Onboarding Process Mistakes That Turn Offboarding Into a 3-Week Job

By the time someone hands in their resignation, the hard part of their exit has usually already been decided. It happened months earlier, in the first few weeks of their onboarding process, back when nobody was watching too closely because the person had just started and there were a dozen other things going on.
A shared login here. A quick SaaS sign-up there. A personal laptop used "just until the new one arrives." None of it feels like a decision at the time. By month six, it's just how things are done. And it's exactly why offboarding, when it finally happens, can turn into a scramble.
Here at Affinity MSP, we see this pattern constantly with growing businesses: a clean exit takes about 90 minutes of IT work. A messy one takes three weeks. The difference almost always comes down to what was set up when the person joined, not what happens when they leave.
Why a weak onboarding process makes offboarding so painful
A well-run exit looks simple. Disable the account in your identity provider, and access drops away across every connected tool automatically. Collect or remotely wipe the device. Redirect the inbox. Reassign CRM and project records. Done.
The messy version starts with someone trying to remember every tool the departing employee ever touched. A Figma account here, a Notion workspace there, an Airtable base nobody else has logged into, most of it with passwords sitting in that person's own password manager. Their laptop's still at home and they're in no hurry to return it. A client calls to say they got a strange email from a personal address. A vendor charges the company card for a licence someone thought was cancelled months ago.
Identity specialists call this the "joiner, mover, leaver" lifecycle, and Microsoft documents it as a formal part of identity governance. Rush the "joiner" stage and you're paying for it in full at the "leaver" stage.
Four onboarding habits that guarantee a difficult exit
Letting new hires sign up for their own SaaS tools. Once someone creates an account with their own work email and password, it's effectively theirs. You often won't know it exists until an invoice turns up, or until it goes dark the day they leave and a project breaks. The fix is routing every new tool through central identity management, connected to single sign-on before anyone logs in for the first time.
Tolerating personal devices "for now." Temporary never stays temporary. Files get downloaded, apps get installed, and by the time someone leaves, you've got no way to remove company data from a device you don't own and never enrolled. Company-owned hardware from day one closes this gap. Where a personal device is unavoidable, managed app access for email and files is the minimum.
Sharing logins to dodge per-seat pricing. When five people share one login, you can't remove one person's access without resetting it for everyone else — usually discovered at the worst possible moment. Per-seat licensing costs more up front and far less at offboarding.
Letting client relationships live in one inbox. When a senior team member leaves, so does the email history, the context, and the half-finished threads that were never logged anywhere else. A shared mailbox or CRM with client threads CC'd in keeps that relationship with the business, not with one person's inbox.
Fixing what's already in place
You can't retroactively onboard your existing team properly, but you can close the gaps before the next departure:
- Run a SaaS audit. Three months of card statements will surface most of the tools nobody remembers signing up for.
- Build a device register. Who has what, whether it's enrolled in management, and what it can access.
- Move client communication to shared channels. Start with your highest-risk accounts first.
Most of this is a spreadsheet and a few honest conversations, not a technology overhaul.
What a good IT provider should be doing at onboarding, not just offboarding
Most IT providers only get a call when someone resigns. That's the wrong end of the relationship to be earning your fee at. A provider who's properly involved at onboarding sets up identity and device management from day one, connects every tool to single sign-on, and keeps a live handover document for each staff member. When that's in place, offboarding is a checklist, not an excavation.
If you're not sure what your current provider does at onboarding, that's worth a conversation — and it's exactly the kind of gap we help close as part of our managed IT services.
Frequently asked questions
How long should offboarding take for a small business?
With solid onboarding hygiene and centralised identity, expect 60–90 minutes of IT time. Without it, the same task can drag out over two or three weeks.
How do I find SaaS tools my team signed up for without telling me?
Review three months of business card statements. Shadow SaaS almost always shows up as a recurring charge.
Can I wipe a personal device after someone leaves?
Only the company data, and only if mobile device management or managed app access was set up while they were still employed.
What role does single sign-on play in offboarding?
It ties every tool to one identity, so disabling that identity revokes access everywhere at once — no manual logins required.



