Letting agency staff offboarding: an access-removal checklist
Applies to United Kingdom. This is general information, not legal advice — check the primary legislation or take advice before acting on a specific case.
A letting agency should start offboarding from a current access list, disable the person's main work identity at the agreed time, then remove or transfer every connected account, approval and physical-access right. Recover devices and keys, move live cases to named owners, review recent activity where the risk calls for it, and keep a completion record. The same process should cover employees, temporary staff and contractors.
Agencies hold tenant, landlord, applicant, contractor and payment information across many services. A departing property manager may also know communal alarm codes, hold property keys and own conversations that are not visible from the main property platform. The checklist therefore needs to follow the person's real work, not stop at their email account.
Set the trigger, time and owner before the last day
Record the person's final working time and whether access should end then or earlier. HR or the responsible manager should give one named offboarding owner the confirmed trigger. That owner coordinates IT, finance, branch management and anyone responsible for keys or devices. For an immediate departure, use the incident or urgent-leaver route instead of waiting for the normal checklist meeting.
The Information Commissioner's Office (ICO) says organisations should remove leavers' access rights in a timely manner, including access held by temporary and contract staff. Itsaccess-control audit guidance recommends a documented process, records showing access was removed and manager confirmation. It also recommends reviewing rights when somebody changes role, so the checklist should cover internal moves as well as departures.
Do not depend on the leaver to remember every account
Build one access map for digital and physical systems
Start with the agency identity provider or email directory, then compare it with application user lists, finance permissions, shared-password records and physical-asset registers. Add services bought directly by a branch or team, including free trials and browser extensions. Check for accounts created with the employee's work email and for supplier portals where another organisation controls removal.
| Area | Examples to verify |
|---|---|
| Identity and email | Work account, mailbox, forwarding rules, delegated access, groups, recovery details and active sessions. |
| Property operations | Property management platform, CRM, maintenance, inspections, inventories, referencing and document storage. |
| Money and approvals | Client accounting, banking, payment approval, payee changes, card access and expense tools. |
| External services | Landlord and tenant portals, contractor networks, utilities, deposit services, e-signing and supplier dashboards. |
| Physical access | Office passes, master keys, property keys, key-safe codes, alarm codes and smart-entry permissions. |
| Devices and data | Laptop, phone, removable media, local downloads, browser profiles, authenticator devices and paper files. |
The National Cyber Security Centre (NCSC) recommends a joiners, movers and leavers process so access can be removed when it is no longer needed. Its guidance for using software services securely says organisations should apply that process to internal and external users. A well-managed central identity can remove access from connected services together; applications outside it still need a separate task and owner.
Sequence the offboarding around the main identity
01
Prepare
Confirm timing, system list, work handover and asset register.
02
Disable
End the main identity, sessions and remote access at the agreed time.
03
Remove
Revoke separate apps, permissions, shared secrets and physical access.
04
Verify
Check account reports, returned assets, transferred work and exceptions.
Disable sign-in and remote access at the approved time, then revoke active sessions and any account-recovery methods controlled by the leaver. Removing a person from a team or hiding their name does not necessarily end an existing session. Check administrator roles, API tokens, mobile-app access, delegated mailboxes and remembered devices according to each service's controls.
Transfer ownership before deleting an account where deletion could remove records or break a workflow. Reassign open maintenance cases, inspections, tenancy progress, complaints, payment approvals and landlord conversations. Preserve business records under the agency's retention policy while preventing the former worker from accessing them. Do not keep an active user solely because a case still belongs to that user.
Deal with shared credentials and indirect access
Shared accounts make offboarding harder because disabling one personal identity does not change a password known by several people. Replace shared credentials the person could use, including alarm panels, key safes, social accounts and supplier portals. Update recovery email addresses and phone numbers. Where possible, replace shared sign-in with named users and role-based permissions.
NCSC's password-manager guidance says a joiners and leavers process should identify shared passwords an administrator could see and change them when that administrator leaves or changes role. Its broader identity and access guidance recommends using organisational sign-in for online services where available, so access can be revoked with the work account.
Review integrations installed by the user as well as their visible account. An email add-in, automation or API connection may retain access after the person's login is disabled. The NCSC SaaS guidance recommends keeping service identities visible, reviewing their permissions and removing integrations that are no longer needed.
Recover keys, devices and local copies
Match physical returns to an asset record. Collect office passes, master or property keys, phones, laptops, storage devices and paper files. Remove smart-lock permissions and change key-safe or alarm codes when the person knew a reusable code. The ICO physical-security toolkit recommends recording physical access rights and including their removal in the leavers' checklist.
For agency-owned devices, confirm who will secure, inspect and reissue them. For approved personal-device use, follow the agency's own-device policy for work accounts and local data. The ICO information-management toolkit recommends a leavers' checklist for returned mobile devices and automatic access revocation or remote blocking after the last day. Do not improvise a remote wipe of personal content without an established policy and authority.
Keep evidence that the checklist was completed
Use a record that another manager can review. A completed tick box without the system, operator or time gives little help when an access question appears later.
| Record | What to capture |
|---|---|
| Trigger | Leaving date and time, role change or contract end, plus the manager who authorised it. |
| Account action | System, account identifier, access removed or changed, operator and completion time. |
| Assets returned | Device, pass, key or file, its identifier, condition and recipient. |
| Work transferred | Owner of each live case, shared inbox, approval queue and supplier relationship. |
| Exceptions | Anything that could not be removed, the interim control, owner and deadline. |
| Final review | Manager confirmation, access report reviewed and any incident assessment opened. |
Review the account and asset reports after the work is finished. Record unresolved items with a temporary control and deadline, then have the responsible manager confirm closure. Sample previous leavers periodically to find systems or branch purchases that the standard checklist still misses.
If access remained open after departure
Remove the access, preserve relevant logs and establish what the account could reach and what activity occurred. Tell the agency's data-protection and security contacts. Unauthorised access to personal data can be a personal data breach, but discovering an open account does not by itself establish that information was viewed or disclosed.
ICO's personal-data-breach guidance says organisations must assess the likely risk to people's rights and freedoms. A report to ICO is required without undue delay and within 72 hours where the breach is likely to result in a risk. Keep the incident assessment even when the reporting threshold is not met, and take advice where the facts or deadline are uncertain.
Make access ownership part of normal agency operations
Add an owner and review date when a person receives a privileged account, shared secret or physical-access right. Give temporary access an end date where the system allows it. This shortens the leaver checklist and makes internal role changes easier to handle.
If you are mapping supplier and application access, use our AI supplier data-check guide. Finance permissions should connect to the bank-detail change workflow, so a leaver cannot keep or approve a payee change through a separate route. Agencies reviewing branch permissions can also use our multi-branch operating guide.
Tekniti runs this work for UK landlords and letting agencies — tracking it, preparing it, and holding what matters for a person to approve. See how it works for landlords or for letting agencies, or write to hello@tekniti.ai.