cybee

Menu

Start freeDeutsch

A freelancer leaves. What access do you remove?

A practical contractor offboarding checklist for agencies: accounts, shared files, AI connections, client keys and the handover record.

Two colleagues make a calm project handover beside a packed laptop bag.
Illustrative scene.

What should a small team include in contractor offboarding?

Agree when work ends, preserve the information your business needs, then remove the person’s accounts, sessions and project access. Review shared credentials, AI connections and automated jobs separately. Confirm who owns unfinished work and record what changed. Removing someone from the team chat is only one item in the process.

Agree the handover before the final day

The developer has finished the build. The designer has delivered the files. You have paid the final invoice. What is less visible is the access accumulated along the way: client folders, deployment tools, shared passwords, an AI connector and a scheduled report that runs under the freelancer’s own account.

Pick an offboarding owner and agree the time access should end. List active projects, outstanding deliverables and the person taking over each one. For company information that must be kept, decide how it will be transferred before deleting accounts. A planned handover avoids forcing someone to choose between blocking access and preserving the work.

Check each account, not just the main login

Work through company email, shared drives, chat, repositories, design tools, customer systems and any administrative roles. Ask whether access came through a team invitation, a personal account, a shared credential or a client’s own administrator. Different routes require different actions. Closing the main company account may not close every independent account.

Use each service’s current instructions to end access and active sessions. Google, for example, documents password resets and sign-in cookie resets as separate controls. Check connected app grants too. Keep a record of the changes and any client administrator who still needs to act, instead of marking the whole departure complete too early.

End access without losing the work

  1. Transfer

    Give active work a new owner.

  2. Remove

    End accounts, grants and shared access.

  3. Verify

    Record results and unresolved items.

Example workflow.

Include the tools that work without the person

Ask the freelancer which assistants, MCP connections and automation platforms they used. A job may keep running after the person leaves, or stop unexpectedly because its owner’s account was closed. Decide which automations are still required, transfer responsibility where supported and verify that continuing work uses an approved company or client account.

Review shared API keys at the service that issued them. If the departing person had access to a key that should remain private, arrange replacement as appropriate and test the dependent workflows. Removing a local connector does not revoke a credential. Do not ask the freelancer to paste secret values into the handover document.

Treat company and personal devices differently

For a company Mac, arrange return and check its state through your authorised management process. For a personally owned device, follow the agreement about company files, access and permitted management. Do not assume you can erase someone’s personal laptop. Record the return or agreed deletion confirmation, with any unresolved issue clearly assigned.

Be precise about what you can verify. Removing access to a shared folder prevents that route being used again; it does not demonstrate that no copies exist elsewhere. If sensitive material or suspicious activity is involved, use your incident process. Routine offboarding and investigating a possible incident require different decisions and records.

Leave a record the next person can understand

Your final record can be short: person, projects, end date, services reviewed, access removed, assets returned and outstanding exceptions. Add who checked it. A temporary support account should have a purpose and an expiry, rather than living indefinitely under “just in case”. Revisit exceptions until each has been resolved or explicitly accepted.

Cybee connects the Mac security review with AI-tool visibility and your connected Google Workspace environment. Use that information to guide the departure checks and keep relevant records. Services outside that scope still need their own review. The goal is an orderly end to access, while your client’s project continues without depending on a departed contractor.

What to remember

  • Preserve required work before deleting accounts.
  • Review AI connections, shared keys and unattended jobs.
  • Record exceptions and verify access ends in each relevant service.
Sources and further reading

Product scope and provider guidance can change. Check the linked source for your own setup.

Put it to work.

Continue with a practical guide or see how cybee helps with the work.