Website Access Cleanup When an Employee or Vendor Leaves
When an employee, freelancer, or agency relationship ends, website access is easy to overlook. The person may no longer appear in the company directory, but their WordPress account, hosting login, analytics access, deployment key, or password-manager invitation can remain active for months.
Good offboarding is not an accusation. It is ordinary access control: people should have the access they need while they need it, and that access should end when the work does.
NIST access-control guidance includes disabling accounts when they are no longer needed and reviewing accounts on a defined basis. A small business can apply that principle without building an enterprise identity program.
Start with ownership, not passwords
Before removing anyone, identify which accounts the business owns and which ones were created in a vendor’s name. The domain registrar, DNS provider, hosting account, content management system, analytics property, tag manager, search tools, forms, email delivery, and code repository should not depend on one departing person’s private inbox.
If the former provider is the only owner, first transfer ownership to a verified company-controlled account. Removing the only administrator before that transfer can turn a routine cleanup into a lockout.
Inventory every access path
The WordPress Users screen is only one part of the picture. Check the systems that can change the site or receive its data:
- Domain registrar and DNS.
- Hosting, control panel, database, and file transfer.
- WordPress or another CMS.
- GitHub or another source repository and deployment platform.
- Analytics, Tag Manager, Search Console, call tracking, and heatmaps.
- Form, SMTP, CRM, scheduling, ecommerce, and payment integrations.
- Password managers, shared inboxes, cloud storage, and backup systems.
- API keys, webhooks, SSH keys, application passwords, and automation tokens.
Our guide to website hosting as a security risk is a useful companion because access cleanup works best when the company can prove who owns each system.
Disable named accounts and rotate shared secrets
For a named account, disable or remove that user after transferring anything the business must keep. For a shared credential, change the password and update every authorized user or system that depends on it.
Do not delete content merely because its author account is leaving. Reassign pages, posts, files, dashboards, workflows, and repositories before removal. Export anything that lives only inside a contractor-controlled system.
Shared accounts create a harder problem because the audit trail cannot show who acted. Replace them with named accounts where the platform allows it, require MFA, and reserve shared emergency credentials for controlled recovery.
Review integrations and machine access
A person can lose dashboard access while an old API token or deployment key continues to work. Review connected applications, personal access tokens, application passwords, SSH keys, OAuth grants, webhooks, automation users, and stored credentials in deployment systems.
Rotate secrets that were visible to the departing person, even if no misuse is suspected. Then verify that forms, deployments, backups, analytics, and other integrations still work. A credential rotation that silently breaks lead delivery is not complete.
Preserve evidence before removing access
Capture the current user and integration lists, ownership settings, and relevant activity logs. Record what was disabled, transferred, rotated, or intentionally retained. If the departure is disputed or security-sensitive, coordinate with the appropriate legal, HR, or security owner before changing evidence or deleting data.
For ordinary offboarding, a short record is enough: system, former access, action taken, new owner, verification result, and date.
Verify from both sides
After cleanup, verify that the former account no longer has access and that the business still does. Test the actual operating paths:
- A current administrator can sign in with MFA.
- The site can still deploy and roll back.
- Forms reach the right inbox or CRM.
- Analytics and search tools still collect data.
- Backups complete and can be accessed by the current owner.
- Domain, DNS, hosting, and billing contacts belong to the business.
This is also a good time to remove dormant accounts that have no current owner or purpose.
Make offboarding a trigger, not an annual surprise
An annual access review is useful, but it should not be the first time anyone checks. Employee departure, agency replacement, project completion, role change, and suspected credential exposure should each trigger an immediate review.
Robben Media can help inventory a website’s ownership and access paths, then fold offboarding checks into an ongoing website support and maintenance plan. The goal is simple: the business keeps control, the departing person loses unnecessary access, and the website continues working.
Jeremy Johnson
Owner
Jeremy co-owns Robben Media and directs strategy for every client engagement. With a Computer Engineering degree from Missouri S&T, he brings deep technical expertise in web development, SEO, and automation. Before acquiring Robben Media in 2023, Jeremy led marketing and branch management in the mortgage industry. He believes marketing should be measured by revenue generated, not impressions reported.