
When someone leaves your charity or non-profit, there is usually a familiar list to work through. Payroll needs an update, keys and equipment come back, and someone has to decide who will take over unfinished work. Their technology access needs the same attention.
A departing employee, contractor, volunteer, or board member may still have access to email, shared files, Microsoft 365, your donor database, finance tools, or other cloud services. In a busy organization, one forgotten account can stay active simply because nobody realized it was still there.
Offboarding works best when it is routine. Your team should know what happens, who is responsible, and when access ends. It should be part of your organization’s broader day-to-day IT support, alongside user account management, Microsoft 365 administration, cybersecurity, and ongoing help for staff.
What Should Happen When Someone Leaves?
The process does not need to be complicated, but it does need to be consistent.
At the appropriate time, the person’s main account should be disabled and any active sessions should be signed out. Their access to Microsoft 365, shared folders, your CRM or donor database, finance systems, project tools, and other work applications should also be reviewed and removed.
Organization-owned laptops, phones, tablets, security keys, or other equipment should be returned. Multi-factor authentication methods connected to the departing person’s account should be removed too.
If they knew passwords for shared accounts, those passwords may also need to be changed. This is especially important when several people have used the same login over time.
Before anything is deleted, though, there is another practical question to answer: what does the organization still need?
A departing staff member’s mailbox may contain conversations that a colleague needs to continue. Important documents might be stored in their OneDrive or another personal work folder. Those files and messages should be transferred to the right person instead of keeping the former employee’s account active indefinitely.
The Access That Is Easy to Forget
Email and Microsoft 365 are usually the obvious places to start. They are rarely the whole picture.
Think about someone who helped run a fundraising campaign last year. They may still have access to an online design tool, your social media accounts, a shared cloud folder, an event platform, or a payment service that the rest of the team barely thinks about anymore.
Volunteers and contractors can be particularly easy to overlook. Someone may have been given access for a six-week project, but nobody set an expiry date or remembered to remove it when the work ended. Board members can have the same issue with governance folders, board packages, or internal planning documents after their term is finished.
Personal devices add another layer. A former team member might have work email or saved logins on a phone, tablet, or browser. Signing out active sessions and removing account access helps make sure those saved connections no longer work.
This is also why individual accounts are so useful. If five people share one password, it becomes much harder to know who still has access when one of them leaves. Stronger password and account security makes offboarding much easier because every person has access that can be managed individually.
Why This Matters for Donor and Organizational Data
Access management is not only about keeping email tidy.
Charities and non-profits may hold donor records, employee information, board materials, financial documents, payment details, and information connected to the people they serve. Some team members need access to that information to do their work. Others do not.
A useful rule is simple: people should have access to what they need while they need it. When their role changes or ends, their access should change too.
Imagine a fundraising employee leaves after several years with the organization. They had access to your donor database, online donation platform, shared fundraising folders, and campaign reports. Even if the departure is completely friendly, there is no practical reason for those accounts to remain available once the handoff is complete.
Removing access is not about treating former staff with suspicion. It is part of taking reasonable care of information your organization has been trusted with. The same principle applies more broadly when protecting donor and payment information, especially when several staff members, volunteers, or outside partners work with the same systems.
Make Offboarding a Repeatable Process
Offboarding becomes much harder when the process depends on somebody remembering every system a person might have used.
That is especially true in smaller charities, where one person may be managing HR, operations, fundraising, and several other responsibilities at the same time. A departure can happen in the middle of a grant deadline, a fundraising campaign, or an already busy week of service delivery.
A simple checklist can take a lot of pressure out of the process. Your team should know who tells IT that someone is leaving, when their access should end, what equipment needs to come back, and who should receive their files or email.
It should also include the less obvious systems. Project tools, shared passwords, social media accounts, online fundraising services, third-party applications, and temporary accounts are easy to miss if nobody has a clear record of them.
The same basic process can work for employees, contractors, volunteers, and board members. The details may be different, but the question stays the same: what did this person have access to, and what needs to happen to that access now?
There is a useful side benefit too. Good offboarding usually starts with good onboarding. If you keep a clear record of the accounts, devices, and systems someone receives when they join, you already have a useful checklist when they eventually leave or change roles.
What Should Your IT Provider Handle?
You should not have to become the person who tracks down every Microsoft 365 setting, device login, and cloud account whenever somebody leaves.
A managed IT provider should be able to take care of the technical parts of offboarding, including disabling accounts, removing cloud access, signing users out of active sessions, updating multi-factor authentication, transferring files or mailboxes, and helping secure organization-owned devices.
They should also help you build a process that works for your organization rather than expecting someone on your team to figure it out from scratch each time.
Staff change roles. Volunteers finish projects. Contractors come and go. Board terms end. Access management is part of normal organizational life, which is why it belongs alongside the other IT services and support a charity should expect from a managed provider.
Make Offboarding Easier on Your Team
When someone leaves, your team should not have to chase down accounts, files, devices, and passwords at the last minute. A clear offboarding process keeps the handoff organized and makes sure access is closed properly.
It is one more part of IT that should be handled with care, without creating more work for the people already carrying the mission.

