
When someone leaves your charity or non-profit, there is usually a familiar list to work through. Payroll needs an update. Keys and equipment come back. Their manager figures out who will take over unfinished work.
Their technology access needs the same attention.
A departing employee, contractor, volunteer, or board member may still have access to email, shared files, Microsoft 365, your donor database, finance tools, or other cloud services. In a busy organization, one forgotten account can stay active simply because nobody realized it was still there.
Offboarding is one of those IT tasks that works best when it is routine. Your team should know what happens, who is responsible, and when access ends.
The Charity Managed IT Buyers' Guide looks at offboarding as part of the broader day-to-day IT support charities should expect, alongside user account management, Microsoft 365 administration, cybersecurity, and ongoing support.
What Should Happen When Someone Leaves?
The process does not need to be complicated, but it does need to be consistent.
At the appropriate time, the person's main account should be disabled and active sessions should be signed out. Their access to Microsoft 365, shared folders, your CRM or donor database, finance systems, project tools, and other work applications should also be reviewed and removed.
Organization-owned laptops, phones, tablets, security keys, or other equipment should be returned. Multi-factor authentication methods connected to the departing person's account should be removed as well.
If the person knew passwords for shared accounts, those passwords may need to be changed.
There is also something important to deal with before accounts are deleted: the work they are leaving behind.
Their mailbox may contain conversations a colleague needs to continue. Important documents might be stored in their OneDrive or another personal work folder. Those files and messages should be transferred to the right person rather than keeping the former employee's account active indefinitely.
The Access That Is Easy to Forget
Email and Microsoft 365 are usually the obvious places to start. They are rarely the whole picture.
Think about a staff member who helped organize a fundraising campaign last year. They may still have access to an online design tool, the organization's social media account, a shared Google Drive, an event platform, or a payment service that the rest of the team barely thinks about anymore.
Volunteers and contractors can be particularly easy to overlook. Someone may have been given access for a short project, but nobody set an expiry date or remembered to remove them when the work ended.
Board members can have the same issue. A former director might still be able to open governance folders, board packages, or internal planning documents months after their term finishes.
Personal devices can add another layer. If someone has saved work logins in a browser or email app, disabling the account and signing out active sessions helps close that door.
This is also why individual user accounts are preferable wherever possible. If five people use one shared password, it becomes difficult to know exactly who still has access when one of them leaves.
For a wider look at passwords, multi-factor authentication, device security, and other everyday protections, this article should link to Cybersecurity Essentials for Charities.
Why This Matters for Donor and Organizational Data
Access management is not only about keeping email tidy.
Charities and non-profits may hold donor records, financial documents, employee information, board materials, payment details, and information connected to the people they serve. Some team members need access to that information to do their jobs. Others do not.
A simple rule helps: people should have access to what they need while they need it.
When their role changes or ends, that access should change too.
Imagine a fundraising employee leaves after several years with the organization. They had access to the donor database, online donation platform, shared fundraising folders, and campaign reports. Even if the departure is completely friendly, there is no practical reason for those accounts to remain open after the handoff is complete.
Removing access is not about treating former staff with suspicion. It is simply good information management.
For more detail on protecting donor and payment information, this section should connect naturally to Protecting Donor and Payment Data: Best Practices for Nonprofits.
Make Offboarding a Repeatable Process
Offboarding gets harder when the process depends on somebody remembering every system a person might have used.
That is especially true in small charities, where one person may manage HR, operations, fundraising, and several other responsibilities at the same time. A departure can happen in the middle of a grant deadline, a fundraising campaign, or a busy service-delivery week.
A simple checklist makes the process much easier.
Your team should know who tells IT that someone is leaving, what date and time their access should end, what equipment needs to be returned, and who should receive their files or email. There should also be a way to review less obvious systems, such as project tools, shared passwords, social media accounts, and third-party cloud services.
The same basic process can work for employees, contractors, volunteers, and board members. The details may change depending on the person's role, but the question stays the same: what did this person have access to, and what needs to happen to that access now?
A good offboarding process also helps with onboarding. When you keep a clear record of the accounts and systems someone receives when they join, you already have a useful starting point when they eventually leave or change roles.
What Should Your IT Provider Handle?
You should not have to become the person who manually tracks down every Microsoft 365 setting, device login, and cloud account whenever somebody leaves.
A managed IT provider should be able to handle the technical side of the process, including disabling accounts, removing Microsoft 365 and cloud access, signing users out of active sessions, updating multi-factor authentication, transferring files and mailboxes, and helping secure organization-owned devices.
They should also help you build a process that your organization can repeat.
That matters because offboarding is not a once-a-year cybersecurity exercise. Staff change roles. Volunteers finish projects. Contractors come and go. Board terms end. Access management is part of the normal life of an organization.
If you are evaluating what ongoing IT support should include, the Charity Managed IT Buyers' Guide provides a broader look at managed IT, cybersecurity, Microsoft 365, user support, and the questions worth asking a potential provider.
A Clear Process Makes Departures Easier
When someone leaves your organization, access management should feel routine, not stressful. A clear offboarding process helps protect sensitive information, keeps your systems organized, and makes it easier for the remaining team to pick up important work.
For many charities and non-profits, the difficult part is not understanding why this matters. It is finding the time to handle it properly every single time.
The right IT partner can take much of that work off your plate. Instead of asking an Executive Director or Operations Manager to remember every login, shared folder, device, and cloud application, you can have a process that is documented, consistent, and built around the way your team actually works.

