationships they own, and the credentials tied to their role.

When that is in place, offboarding becomes a checklist. Without it, offboarding becomes an investigation.

Ask your IT provider what they do at onboarding. If the answer is “not much” or “we usually get called when someone leaves,” that is worth a serious conversation.

A 60-Day Plan Before the Next Resignation

You do not need to know who will leave next to prepare. The work is easier when no one is under pressure.

Weeks 1 and 2: Run the SaaS Audit

Review business credit card statements. List every recurring SaaS charge. Identify the owner, login method, and backup access for each tool. Flag any account that would be hard to access if one person left this week.

Weeks 3 and 4: Build the Device Register

Confirm what every employee uses for work. Include company-owned and personal devices. Enroll company devices in a management system if they are not already enrolled. For personal devices, require managed app access for company email and files.

Weeks 5 and 6: Review Client Communication

Find client relationships that live mainly in one person’s inbox or phone. Move the highest-risk accounts into shared mailboxes, aliases, or CRM logging first.

Weeks 7 and 8: Write the Onboarding Process

Use what you learned in the first six weeks to write the onboarding process you wish you already had. Apply it to the next hire from day one. Then use it as the template for handover records for current staff.

This work does not need to be perfect to be useful. It just needs to make access, devices, client ownership, and SaaS tools visible.

Frequently Asked Questions

How Long Should Offboarding Take in a Small Business?

With clean onboarding and centralized identity, the IT side of offboarding should take about 60 to 90 minutes. Without that foundation, it can turn into two or three weeks of scattered cleanup.

How Do I Find SaaS Tools My Team Signed Up for Without Telling Me?

Start with three months of credit card statements for every card used for business expenses. Most shadow SaaS tools show up as recurring charges.

Can I Wipe a Personal Device After Someone Leaves?

You can remove company data only if the right tools were set up while the person was still employed. Mobile device management or managed app access can remove company email, files, and credentials from a personal device. Without those tools, your options are limited.

What Is the Role of Single Sign-On in Offboarding?

Single sign-on ties each tool to one central identity. When that identity is disabled, access to connected tools is removed. Without single sign-on, each platform must be checked and updated by hand.

Should Employees Use Only Company Devices?

Where practical, yes. Company-owned devices are easier to manage, secure, and wipe. If personal devices are allowed, use managed app access or device management. A personal device with saved company credentials and no management is a high-risk setup.

Final Takeaway

If offboarding feels harder than it should, your onboarding process needs attention.

Shared logins, unmanaged devices, shadow SaaS tools, and client history trapped in one inbox all create problems later. They may not feel urgent when a person starts. But they become urgent when that person leaves.

Start by auditing what exists now. Build your SaaS list. Create a device register. Move client communication into shared systems. Ask your IT provider to help at the start of employment, not only at the end.

Caldera Cybersecurity can help you tighten the full employee lifecycle so the next departure is a checklist, not a scramble.

Related articles

You may also be interested in

Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.
Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Hot daily news right into your inbox.