Here is an uncomfortable exercise. Think of the last two people who left your business. Can you say, with certainty, that neither of them can still read company email, open the shared drive, log into the accounting system, or see the customer list? In most small businesses the honest answer is "probably not", followed by a pause, followed by someone opening a laptop to check.

Nobody plans to leave an ex-employee with the keys. It happens because access is granted one urgent day at a time, and revoked never.

How the gap opens

Access accumulates the way clutter does. A new hire needs email on day one, the job-costing system in week two, the supplier portal in month three, the bank's approval app when a manager goes on leave and someone must release payments. Each grant is small, reasonable and urgent. None of it is written down, because everyone is busy and the person is standing right there.

Then, two years later, they resign — on good terms, usually — and the offboarding consists of a farewell lunch and a returned laptop. The email keeps working because a client "might still write to them". The shared warehouse password doesn't change because changing it means telling six people. The accounting login survives because nobody remembered it existed. There is no malice anywhere in this story, and that is precisely why it is so common.

You cannot revoke what you never recorded. The real offboarding failure happens at onboarding, when access is handed out and written down nowhere.

The register is the fix

The unglamorous heart of access control is a list: for each person, every system they can reach, the level of access, and who approved it. Keep it anywhere durable — a page per person is enough. The moment this register exists, offboarding stops being an archaeology project and becomes a checklist you run in an hour. It also answers the auditor's and POPIA question — "who can see personal information in your business?" — with a document instead of a shrug.

Two habits keep it honest. Every new access grant gets a line in the register at the moment it is granted, no exceptions. And once a year, a manager reads each person's page and asks whether they still need each item — because roles drift, and the person who moved from sales to dispatch eighteen months ago almost certainly still has sales access.

The leaver checklist

  • Disable the identity first. Email and single sign-on are the master keys; turn them off on the last working day, and everything connected to them dies with them.
  • Transfer, don't delete. Move ownership of files, documents and records to a colleague. Forward the mailbox for a defined period. Deleting an account on day one destroys history you may need.
  • Rotate every shared secret they knew. The Wi-Fi, the alarm code, the shared "admin" login, the social media accounts. A password manager makes this an hour's work instead of a week's.
  • Remove the physical and financial layers. Keys, tags, fuel cards, bank approval rights, signatory powers, the company card saved in their browser.
  • Sweep the informal channels. WhatsApp groups, supplier portals, the courier's booking site, the CCTV app. These outlive employment more reliably than anything official.

The two-leaver audit

Take the last two people who left. Check three things for each: does their email still accept a login, does one shared password they knew still work, and can their account still open your line-of-business system? Thirty minutes, and you will know whether you have a process or a hope.

When it isn't amicable

Most exits are friendly, and the checklist can run with ordinary courtesy. A dismissal, a retrenchment or a resignation in anger is different: access is disabled when the conversation happens, not at close of business. This is not paranoia — the overwhelming majority of insider incidents in small businesses happen in the window between "it went badly" and "IT got around to it". Having the register means this can be done in minutes, calmly, without the theatre of guessing what to switch off.

It protects the leaver too. When the stock count is wrong three weeks later, the person whose access verifiably ended on the 31st is above suspicion — the same logic as an audit trail, which protects the innocent far more often than it catches the guilty.

An hour a month, honestly kept

Joiner, mover, leaver: three moments where access changes hands. A business that writes down what it grants, reviews it yearly, and runs a checklist on every exit has closed one of its largest unpriced risks — for the cost of a register and an hour a month. The business that doesn't will find out what it forgot at the worst possible time, from the worst possible person.