By the time an employee hands in their notice, the decisions that will make their departure clean or chaotic have already been made. They were made in the first weeks of that person’s tenure, when nobody was paying close attention because the new hire had just arrived and there were a hundred other things going on.

A shared login here. A quick SaaS sign-up there. A personal laptop used “just until the company hardware arrives.” By month six, none of those feel like decisions. They feel like how things are.

What’s Really Going Wrong When Offboarding Takes Three Weeks

A clean offboarding takes about 90 minutes of IT time. An account is disabled in your identity provider, which cascades access revocation across every connected tool. The device gets wiped. Email is forwarded to a manager or converted to a shared mailbox. Accounts in your CRM and project tools are reassigned. A handover document gets filed.

The messy version of the same process takes three weeks. It starts with a manual list of tools nobody can fully remember, which often means asking the departing employee to help reconstruct it. You find a Figma account, a Loom workspace, a Notion instance, and an Airtable base, all set up independently, all with passwords sitting in that person’s personal password manager. The laptop is at their home and they’re not in a rush to return it. A client emails asking about a strange message from a personal address. Six weeks later, a vendor charges the company card for a seat you thought you cancelled.

Whether your offboarding is 90 minutes or three weeks depends almost entirely on what was set up during onboarding.

Four Onboarding Shortcuts That Guarantee a Messy Exit

Letting new hires sign up for SaaS tools on their own. When a staff member creates an account independently — using their work email and a password only they know — that account is functionally theirs. You may not know it exists until a vendor invoice shows up, or until the account goes dark after they leave and a client project breaks. The fix is provisioning every tool through a central identity system, with each new SaaS application connected to single sign-on before the first user logs in.

Tolerating personal devices “just until we get them sorted.” Personal devices used for work don’t stay temporary. The employee installs apps, connects to client systems, and downloads files. By the time they leave, you have no ability to wipe company data from a device you don’t own and never enrolled in a management system. You’re relying on their goodwill — which is usually fine, but it isn’t a security control. The fix is company-owned hardware on day one, enrolled in mobile device management before use.

Shared logins for tools you didn’t want to pay per-seat for. When five people share a single login, you can’t remove one person’s access without changing the password for everyone — and you usually find this out when the person leaving is the one who originally set up the account and nobody else remembers the credentials. Per-seat licensing is the cost of doing this properly. The savings from shared logins reappear during offboarding as wasted hours and lingering access.

Letting client relationships live in one person’s inbox. For professional services firms, this is the most damaging pattern. When a senior person leaves, client context, email history, and active threads leave with them. From the client’s side, your business simply doesn’t know who they are anymore. A shared mailbox or CRM where client threads are consistently logged is a meaningful improvement over what most small businesses currently have.

How to Retrofit Hygiene on the Team You Already Have

You can’t re-onboard your existing staff, but you can audit what’s there and close the gaps before the next departure.

Start with a SaaS audit: pull three months of statements from every card used for business expenses and list every recurring charge. For each tool, identify who set it up, who uses it, whether credentials are shared, and whether the tool is connected to your identity system or running independently.

For devices, check whether every machine used for client work is enrolled in your device management platform. Personal devices that aren’t enrolled and aren’t covered by managed app access are a gap.

For identity, run a user access review — a list of every account in every system and what permissions it currently holds. The goal isn’t to find wrongdoing; it’s to find access that no longer reflects the person’s current role or the organization’s current structure.

What Your IT Provider Should Be Doing at Onboarding

A proper IT onboarding process provisions every new hire through single sign-on before their first day, enrolls their device in management before it touches company data, and documents what accounts and access were created — so that documentation can be used in reverse at offboarding.

If your current onboarding process is “set up the email and hand them a laptop,” the three-week offboarding you’re occasionally dealing with is the predictable result.

If you’d like to walking through what your current onboarding and offboarding process looks like from an IT perspective, we’re happy to take a look.