Someone’s last day at a Comox Valley workplace is usually full of cake, handshakes and a hurried transfer of “the important stuff.” What often gets skipped is quieter and more important: closing every door they could still walk through — email, files, apps, phones and shared passwords.

At Human Touch IT, we help clinics, trades shops, churches, nonprofits and small businesses across Courtenay, Comox and Cumberland turn offboarding into a calm, repeatable checklist. You do not need a corporate security team. You need a short list that someone owns every time a person leaves.

Why departed access is a Valley-sized risk

Most local teams run Microsoft 365, a few vendor portals (payroll, banking, booking, suppliers), shared inboxes like info@ or booking@, and at least one laptop or phone that signed into everything. When someone leaves — resignation, contract end, seasonal volunteer wrap-up — those credentials do not expire on their own.

Left open, a mailbox can still receive invoices or patient-adjacent mail. A OneDrive folder can still hold job files. An MFA authenticator on a personal phone can still approve a sign-in. A vendor portal password shared “just for convenience” can still move money or change shipping details. None of that requires drama. It only requires that nobody ran the checklist.

The first 24 hours

Speed matters more than perfect paperwork on day one. Aim for three moves before the leftover cake is gone:

  1. Disable the account — Block sign-in in Microsoft 365 (or your directory). Do not wait until you have finished reclaiming the licence.
  2. Revoke active sessions — Sign the person out of Outlook, Teams, browsers and mobile apps so a still-open laptop does not stay connected.
  3. Reset shared passwords — Wi-Fi guest keys, door codes where IT overlaps facilities, shared inbox passwords, and any login the departing person knew because “everyone used the same one.”

You can tidy licences, archives and documentation later in the week. Closing the door first prevents the awkward call that starts with “we think they can still get in.”

Microsoft 365 checklist

For most Courtenay, Comox and Cumberland offices, Microsoft 365 is the centre of the map:

  • Mailbox — Decide whether to convert to a shared mailbox, set a temporary forward to a manager, or archive. Avoid leaving a fully interactive user account live.
  • OneDrive — Transfer ownership of business files before deleting the account. Personal photos can wait; job folders cannot.
  • Teams — Remove from private chats, channels, tabs and shared files. Check guest access if they worked with outside contractors.
  • Admin roles — Strip Global Administrator, billing, Exchange and other elevated roles immediately. A former bookkeeper who still holds billing admin is a quiet liability.
  • Forwarding rules — Clear inbox rules and Outlook client rules that auto-forward mail offsite. This is a classic leftover.
  • Licences — Reassign seats only after access is closed, so you are not paying for an open door.

If your team also uses SharePoint libraries or a company SharePoint site, confirm group memberships the same day.

Beyond email: devices, MFA, portals and shared inboxes

Offboarding fails when it stops at the mailbox. Walk the rest of the list:

  • Devices — Collect or remotely wipe laptops, phones and USB keys. Confirm Bitlocker/FileVault recovery keys are documented for the business, not tied to a personal Microsoft account.
  • MFA apps — Remove authenticator entries and recovery codes from personal phones. Reset MFA for any shared accounts they helped set up.
  • Vendor portals — Payroll, banking, CRA Business Account helpers, booking systems, supplier portals, donation platforms — change passwords and remove user seats.
  • Shared inboxes — info@, booking@, donations@, reception@ — confirm who owns them now and remove the departed person’s aliases.
  • Door codes / alarm panels — Where your office mixes facilities and IT, loop in the person who manages physical access so codes rotate with staff changes.

Clinics care about patient trust and booking systems. Trades care about field phones and job-file folders. Churches and nonprofits care about volunteers, donation inboxes and board turnover. The checklist is the same; the emphasis shifts.

Who should own the list

Pick one owner — office manager, practice lead, or your MSP — and keep the checklist in a place you will actually open on a Friday afternoon. Human Touch IT often runs this with Valley clients as part of managed support: we disable accounts, revoke sessions, walk the M365 list, and flag vendor portals the owner still needs to touch (banks rarely let an MSP click “reset” alone).

You stay in control. We bring the calm sequence so offboarding does not compete with the farewell card.

A practical Friday question

Before the next goodbye lunch in Courtenay, Comox or Cumberland, ask: if that person tried to sign in tonight, what would still open? If the honest answer is “I’m not sure,” you already know the project for next week.

Human Touch IT is local MSP support with a human touch — Microsoft 365, cybersecurity hygiene and practical checklists for Island-sized teams.

👉 humantouchit.ai
📱 +1 250-792-0190 (call, text or WhatsApp)