
How to Onboard and Offboard Employees the Secure Way
Every employee who joins your firm gets handed keys: email, client files, the practice management system, the billing platform. Secure onboarding and offboarding is the discipline of handing those keys out deliberately and getting every single one back the day the person leaves, from a checklist rather than from memory. Most firms manage the first half badly and the second half barely at all. Onboarding is a scramble to get the new person productive. Offboarding is an afterthought that happens days or weeks later.
Sometimes never.
What stays behind when someone leaves
Think about what a departing staff member can typically still reach: client financial records or case files, years of email, the document archive, billing histories, internal chat. If those doors stay open after the person walks out, you're exposed in every direction at once. Compliance frameworks assume prompt revocation. Attackers love orphaned accounts precisely because nobody's watching them. And there's a business risk that gets discussed far less than either, which deserves its own story.
The pattern with the client list
There's a story that operations consultants and employment lawyers both recognize on sight, because a version of it plays out somewhere every single year. The details move around. The shape doesn't.
A senior person leaves the firm. Decent terms, cake in the break room, no drama. Whoever half-handles IT disables their email, because email is the thing everyone remembers. The practice management login survives, because nobody owns the job of killing it and the offboarding checklist is a vibe rather than a document. Months pass. The firm notices client attrition creeping upward, one quiet disengagement at a time, and the departures are oddly concentrated: they're the clients the departed employee used to handle. When someone finally pulls the access logs, there it is. Logins, long after the leaving date. Contact details, engagement histories, fee arrangements, all of it browsable from a couch.
The client list didn't get hacked. It walked, through a door the firm forgot it had issued a key to.
What makes the pattern instructive is that it's three failures wearing one face. An operations failure, because no checklist meant no revocation. A security failure, because nobody reviewed who could reach what. And a growth failure, because the damage surfaced as lost revenue that took months to trace back to its cause. It's also a clean illustration of why MFA on its own won't save you. MFA verifies that the right person holds the account. It has no opinion about whether the account should still exist.
Onboarding, done properly
Good onboarding gets the new person productive fast and sets the security norms on day one, in the same motion. The two goals aren't in tension. A person who's given the right access immediately never learns to borrow someone else's.
Before their first day, provision their accounts. Email, practice management, whatever the role needs, ready when they arrive, because the alternative is someone sharing credentials as a temporary measure, and temporary measures in firms have a way of celebrating anniversaries. Grant access by role and no wider. The new bookkeeper doesn't need the M and A folder. This is least privilege, and it's the cheapest security control that exists. Prep the hardware too: encryption on, endpoint protection installed, firm policies applied before the laptop ever reaches a desk.
During the first week, run security training before they touch client data, not after. Password manager, phishing basics, how to report something weird without embarrassment. Set up MFA on every system that supports it and don't present it as optional. Get the policy signatures done, acceptable use and data handling both. And pair them with a buddy who models the right habits, because new hires copy what they see far more faithfully than what they signed.
Offboarding, the same day
The revocation clock starts the moment employment ends, and the first hour matters most.
In that hour: disable every account. Disable, don't delete, since you'll need the data, but access dies now. Remote access and VPN go first, then MFA tokens come off their devices, then any shared passwords get rotated. Ideally shared passwords don't exist, but reality is messy, and the messier your reality, the faster you rotate. Collect the hardware before the goodbye lap.
Within 48 hours, pull the file access logs for the final few weeks and look for bulk downloads or odd hours. Forward their email to a named colleague so client messages don't fall into a void. Tell affected clients who their new contact is, in your words, before the departure announcement does it for you. And write down what they were working on and who inherits it.
Within 30 days, archive their mailbox and files per your retention policy, then audit for leftover permissions in every system. That last sweep always finds something. Always.
The mistakes that undo all of it
Shared logins top the list. When five people use one login, you can't revoke one person without disrupting four, so nobody revokes anything. Individual credentials, every system, no exceptions.
Forgotten third-party tools come second. Your checklist covers the core systems, but what about the design tool, the scheduling app, the seat on a client's own portal? Your vendor inventory doubles as the offboarding map, and without one you're guessing which accounts even exist.
Then there's the process that lives in one person's head, executed from memory, differently each time. Write it down and name an owner.
And the softest mistake: treating friendly departures casually. The checklist doesn't care about the going-away card. Run it identically for the beloved retiree and the abrupt resignation, because the exposure is identical, and because a consistent process is the only kind anyone actually follows.
The seasonal people count too
Firms that build a careful process for permanent staff often run none at all for everyone else. The temporary preparer who joins for filing season. The contractor who built the website two years ago. The outsourced bookkeeper whose engagement ended in the spring. All of them got access because they needed it to do the work, and access granted for a season has a way of outliving the season by years.
Put every non-employee with credentials on the same checklist as employees, with one addition: an expiration date set the day the access is granted. A seasonal account that shuts itself off on April 30th doesn't depend on anyone remembering anything, and April-you will have made a decision that exhausted-May-you never has to. If the person returns next season, reactivating an account takes minutes. Discovering in November that last year's temp could still open client returns takes considerably longer to explain.
Let the systems do the remembering
Manual offboarding leaks. If your firm runs single sign-on, one disabled account cascades across everything behind it, which turns an afternoon scavenger hunt into a switch. That's also an argument for SSO in the tech friction column, so it pays twice. Identity management tools go further and deprovision across systems automatically. Smaller firms can get most of the way there with a maintained checklist and named owners, which costs nothing but discipline.
Getting keys back should feel as unremarkable as handing them out. The firms that treat it that way protect their clients, their reputation, and the client list that took twenty years to build. There's more on making processes survive busy seasons in our firm operations guide, and if you'd like a second set of eyes on your offboarding checklist before the next resignation letter arrives, we're easy to reach.



