Why Messy Offboarding Is Actually an Onboarding Problem
By the time someone hands in their notice, the decisions that will make their departure clean or chaotic have already been made. They were made in their first few weeks, when everyone was busy and the new hire was still finding their feet. A shared login here, a quick sign-up for a SaaS tool there, a personal laptop used until company hardware arrived. By month six, none of those feel like decisions. They feel like how things work.
When offboarding is messy, most business owners assume the problem is the exit. It is not. The problem is everything that happened at the start.
A clean offboarding - when things have been set up properly - takes an IT engineer about 90 minutes. An account is disabled in one place, and access to every connected tool is revoked automatically. The device is wiped remotely or collected and wiped on-site. Email is forwarded to a manager or converted to a shared mailbox. Client relationships and system access are handed over via a document that was templated at onboarding and just needs filling in.
The messy version of the same process can take three weeks. It starts with a manual list of tools nobody can fully remember, which often means asking the departing person to help reconstruct it. You find a project management tool, a video platform, a database, and a workspace, all set up independently, all with passwords in their personal password manager. Their laptop is at home and they are not in any rush. A client emails to say they received a strange message from a personal address. Six weeks later, a vendor charges the company card for a seat you thought had been cancelled.
The four shortcuts that cause this are consistent across almost every small professional services business. The first is letting staff sign up for software tools on their own. When someone signs up for a tool using their work email and a password only they know, that account is functionally theirs. You may not know it exists until an invoice appears, or until something breaks after they leave. The fix is provisioning every tool through a central identity system, where any new application is connected to your single sign-on - a system that ties all software access to one central login - before the first person uses it.
The second shortcut is tolerating personal devices temporarily. Personal devices used for work do not stay temporary. Files get downloaded, client systems get connected to, and what started as a stopgap becomes how the person works permanently. When they leave, you cannot wipe company data from a device you do not own and never enrolled in a management system. You are relying on goodwill, which is usually fine - but goodwill is not a security control. Issuing company devices on day one and enrolling them in a device management system is the standard that healthcare practices and law firms in particular cannot afford to skip.
The third is shared logins for tools the business did not want to pay per seat for. When five people share one login, you cannot remove one person's access without changing the password for everyone. The money saved on per-seat licensing reappears at offboarding as wasted hours and exposed access. The fourth, especially relevant in professional services, is letting client relationships live entirely in one person's inbox. When a senior adviser or account manager leaves, their client context leaves with them. The email history, the preferences, the half-finished threads - all inaccessible. From the client's perspective, your business simply does not know who they are anymore.
Most Canterbury businesses need to fix this for the team they already have, before the next hire arrives. The place to start is a SaaS audit: pull three months of credit card statements from every card used for business expenses and list every recurring software charge. For each one, find out who set it up, who holds the login, and whether anyone else could access it if that person left this week. You will find tools nobody remembers, accounts tied to personal emails, and seats still being charged for people who have already left. This is not a technical exercise. It is a spreadsheet and an afternoon. If you are unsure what your business is actually subscribed to, the decisions around cloud storage for small businesses are a useful place to see what a more deliberate approach looks like.
Alongside that, build a device register. A simple list of who has what, when it was issued, whether it is enrolled in a management system, and what company data it can reach. Ask every staff member to confirm what devices they use for work, including personal ones. Most people will confirm without issue once they know nothing punitive will follow. For any personal device with access to company systems, the minimum is making sure email and file access happens through managed applications that can be remotely disconnected when someone leaves. If you are not sure whether your current devices are up to that standard, it is worth checking the signs that your business devices need replacing before the next hire arrives.
The other piece most businesses are missing is where their IT support fits in this lifecycle. Most IT providers get called when someone resigns. They show up, disable the account, collect the laptop if they can find it, and do their best with whatever documentation exists. That is the wrong end of the process to be involved in. The model that works puts your IT engineer at onboarding too - setting up the new account, enrolling the device, connecting every tool to a central identity that can be switched off in one action. Managed IT support for professional services firms is built around exactly this kind of lifecycle management, covering both ends rather than just the exit. They should also maintain a handover document for each staff member, updated periodically, listing every system the person accesses and every credential tied to their identity. When that is in place, offboarding becomes a checklist rather than a three-week excavation.
Our medium sized business changed IT providers to IT Stuffed six months ago and the service has been excellent. We are making good progress to strengthening our IT infrastrucute and we have more confidence that our data and business security is improving.
Demelza Pearey
Our organisation engaged IT Stuffed a bit over a year ago and we have been very happy with their services to date. We value them being a local small business and appreciate their friendly yet professional interactions. They do not fluster easily and that has a calming effect on people with IT challenges. When faced with a cyber-attack a year ago we greatly appreciated the immediate and ongoing support we received from IT Stuffed. Happy to recommend this service.
Maggy Tai Rākena
If you are not sure whether your current setup would survive a clean departure, ask your IT provider what they do at onboarding. If the answer is mostly silence or "we usually get called when someone leaves," that is worth addressing before the next resignation arrives.
ITstuffed works with professional services businesses across Canterbury on exactly this - both ends of the staff lifecycle, not just the exit. A 15-minute IT Fit Check is a good place to find out where the gaps are.
