Someone leaves the company. You collect the laptop, deactivate the email account, update the org chart. Offboarding, done.
Except it usually isn’t, and the gap between “feels done” and “actually done” is bigger than most small business owners assume.
The numbers are worse than they sound
A 2025 study by Wing Security looked at how well businesses actually close out departing employees’ access, and found that 63% still have former employees with live access to corporate data through SaaS applications that were never properly deprovisioned (source). Not eventually cleaned up. Never touched at all.
A separate 2025 survey from Beyond Identity asked former employees directly whether they still had access to anything from their old workplace after leaving. 83% said yes to at least one thing, whether that was email, internal documents, or a work-related account. Only 40% of employees said their company device was actually wiped before they left, even though 53% of managers were confident it had been. Only 35% had their accounts reset or deleted as part of the process (source).
That gap, between what managers assume happened and what actually happened, is basically the whole article in one sentence.
Why this keeps happening
It’s rarely negligence, in our experience. Most small businesses just don’t have a written, system-by-system offboarding checklist, so the process defaults to whoever’s handling it that day, working from memory, under time pressure, often during a conversation that’s already stressful for everyone involved.
Disabling the main email account is the obvious step, and it’s the one that reliably gets done, because it’s the one everyone thinks of first. What tends to fall through is everything downstream of that. The VPN login that got set up separately. The shared password for the accounting software that five people know. The remote desktop access that got turned on eighteen months ago for a one-off reason and never turned back off.
Then there’s the one that gets missed most often, mostly because it doesn’t look like “access” in the way people picture it: the actual Windows account on the physical laptop the employee used every day. Disabling someone’s company email doesn’t touch that account at all. If the laptop gets handed to someone else without a proper wipe, or sits in a storage closet for six months before anyone thinks about it again, that login is often still sitting there, fully functional, waiting for someone to use it.
What “properly revoked” actually means
If you want to check whether your own offboarding process would hold up, here’s roughly what a complete one covers, beyond the email account.
The local account on the machine itself, not just the cloud services tied to it. Any shared logins the employee had, since a password five people know is a password that never really gets revoked, it just gets forgotten about. VPN and remote access permissions specifically, since these tend to get set up outside the main account system and are the easiest to overlook entirely. And an actual device wipe or reset before that laptop goes to anyone else, rather than assuming a password change on one account was enough.
Most businesses get through two or three of these fairly consistently. Very few get through all of them, every single time, for every departure, no exceptions.
The honest fix
Build a better checklist. You should, and it’ll close most of the gap. But a checklist only works if it’s followed completely, by whoever happens to be handling a particular exit, on a day that’s rarely calm. Even a good process has an off day somewhere along the way.
That’s really the gap Login AlertX fills here, not as a replacement for proper offboarding, but as the thing that catches it when a step gets missed anyway. If an account that should’ve been closed out weeks or months ago logs into a company machine again, you get an alert the moment it happens, not months later when something’s already gone wrong. Same story for a login from a laptop that was supposed to be sitting wiped in a closet, or a remote connection using credentials nobody remembers were still active.
You don’t need to trust that every step of every offboarding was handled perfectly. You just need to know if one wasn’t.
Login AlertX watches every login, failed attempt, and remote connection on your business machines and sends an alert the instant one happens, whether that account should still be active or not. See how it works.
