Closing a leaver's email access takes more than a password change on their last day. Employee offboarding email access is only fully closed when every active session is ended, rules forwarding mail outside the organisation are deleted, shared mailbox and file permissions are removed, and the mailbox contents are handed to a named owner.
Done by hand across separate systems, one of these steps is always missed, so the goal is to shut all access through a single identity in a single action. How long the mailbox is kept, and why, should be set in advance in a written retention policy that meets data protection law, including KVKK for organisations operating in Türkiye.
The access points that get missed on leaving day
In many organisations offboarding starts in HR and reaches IT as an email: "Ahmet leaves on Friday, please close his account." IT changes the password and the job is marked done. Yet an email account has several doors leading outside:
- Active sessions: a session left open on a personal phone or home laptop can, on some systems, keep working for a while after the password changes.
- Forwarding rules: a rule set up months ago to copy incoming mail to a personal address keeps running for as long as the account is live.
- Shared mailboxes: permissions on addresses such as
sales@oraccounts@are easily forgotten if they are managed separately from the personal mailbox. - File shares: documents shared by link rather than attachment stay reachable if the link never expires. We explain how to tie shares to roles in file sharing permissions.
- Other systems: supplier portals, cloud services and banking channels registered with the work address, whose password-reset links arrive in that mailbox. Single sign-on (SSO) brings this scattered access back to one point.
Critical roles and sudden departures
Not every departure carries the same risk. For roles that touch payments, personal data or permissions (finance, purchasing, HR, system administrators), access may need to be narrowed as soon as the departure is confirmed rather than on the last day. When a departure is sudden or contentious, every step needs to be completed within the same hour, which is only realistic if access is managed from one place.
The second problem is lost knowledge. Customers and suppliers keep writing to the old address; close the mailbox abruptly and those messages disappear, leave it open and nobody knows who is reading it.
The cost of not closing access on time
A leaver's account usually becomes a risk not through malice but because it is forgotten. An active account with no owner is an ideal entry point: if its password leaks, nobody notices.
According to the Verizon 2026 Data Breach Investigations Report, use of stolen credentials held steady as an action in 36% of breaches.
- The Microsoft Digital Defense Report 2025 states that more than 97% of identity attacks are password attacks. Unused accounts that nobody monitors are convenient targets for them. For the basics of a password policy, see business password security.
- Sophos' State of Identity Security 2026 survey of 5,000 IT and security leaders in 17 countries found that 71% of responding organisations suffered at least one identity-related breach in the past year, while only 24% continually monitor for unusual login attempts.
- In Türkiye, breaches are on record: the KVKK 2025 Annual Activity Report shows that the Personal Data Protection Authority received 328 data breach notifications in 2025. Unauthorised access to a mailbox full of customer correspondence can easily become one of them.
Employee offboarding email access: a step-by-step checklist
Turn this list into a leaver form shared by HR and IT. Every step needs an owner and a completion date.
Before the leaving date
- Name the mailbox successor. Decide who takes over the correspondence (a manager or a colleague) when the departure is announced.
- Hand over shared mailbox duties. Work the leaver handles in shared addresses should be reassigned before their permissions are removed. How to remove delegate and send-on-behalf rights is covered in mailbox permissions and delegation.
- List accounts opened with the work address. Supplier portals, cloud services, social media management; their addresses and credentials need to be transferred.
- Check the mailbox's forwarding rules. Remove any forwarding to external addresses now.
On the last day
- End every session. Changing the password is not enough; all open sessions, including mobile apps and browsers, must be terminated.
- Remove access to every product at once. Email, file sharing, shared mailboxes and internal systems. If one stays open, closing the others means little. Physical access matters too: link your card access control system records to the leaver form so the card is disabled the same day.
- Revoke non-expiring share links. Review external shares the person created.
- Set up an auto-reply and routing. People writing to the old address should be told who their new contact is, and incoming mail should reach the successor.
After the leaving date
- Review the audit log. Look for unusual bulk downloads or external forwarding in the final weeks.
- Apply the retention period. Keep the mailbox, with restricted access, for the period set in your retention and disposal policy, then delete or anonymise it. The wider framework is in our data retention and disposal policy guide.
| Step | Managed by hand | Single-identity environment |
|---|---|---|
| Password and sessions | System by system | One action across all products |
| Shared mailbox permissions | Mailbox by mailbox | Updated automatically with department changes |
| File access | Separate action in a separate system | Closes with the same identity |
| Evidence | Email threads | Audit log |
The data protection angle: what to do with the mailbox
A leaver's mailbox holds personal data about customers and suppliers, and about the employee. KVKK (Türkiye's Law No. 6698 on the Protection of Personal Data, broadly comparable to GDPR) requires personal data to be kept only for specified, explicit and legitimate purposes, and only for as long as that purpose requires. Three things should therefore be written down in advance:
- Purpose: why is the mailbox kept? Business continuity, evidence in case of legal disputes, or a statutory retention obligation.
- Period and access: how long will it be kept, and who may access it during that time, on what grounds?
- Notice: employees should be told when they join that the work email account is for business use and how it will be handled after they leave.
We help organisations write this policy through our data protection compliance work. We cover the archiving side in our article on email archiving and data protection.
If you are planning to change email systems, migration is the best time to clean out mailboxes left open for former staff; see the steps in our business email migration guide.
In a group of companies, leaving is not the only risk: someone transferring from one company to another can keep an old mailbox open too. Managing this from one panel is covered in email management for multiple companies.
How we approach offboarding at Digital Bridge
We set up offboarding as a process shared by HR, IT and legal, not as a single IT ticket:
- Access inventory: we map every system an employee reaches with their work identity and identify which ones are closed by hand when someone leaves.
- Process design: we adapt the checklist above to your organisation and connect the leaver record in your HR and personnel management system so that it triggers the IT steps.
- Security review: as part of our cyber security consultancy, we look for ownerless accounts, external forwarding rules and non-expiring share links.
- Move to a single identity: by bringing email and file management under one identity, we reduce offboarding to a single action. How to test account lifecycle management as a criterion when choosing a provider is covered in how to choose business email.
How offboarding works in Smart360
Our own Smart360 family brings SmartMail (business email) and SmartFiles (business file management) together under one panel and one identity, SmartID. In offboarding, that translates into something concrete.
Scenario: a member of the sales team leaves on Friday. Their manager closes the employee's access from the single panel and access is removed across every product in one action: the personal mailbox, the project areas in SmartFiles and the shared mailbox permissions together. Nothing has to be done system by system, so nothing is forgotten.
Other details in the same scenario:
- Sessions: all sessions are listed with device details and can be ended remotely; changing a password closes every session. A session left open on a personal phone can be spotted in that list and ended.
- Passwords that are never handed out: the system generates mailbox passwords and stores them encrypted with AES-256-GCM; they are not distributed to employees. A leaver walks away without a known mailbox password that could be reused elsewhere.
- Shared mailboxes: access follows the department, and when someone leaves a department their mailbox access is removed automatically. A change of department likewise updates access across all products. Our guide to shared mailbox management explains how to structure shared mailboxes.
- Knowledge that stays: when customer correspondence lives in shared mailboxes and documents live in SmartFiles department and project areas, knowledge does not leave with the person. SmartFiles never overwrites: every file uploaded under the same name is kept as a new version.
- Short-lived links: SmartFiles download and preview links expire within minutes, so they do not linger as a lasting way in.
- A trail: the audit log and the activity log on every message show who did what in a mailbox before and after the departure.
Next step
Start by seeing which access points are closed by hand today when someone leaves. You can explore Smart360's single identity and access management on the Smart360 page, or contact us to review your offboarding process together, from access inventory to the leaver form. The other articles on identity, access and archiving are gathered in our Business Email & Documents guide.